ShinyHunters spent two weeks inside Oracle PeopleSoft servers using a vulnerability Oracle had not yet patched. By the time Oracle published its advisory on 10 June 2026, the group had already reached Moody Bible Institute, a Chicago-based Christian college, and was preparing to list it on a leak site. More than 2.3 million donors, students, alumni and staff had their data taken. Nobody confirmed a single export while it happened.
Published on 13 July 2026
Between 27 May and 9 June 2026, the data extortion group ShinyHunters, tracked by Google's Mandiant as UNC6240, exploited an unpatched remote code execution flaw in Oracle PeopleSoft to break into enterprise systems across the education sector. Among the victims was Moody Bible Institute (MBI), a Chicago-based Christian college with more than a century of enrolment, donor, and alumni records on file. Oracle did not publish an advisory for the vulnerability, tracked as CVE-2026-35273, until 10 June, which means for at least two weeks the bug was a true zero-day: rated 9.8 out of 10 on the CVSS scale, requiring no login and no user interaction, just network access over HTTP, to take full control of a PeopleSoft server.
The flaw sat in the Environment Management Hub, a PeopleSoft component many institutions leave reachable from the open internet. Once inside, the attackers moved quickly and carelessly, leaving their own staging infrastructure exposed on five sequential IP addresses running a bare Python web server. That exposure let researchers reconstruct the attack chain: the group deployed MeshCentral remote-management agents disguised as Microsoft Azure binaries, calling home to a command-and-control domain, built to look like Azure's NetApp Files service. A script named [victim]_fanout.sh then sprayed a hardcoded list of usernames and passwords over SSH against every internal host it could find, moving laterally through each compromised network before compressing the harvested data and shipping it out over SSH to infrastructure tied to the ShinyHunters leak site.
On 15 June 2026, ShinyHunters added Moody Bible Institute to that leak site, claiming more than 23 gigabytes of data spanning enrolment, donor relations, payroll, and internal communications. The haul included an estimated 46 million communication records, 2.2 million enrolment-lead records, more than 108,000 biodemographic master files carrying names, addresses, and dates of birth, donor gift histories, employee payroll files listing home addresses and earnings, and student housing assignments. Mandiant separately confirmed the campaign hit more than 100 organisations with exposed PeopleSoft endpoints, 68 percent of them in higher education, most in the United States.
The Institute has confirmed it is investigating and has engaged outside cybersecurity experts, but weeks after the leak site posting it still has not disclosed how many of its own systems were touched or confirmed the attack's starting point. Independent analysis puts the number of unique individuals affected at more than 2.3 million: donors, students, alumni, and staff. Class action law firms are already circling, and because the exposed dataset touches education records, Moody faces a state-by-state notification exercise under FERPA and dozens of overlapping breach notification laws, each with its own deadline and definition of what counts as personal information.
The defences that failed here were not weak by conventional standards. A patch cycle cannot close a hole nobody has published yet, and there is no firewall rule that anticipates a zero-day two weeks before the vendor knows about it. That is precisely the point: the vulnerability was never the part of this attack Moody Bible Institute could have controlled. What it could have controlled was what happened next, when tens of millions of records were packaged, compressed, and moved off its network with nobody in the organisation confirming that any of it should be leaving.
A bulk export of enrolment, donor, or payroll data at this scale is an execution event. Before a dataset of that size and sensitivity can leave the network, whether the request comes from a legitimate administrator console or a remote-management agent dressed up as an Azure service, a confirmation request goes to the named data protection authority on their registered device, requiring a biometric response before the transfer is permitted to complete. It does not matter whether the session token is valid, whether the agent looks like Microsoft software, or whether the attacker has already moved laterally through half the network.
A zero-day exploit, however well disguised the infrastructure behind it, cannot produce a biometric confirmation from a named authority on a device it does not control. The execution boundary holds regardless of how the attacker got in.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Khandelwal, S. 2026. ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities. The Hacker News, 11 June 2026.
2. Google Cloud / Mandiant. 2026. ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit. Google Cloud Blog, June 2026.
3. The Register. 2026. Moody Bible Institute breach leaves 2.3M accounts needing salvation, says cyber expert. The Register, 6 July 2026.
4. Cybersecurity Advisors Network. 2026. Week 25 – Caught in the Web: ShinyHunters Spins a MeshCentral Trap for PeopleSoft. Cybersecurity Advisors Network, 19 June 2026.
5. SC Media. 2026. Moody Bible Institute data breach exposes 2.3 million individuals. SC World, July 2026.
Back to Blog
Case Studies·4 min read
Oracle patched the PeopleSoft flaw on 10 June. ShinyHunters had already been inside Moody Bible Institute for two weeks.
By GoFirm
