Back to news

ShinyHunters Zero-Day Hits Universities; New Ransomware Gang Rises Fast

Two separate threat actors are reshaping enterprise risk: one exploiting an Oracle PeopleSoft flaw before a patch existed, another scaling ransomware operations with a 90% affiliate payout model.

ShinyHunters Zero-Day Hits Universities; New Ransomware Gang Rises Fast

What happened

The extortion group ShinyHunters, tracked by Google Mandiant as UNC6240, compromised enterprise systems by exploiting an unpatched vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273. The attacks ran from May 27 through June 9, with Oracle releasing its advisory only on June 10 — meaning victims had no official patch available during the entire active campaign. Higher education institutions bore the brunt of the intrusions, with stolen data used as leverage for extortion demands. Separately, a ransomware operation calling itself The Gentlemen has surged to become the second most prolific ransomware group by victim count, fueled by an aggressive recruitment model that returns 90 cents of every ransom dollar to its affiliates — an unusually generous split that has attracted seasoned operators quickly.

Why it matters for your business

The Oracle PeopleSoft campaign illustrates the acute danger of the zero-day window: organizations running campus or enterprise HR and finance platforms had no vendor-sanctioned remediation available while attacks were actively underway, making network segmentation, anomaly detection, and rapid threat intelligence feeds critical compensating controls. Any organization dependent on PeopleSoft should audit logs for the May 27–June 9 timeframe immediately and apply Oracle's June 10 patch without delay. The rapid ascent of The Gentlemen underscores a structural shift in the ransomware economy — high affiliate commissions lower the barrier for skilled criminals to join established operations, accelerating both victim volume and operational sophistication. Security and finance leaders should reassess cyber insurance coverage and incident response retainers in light of a ransomware market that is actively recruiting talent at scale.

What to watch next

Mandiant's attribution work on UNC6240 is ongoing, and further victims from the PeopleSoft campaign are likely to surface as forensic investigations conclude across affected universities. On the ransomware front, investigative reporting is closing in on the real-world identity behind The Gentlemen's administrator, which could trigger law enforcement action — or prompt the group to rebrand, as has happened repeatedly with high-profile ransomware outfits. Organizations should monitor Oracle's patch cadence closely, as researchers often discover related vulnerabilities in the same codebase following a high-profile zero-day disclosure.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp