What happened
The extortion group ShinyHunters, tracked by Google Mandiant as UNC6240, compromised enterprise systems by exploiting an unpatched vulnerability in Oracle PeopleSoft, identified as CVE-2026-35273. The attacks ran from May 27 through June 9, with Oracle releasing its advisory only on June 10 — meaning victims had no official patch available during the entire active campaign. Higher education institutions bore the brunt of the intrusions, with stolen data used as leverage for extortion demands. Separately, a ransomware operation calling itself The Gentlemen has surged to become the second most prolific ransomware group by victim count, fueled by an aggressive recruitment model that returns 90 cents of every ransom dollar to its affiliates — an unusually generous split that has attracted seasoned operators quickly.
Why it matters for your business
The Oracle PeopleSoft campaign illustrates the acute danger of the zero-day window: organizations running campus or enterprise HR and finance platforms had no vendor-sanctioned remediation available while attacks were actively underway, making network segmentation, anomaly detection, and rapid threat intelligence feeds critical compensating controls. Any organization dependent on PeopleSoft should audit logs for the May 27–June 9 timeframe immediately and apply Oracle's June 10 patch without delay. The rapid ascent of The Gentlemen underscores a structural shift in the ransomware economy — high affiliate commissions lower the barrier for skilled criminals to join established operations, accelerating both victim volume and operational sophistication. Security and finance leaders should reassess cyber insurance coverage and incident response retainers in light of a ransomware market that is actively recruiting talent at scale.
What to watch next
Mandiant's attribution work on UNC6240 is ongoing, and further victims from the PeopleSoft campaign are likely to surface as forensic investigations conclude across affected universities. On the ransomware front, investigative reporting is closing in on the real-world identity behind The Gentlemen's administrator, which could trigger law enforcement action — or prompt the group to rebrand, as has happened repeatedly with high-profile ransomware outfits. Organizations should monitor Oracle's patch cadence closely, as researchers often discover related vulnerabilities in the same codebase following a high-profile zero-day disclosure.
