ShinyHunters Extorted Boeing‑Spun‑Off Unit After Exploiting Oracle PeopleSoft Zero‑Day
ShinyHunters leveraged CVE‑2026‑35273 in Oracle PeopleSoft to steal data from a Boeing‑divested business unit and demand ransom. The incident illustrates why continuous third‑party risk monitoring and patch‑validation are essential for audit readiness.
ADTP Breach Watch· October 7, 2026· Krebs on Security
SeverityHigh
Type💀 Breach
ConfidenceHigh
ReportedOct 7, 2026
Manufacturing & IndustrialAerospace & defense manufacturersEnterprises using Oracle PeopleSoft for HR/payrollVulnerability Exploit
What happened
The hacking group exploited a newly disclosed Oracle PeopleSoft vulnerability (CVE‑2026‑35273) to gain unauthorized access to data held by a Boeing‑spun‑off unit. The stolen data was used to extort the organization before the alleged gang leader was detained in Jordan.
Why it matters for trust and compliance
The breach underscores the need for a control‑assurance program that continuously monitors third‑party SaaS patch status and records remediation evidence, satisfying multiple framework requirements with a single control objective.
Continuous monitoring of vendor patch cycles provides real‑time evidence for audit readiness.
Documented due‑diligence on SaaS security posture creates a defensible audit trail across frameworks.
Who is affected
Aerospace & defense manufacturersEnterprises using Oracle PeopleSoft for HR/payroll
Recommended actions
Map the PeopleSoft patch‑management gap to your vendor‑risk control area and collect remediation evidence.
Integrate continuous third‑party risk assessments into your audit‑readiness workflow.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.