ShinyHunters Targets Enterprise Data Systems
Coverage from BleepingComputer, ComplexDiscovery, and others

ShinyHunters is linked in reporting to a series of data-theft and extortion incidents affecting Ernst & Young, Oracle PeopleSoft users, Odido, and the Council of Europe.
The activity includes exploitation of enterprise applications, compromise of third-party platforms, theft of sensitive personal and financial records, and threats to publish data through leak sites. Several attacker claims and the full scope of affected data remain unverified, while incident response, regulatory notifications, and vendor mitigations are ongoing.
The update adds a new Council of Europe PeopleSoft-related incident, broadening the story beyond EY, Oracle customers, and Odido. It also shifts the framing toward ongoing response activity, with regulatory notifications and vendor mitigations now explicitly underway.
The main update is stronger, more specific confirmation of separate incidents: EY now confirms unauthorized access and document downloads, Oracle has issued an emergency warning on actively exploited PeopleSoft flaws, and Odido has acknowledged large-scale customer data exposure. Attribution and full scope still remain partly unverified.
- EY confirmed unauthorized access and document downloads.
- Oracle issued an out-of-band warning for CVE-2026-35273.
- Reported PeopleSoft exploitation affected more than 100 organizations.
- Odido acknowledged exposure of personal data belonging to millions.
- Odido disputed claims about passwords and billing data.
The story has broadened from a PeopleSoft-focused exploitation campaign into a wider set of ShinyHunters-linked intrusions using multiple access paths, with EY and telecom/customer-data breaches now central examples. The main new emphasis is on vendor compromise, stolen credentials, and extortion-driven exposure across more sectors, while attribution and total scope remain unsettled.
- Ernst & Young's third-party IT service management breach exposed support-ticket attachments.
- Stolen credentials, analytics tokens, and OAuth access are recurring access paths.
- Reported impact includes 6.2 million Odido customers.
- Healthcare, retail, telecom, and public-sector environments are newly emphasized.
- Response now includes regulatory notification and identity monitoring.
ShinyHunters-linked attackers exploited a critical Oracle PeopleSoft PeopleTools vulnerability, CVE-2026-35273, to target cloud and on-premises environments and steal organizational data. Google Threat Intelligence Group and Mandiant observed malicious activity affecting more than 100 potentially vulnerable organizations, with higher education disproportionately represented, while Oracle issued emergency mitigations for affected PeopleTools versions. The scale of exposed data, uncertainty around individual victim impact, and extortion-driven leak activity make rapid investigation and access restriction important for PeopleSoft operators.
