NAIC Breach Exposes Oracle PeopleSoft Zero-Day Used to Steal 3.1TB of Insurance Data

ShinyHunters breached 100+ orgs exploiting a critical unauthenticated RCE zero-day in Oracle PeopleSoft (CVE-2026-35273) before the June 10 emergency patch. Any GCC organization running unpatched PeopleTools 8.61 or 8.62 faces immediate automated exposure right now.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
A financial services office environment with database workstations, representing the NAIC data breach in which ShinyHunters exploited an Oracle PeopleSoft zero-day vulnerability to steal 3.1 terabytes of sensitive insurance industry data, with direct implications for any organisation running PeopleSoft on-premises.

A financial services office environment with database workstations, representing the NAIC data breach in which ShinyHunters exploited an Oracle PeopleSoft zero-day vulnerability to steal 3.1 terabytes of sensitive insurance industry data, with direct implications for any organisation running PeopleSoft on-premises.

A critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft Enterprise PeopleTools has been actively exploited in the wild by the ShinyHunters extortion group, compromising more than 300 PeopleSoft instances across over 100 organisations globally between 27 May and 9 June 2026. Oracle released an emergency out-of-band Security Alert and patch for the vulnerability, tracked as CVE-2026-35273, on 10 June 2026. The flaw carries a CVSS 3.1 score of 9.8 and requires no authentication or user interaction to exploit.

What the Vulnerability Is

CVE-2026-35273 resides in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools and is exploitable remotely over HTTP. A successful exploit allows an attacker to execute arbitrary code on the affected server, with confirmed post-compromise paths leading to full system compromise and lateral movement into connected Windows domain infrastructure. Mandiant classified the underlying flaw as a server-side request forgery weakness and confirmed active exploitation as a zero-day beginning on 27 May 2026, two weeks before Oracle published its advisory.

The vulnerability was discovered and responsibly reported to Oracle through TrendAI's Zero Day Initiative by researchers Bobby Gould, Lucas Miller, and Minh Giang. PeopleTools versions 8.61 and 8.62 are affected. Oracle PeopleSoft Enterprise Applications customers may also be impacted due to shared component dependencies.

The ShinyHunters Campaign

ShinyHunters, also tracked by Mandiant as UNC6240, ran an automated exploitation campaign against internet-facing PeopleSoft environments throughout late May and early June 2026. The campaign disproportionately targeted the higher education sector, with 68 per cent of the more than 100 notified organisations being universities and colleges. Stolen data was published on the ShinyHunters dark web data leak site on 9 June 2026, one day before Oracle's advisory.

The attackers exploited PeopleSoft's Environment Management Hub endpoints specifically, targeting the /PSIGW/HttpListeningConnector and /PSEMHUB/ URI paths. Post-exploitation activity documented across victim environments included creation of new local Windows accounts, deployment of web shells in the PeopleSoft Internet Architecture web root, lateral movement to domain controllers within hours of initial compromise, and in some cases, delivery of extortion markers. The presence of a file named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT anywhere in the PeopleSoft web root confirms a successful breach.

Why GCC Enterprises Are Exposed

PeopleSoft is embedded across GCC government entities, universities, financial institutions, healthcare organisations, and large enterprises as the primary platform for HR, payroll, finance, and supply chain operations. Saudi Arabia and UAE government bodies and parastatal organisations are among the most significant PeopleSoft deployments in the region. The combination of a 9.8 CVSS score, unauthenticated remote exploitation, and a proven automated attack chain capable of compromising 300 instances in a two-week period means that any internet-accessible PeopleSoft instance running PeopleTools 8.61 or 8.62 that has not yet applied the June 10 patch must be treated as potentially compromised.

The ShinyHunters group has a documented presence in GCC cybercrime intelligence reporting as a member of the broader SLH alliance alongside Scattered Spider and LAPSUS$, all of which share data theft infrastructure and extortion operations. The PeopleSoft campaign confirms that the group is actively targeting enterprise ERP infrastructure at scale.

Immediate Remediation Steps

Oracle released the emergency patch for CVE-2026-35273 on 10 June 2026, bypassing the normal quarterly patch cycle because the vulnerability was under active exploitation. GCC enterprises running PeopleTools 8.61 or 8.62 must apply this patch immediately via My Oracle Support (Doc ID 2999999.1). The June 2026 Critical Security Patch Update released on 16 June 2026 also incorporates the Security Alert fix alongside patches for 243 additional CVEs across 11 Oracle product families and should be applied as the complete remediation package.

Organisations that cannot patch immediately should implement the following interim controls without delay. Disable the Environment Management Hub service in multi-server configurations, or remove the PSEMHUB application entirely in single-server configurations. Block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the network perimeter or firewall layer. Rapid7 confirms that restricting these endpoints does not break standard end-user PeopleSoft Internet Architecture browser sessions. Monitor outbound SMB traffic on TCP port 445 from PeopleSoft servers to untrusted external destinations.

Investigating for Prior Compromise

Because exploitation began on 27 May 2026, two weeks before Oracle's advisory and patch, every PeopleSoft environment should be investigated for signs of prior compromise regardless of whether the patch has been applied. The following steps should be completed as part of a compromise assessment.

Search PeopleSoft logs for connections from the confirmed ShinyHunters infrastructure: 142.11.200.186 through 142.11.200.190, 108.174.202.99, and 176.120.22.24. Search the PeopleSoft web and application server directories for the extortion marker file README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. Audit recently created or modified .xml files under the envmetadata/data/environment/ directory. Review for suspicious POST requests to /PSIGW/HttpListeningConnector containing loopback addresses or internal IP ranges within headers or parameters. Check for unexpected new local Windows accounts, particularly any named psadmintemp. Rotate credentials on all default PeopleSoft administrative accounts including psoft, oracle, and linuxadm regardless of whether compromise indicators are found, as the campaign specifically targeted these accounts.

For GCC enterprises subject to UAE NESA Information Assurance Standards or Saudi Arabia's NCA Essential Cybersecurity Controls, ERP platform security falls squarely within mandated critical system protection and patch management obligations. An unpatched PeopleSoft instance with a CVSS 9.8 unauthenticated RCE flaw that has been under active automated attack since late May represents a material compliance failure under both frameworks, not only a technical one.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Enterprise ERP Security GCCFinancial Services Cybersecurity MENAZero-Day Vulnerability Response 2026GCC Government and Banking IT Security