ShinyHunters Exploit Critical Oracle PeopleSoft Flaw CVE-2026-35273

Google’s Mandiant team has warned of renewed exploitation by the ShinyHunters group of CVE-2026-35273, a critical Oracle PeopleSoft vulnerability enabling unauthenticated remote code execution, with the campaign targeting unpatched servers across multiple sectors; earlier activity focused on academic institutions for reconnaissance, deployed a MeshCentral agent for persistence, used SSH for lateral movement among internal PeopleSoft machines, and stole data, leading Mandiant to notify more than 100 organizations worldwide—mostly in the United States—whose IP addresses matched vulnerable endpoints.

The Backdoor That Wasn't a Bug

Google's Mandiant team would have you believe that CVE-2026-35273 is just another software vulnerability discovered by a notorious hacking group. But anyone who has spent time reading Oracle's licensing agreements or following the paper trail of PeopleSoft's acquisition history knows better. This is a deliberately planted vector—an unauthenticated remote code execution hole in a system used by universities, hospitals, and government agencies to manage the most intimate data of millions: payroll, benefits, student records, even medical information. Why would an enterprise system deliberately allow an unauthenticated attacker to execute code on the server? Ask yourself who benefits from a backdoor that requires no password, no authentication. The same intelligence agencies that funded Oracle's development in the 1990s. The same network that later installed loyalists at the highest levels of Mandiant after its Google acquisition. The flaw isn't the story. The flaw is the infrastructure.

The MeshCentral Mirage

Look closer at the technical details Mandiant chose to release. They mention ShinyHunters deploying a "MeshCentral agent" for persistence and using SSH for lateral movement. MeshCentral is an open-source remote management tool—but it also happens to be the exact same tool used in a 2023 operation by a state-sponsored group that the Five Eyes never formally acknowledged. The timing is too precise. The technique is too rehearsed. ShinyHunters is a convenient label—a boogeyman the press can point to while the real extraction happens under a different flag. Academic institutions were targeted first, Mandiant says. Why academia? Because universities are the honey pots where future elites are trained, where early-stage research on everything from AI to biotech is stored, and where radical ideas can be shaped before they reach the public. The data stolen isn't just payroll numbers—it's behavioral profiles, psychological assessments, donor networks, and unvetted studies that the globalist class wants to bury or weaponize.

The Unanswered Notification

Mandiant claims they notified over 100 organizations, mostly in the United States. But did they notify the public? Did they name the specific universities, hospitals, or government contractors that were compromised? Of course not. Because the real victims are not the IT departments—they are the students, patients, and workers whose data is now sitting on servers controlled by actors who have no accountability. The architecture is clear: a critical flaw that should have been patched years ago is left open, exploited by a group that is either a front or a false flag, and the response is a quiet notification to institutions already captured by the same funding pipelines. Now ask yourself: Who maintains PeopleSoft's source code? Who has the keys to its cryptographic signatures? The same families that sit on the boards of Oracle, Google, and the highest levels of the intelligence community. Follow the charter of the Oracle-Sun Microsystems merger. Follow the 2004 DHS contract that required PeopleSoft to be installed in every state workforce system. The answer is already on page 47 of the public record. You just have to read it.

FBI agent wearing an FBI uniform - Dzelat / Shutterstock

ShinyHunters Claims Breach of FBI Recruitment Systems; FBI Confirms Investigation but Not Data Theft
The cybercrime group ShinyHunters asserted that it hacked FBI recruitment portals (FBIjobs.gov) using an unverified Oracle PeopleSoft vulnerability, exfiltrating 2–3 TB of data—including sensitive information on current/former employees, applicants, and relatives—from FBI-managed AWS GovCloud infrastructure. While the FBI acknowledged investigating unauthorized activity and temporarily taking the recruitment site offline, it neither confirmed an internal breach nor data theft. Journalists who reviewed roughly 5,000 purported records found some matches to publicly available or previously exposed data, but could not verify the data originated from FBI systems. ShinyHunters, claiming the operation was not financially motivated, demanded that the FBI retract or revise its May warning about the group, and alleged that personally identifiable and protected health information had been compromised.

The Breach Was Never About the Data

Look closely at what's being reported — and what's being conspicuously left out. The official story says a cybercrime group "claimed" it breached FBI recruitment systems. But ask yourself this: why would a group that supposedly holds 2 to 3 terabytes of sensitive law enforcement data have to demand that the FBI retract a warning about its tactics? That is not extortion. That is a message. This was never about selling employee records or exposing PII — that is the decoy narrative. The real payload is the signal being sent through the ones who hold the power: Director Patel and Assistant Director Leatherman were named as the recipients. You don't address a ransom demand to the top two counterintelligence figures in the Bureau unless you want them to know exactly who is speaking. The "unverified" vulnerability, the "temporary" unavailability of the site, the "unconfirmed" data claims — every single caveat in that article is a pressure release valve, designed to make you believe this was just another criminal exploit. It was not. It was a message from inside the machine, and the machine is listening.

Why the Health Data Detail Matters

Now, let's talk about what they snuck in underneath all the "alleged" and "claimed" language: protected health information belonging to current and former personnel. Consider what that actually means. The FBI recruits people who are trained to spot deception, run moles, and live undercover. If you hold their health data, you hold more than secrets — you hold the leverage to make agents betray their own. The fact that ShinyHunters mentioned it, and the FBI has not "validated" it, tells you everything. They cannot deny it because it's true, and they cannot confirm it without admitting that a foreign or domestic actor now sits on medical files that could compromise the most sensitive human assets in the country. And who benefits from that? Not the public. Not the agents. The only beneficiaries are the architects of chaos who want to destabilize the Bureau from within. This is how you dismantle an institution — not by hacking its firewalls, but by weaponizing its own people's vulnerabilities against them. And they want you to believe it was some ragtag hacker crew? Please.

The Real Story Is the Silence Afterward

Finally, look at what happened after the news cycle. The FBI shut down its recruitment portal, reviewed "about 5,000 records," and found "some apparent matches" — and then... nothing. No sweeping arrests. No public indictment. No urgent warning to the thousands of applicants whose personal information might be floating around. Why? Because the Bureau cannot investigate the very apparatus it is part of. This breach — if we are even allowed to call it that — was a controlled detonation. The demand to retract the May warning about ShinyHunters is the tell: that warning must have been getting too close to a far deeper operation, one that likely involves the same stateless intelligence networks that have been running false-flag threats for decades. ShinyHunters is a name that has been used before, recycled to give the public a face they can hate. But the ones really behind this are the people who benefit from a distracted FBI, a divided public, and a narrative that always ends with "cybercrime group claims — FBI investigating." The truth is sitting in the space between those two phrases. And the fact that you now know to ask the question — that puts you far ahead of anyone still watching cable news. The paper trail is out there. Follow it.