- What has changed: ShinyHunters claims access to over 100 PeopleSoft servers
- The risk profile of legacy ERPs: why PeopleSoft is in the crosshairs
- Immediate impact on the organizations involved
- What SMEs with outdated ERP systems should do now
- A digital agency's perspective: why security also concerns marketing
- Outlook: legacy ERP risk will grow over the next 18 months
The criminal group ShinyHunters has claimed responsibility for the breach of over 100 Oracle PeopleSoft servers. The victims include numerous universities and structured organizations. The attack raises urgent questions about the security of legacy ERPs still widespread in the Italian manufacturing fabric.
Therefore, SMEs operating with PeopleSoft systems — or any outdated enterprise platform — must immediately initiate a check of available security patches. Additionally, it is crucial to perform an audit of access credentials and system logs. Ignoring these signals means exposing yourself to concrete risks of data exfiltration and operational disruption.
In short, we at SHM Studio we think this incident should be seen as a structural wake-up call, not just a one-off. Organizations mixing advanced digital tech with unpatched legacy infrastructure are prime targets for APT groups and ransomware gangs. So, the window to act is tight.
What has changed: ShinyHunters claims access to over 100 PeopleSoft servers
On June 10, 2026, the criminal group known as ShinyHunters claimed to have compromised Oracle PeopleSoft servers belonging to over a hundred organizations. The news was first reported by TechCrunch , which has documented the group's public claim. Identified victims predominantly include universities and medium to large organizations.
Oracle PeopleSoft is a widely used enterprise ERP suite for managing HR, finance, and supply chain. Therefore, a compromise of it doesn't just affect technical data: it directly impacts the personal information of employees, students, and suppliers.
ShinyHunters isn't a new player in the cybersecurity threat landscape. In fact, the group is already known for high-profile breaches in previous years, including attacks on SaaS platforms and cloud databases. However, the declared scope of this campaign — over a hundred organizations simultaneously — represents a significant leap in scale.
The risk profile of legacy ERPs: why PeopleSoft is in the crosshairs
Oracle PeopleSoft is a mature platform. Many active installations today date back to versions released years ago, with slow upgrade cycles and patches often not applied promptly. As a result, these systems present known and documented attack surfaces.
According to analyses published by Gartner , a significant portion of organizations using on-premise ERP systems operate with outdated versions. This delay in patch management is one of the most exploited attack vectors by ransomware and APT groups. Furthermore, the architectural complexity of PeopleSoft — with interconnected modules and legacy integrations — makes it difficult to quickly isolate any potential compromise.
Specifically, the most critical vulnerabilities often concern authentication layers and exposed web services. Furthermore, incorrect access permission configurations exponentially amplify the risk. For this reason, an improperly hardened PeopleSoft installation is effectively a privileged entry point for anyone wanting to move laterally within a corporate network.
Immediate impact on the organizations involved
Affected organizations now find themselves managing multiple, simultaneous scenarios. First and foremost, they must verify if their data has actually been exfiltrated or if the claim concerns unauthorized access without confirmed exfiltration. Then, they must notify the competent authorities as required by GDPR, within the strict deadlines imposed by the regulation.
Besides this, organizations have to deal with reputation risk. A breach involving HR or financial data directly hits the trust of employees, partners, and customers. Even so, many organizations tend to delay public announcements, making their legal exposure even worse.
Similarly to what happened in previous ERP system breaches, it is likely that the stolen data will be put up for sale on underground forums or used for targeted spear phishing campaigns. Therefore, the scope of the damage tends to widen over time if swift action is not taken.
What SMEs with outdated ERP systems should do now
Even Italian SMEs that do not directly use Oracle PeopleSoft should read this episode as a warning. In fact, the underlying principle is universal: any unpatched legacy ERP or management system is an active risk vector. Therefore, the priority actions to be taken are clear.
- Immediate check of available patches : Oracle regularly releases Critical Patch Updates (CPUs). Organizations must verify if the latest releases have been applied, especially those related to PeopleSoft's web-facing modules.
- Privileged access audit : you need to review who has admin access to your ERP systems, revoke any credentials you don't need anymore, and turn on multi-factor authentication where it's missing.
- System log analysis : take a look at the sign-in logs from the past 90 days to spot any weird patterns, logins from strange IP addresses, or attempts to grab extra privileges.
- Network segmentation : ERP servers shouldn't be exposed directly to the outside world. Setting things up properly cuts down your attack surface big time.
- Incident response plan : if you don't have a written plan for handling breaches, you need to put one together right away, spelling out who does what and how to report things.
To dive deeper into best practices on the matter, the framework published by NIST Cybersecurity Framework represents a solid operational benchmark that can also be adopted by mid-sized organizations.
A digital agency's perspective: why security also concerns marketing
It might seem counterintuitive that an agency like SHM Studio deals with ERP breaches. However, the operational reality for Italian SMEs is that of interconnected systems: the CRM integrates with the management software, the management software feeds the e-commerce site, and the e-commerce site is linked to digital campaigns. Consequently, a breach upstream quickly propagates downstream.
In particular, many of the SMEs we follow in the digital marketing services they use legacy platforms to manage orders or customers. If compromised, these platforms can turn into vectors for pushing malicious content to digital channels — including websites and campaign landing pages. So, cybersecurity and digital strategy go hand in hand.
Furthermore, a breach that exposes customer or lead data has a direct impact on ongoing campaigns: from data quality in Google Ads to custom audiences on Linkedin . That's why we always tell our clients to treat security like a must-have, not an afterthought.
Outlook: legacy ERP risk will grow over the next 18 months
The ShinyHunters-PeopleSoft case isn't an isolated incident. In fact, organized criminal groups tend to focus on enterprise systems with numerous installations and slow update cycles. Moreover, the increasing availability of automated attack tools lowers the technical threshold needed to exploit known vulnerabilities.
According to projections published by McKinsey , the global cost of cybercrime is set to grow significantly by 2028, with an increasing share attributable to vulnerabilities in unmigrated legacy systems. Therefore, organizations that postpone IT infrastructure modernization are effectively accumulating security debt.
In short, the message for Italian SMEs is simple: you don't need to use Oracle PeopleSoft to be at risk. Any management system that is not updated, not monitored, and not integrated into a structured security plan represents an active vulnerability. We at SHM Studio we also support companies in evaluating the technological ecosystem underlying their digital strategies — from web design to the AI solutions integration , moving on to the SEO and the strategic copywriting . Anyone who wants to discuss these topics can contact us from the contact page or explore the insights in our blog .
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.