ShinyHunters Targets Enterprise Data Systems
Coverage from BleepingComputer, ComplexDiscovery, and others

ShinyHunters is linked in reporting to a series of data-theft and extortion incidents affecting Ernst & Young, Oracle PeopleSoft users, Odido, and the Council of Europe.
The activity includes exploitation of enterprise applications, compromise of third-party platforms, theft of sensitive personal and financial records, and threats to publish data through leak sites. Several attacker claims and the full scope of affected data remain unverified, while incident response, regulatory notifications, and vendor mitigations are ongoing.
The update adds a new Council of Europe PeopleSoft-related incident, broadening the story beyond EY, Oracle customers, and Odido. It also shifts the framing toward ongoing response activity, with regulatory notifications and vendor mitigations now explicitly underway.
The main update is stronger, more specific confirmation of separate incidents: EY now confirms unauthorized access and document downloads, Oracle has issued an emergency warning on actively exploited PeopleSoft flaws, and Odido has acknowledged large-scale customer data exposure. Attribution and full scope still remain partly unverified.
