Skip to main content
HIGH Threat Intel #ShinyHunters#Ransomware

ShinyHunters Arrest and PeopleSoft Zero-Day Exploitation

2 min read Runtime Rebel Intel
Primary source: krebsonsecurity.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: The ShinyHunters syndicate retaliated against law enforcement by launching high-profile data thefts targeting the FBI and extorting the Cl0p ransomware group.
  • Affected systems: Oracle PeopleSoft instances vulnerable to zero-day exploitation via CVE-2026-35273.
  • Remediation: Ensure all Oracle PeopleSoft deployments are fully patched against CVE-2026-35273 and review perimeter logs for indicators of compromise.

Advertisement

Overview of the Dutch Police Arrest

Authorities in the Netherlands arrested a 24-year-old convicted cybercriminal on suspicion of aiding data thefts and extortions orchestrated by the prolific hacker collective ShinyHunters. According to multiple sources familiar with the investigation, the detained individual is Pepijn van der Stap, a resident of Almere and Lelystad who was previously convicted in 2023 for cybercrimes associated with RaidForums and Breached under the handle “Umbreon.”

Despite a prior conviction and a subsequent prison sentence, van der Stap had recently worked in offensive security roles for regional startups. Following his detention in mid-September, the ShinyHunters syndicate mobilized swiftly, confirming full emotional and financial support for their detained associate while openly taunting Dutch law enforcement.

Retaliatory Attacks and PeopleSoft Exploitation

In the immediate wake of the arrest, the threat actor group escalated operations with a series of brazen data thefts. Most notably, the collective claimed credit for breaching the FBI’s job application portal at apply.fbijobs.gov. According to security reporting, the incident exposed sensitive records—including Social Security numbers, internal team assignments, and psychiatric files—belonging to over 5,000 personnel.

Security analysis indicates that the campaign relied heavily on weaponising CVE-2026-35273, a security flaw affecting Oracle PeopleSoft. Threat intelligence teams noted that the collective utilized this vulnerability as a zero-day vector before Oracle issued formal patches and mitigation guidance.

Impact on Telecommunications and Extortion Operations

Prior to the FBI incident, the same network of actors successfully compromised Odido, the largest mobile telecommunications provider in the Netherlands, using sophisticated social engineering techniques over telephone lines to siphon records belonging to approximately 6.2 million Dutch citizens. Furthermore, the group turned its sights inward within the cybercrime ecosystem, launching extortion demands against the Cl0p ransomware operation.

Mitigation and Recommendations

Defenders managing enterprise human resources platforms must prioritize immediate remediation steps to counter ongoing exploitation waves associated with these campaigns:

  • Apply official vendor patches for CVE-2026-35273 across all Oracle PeopleSoft installations immediately.
  • Deploy web application firewall (WAF) rules designed to detect and block abnormal application-layer requests targeting recruitment and portal endpoints.
  • Conduct thorough log analysis for unusual administrative authentications, particularly involving external recruitment portals and legacy HR workflows.

Related: CVE-2026-21962: Oracle WebLogic RCE Under Active Attack, Mount Royal University Data Breach: Ransomware Impact & Mitigation

Advertisement

Advertisement