They Didn't Lock the Doors — They Took the Filing Cabinets
Two weeks ago, the cybercriminal group ShinyHunters announced they had breached more than 100 organizations — most of them universities — by exploiting a single zero-day vulnerability in Oracle PeopleSoft. The University of Nottingham alone lost 454,600 student records. Names, addresses, passport numbers, disability status, academic records, financial details. All of it published online before most victims knew they had been hit.
If you sit on a board or run an organization that relies on enterprise software you didn't build, this story should keep you up at night. Not because of the technical details, but because of what it reveals about where your real risk lives.
One Vulnerability, 300 Systems, Zero Warning
The vulnerability — CVE-2026-35273 — carried a severity score of 9.8 out of 10. It required no login credentials and no user interaction. An attacker just needed network access over HTTP to take over the server. Oracle PeopleSoft is the student information system behind roughly 10 percent of the North American higher education market, running on hundreds of campuses.
ShinyHunters exploited this flaw between May 27 and June 9. Oracle didn't publish its advisory until June 10 — meaning every affected organization was exposed for nearly two weeks with no patch available and no warning from the vendor. Mandiant, Google's threat intelligence arm, confirmed the timeline and notified more than 100 organizations whose systems matched vulnerable endpoints. Sixty-eight percent were in higher education.
This wasn't a sophisticated, months-long infiltration. The attack script spread over SSH by spraying a list of default usernames and passwords against internal hosts. Data was compressed and exfiltrated to servers hosting the ShinyHunters leak site. The whole operation was industrialized — automated, repeatable, and fast.
They Didn't Even Bother Encrypting Anything
Here's the part that should reframe how your organization thinks about cyber risk: ShinyHunters didn't deploy ransomware. They didn't lock anyone out of their systems. They just took the data and threatened to publish it.
This is the new reality of cyber extortion in 2026. Across the threat landscape, groups are abandoning encryption entirely. They steal your data, contact you, and say: pay us or we publish everything. In 2025, only 28 percent of ransomware victims paid the ransom. Attackers noticed. Why go through the technical complexity of encrypting systems — which triggers endpoint detection tools and backup recovery procedures — when you can just quietly exfiltrate files and apply pressure through exposure?
For executives and board members, this shift matters enormously. Your incident response playbook probably centers on "can we restore operations from backups?" That question is irrelevant when the attacker never disrupted operations. Your systems kept running. Your students kept logging in. And meanwhile, what ShinyHunters claims was over 40 gigabytes of their most sensitive personal information was being uploaded to a criminal server.
The Three Questions That Should Have Been Asked
In Cyber Risk Is Business Risk, I lay out a framework built around three questions every executive should ask about their organization's cybersecurity posture. The ShinyHunters campaign is a case study in what happens when those questions go unasked.
What are we protecting? Universities hold student data that in many cases is more sensitive than what a typical corporation handles — passport numbers, disability status, ethnicity, financial aid details. This isn't just PII. It's information that can be weaponized for identity theft, discrimination, and targeted fraud. If your organization holds data this sensitive, your board needs to know exactly where it lives and who can access it.
Who is responsible? Oracle built PeopleSoft. But when it was breached, it was the universities — not Oracle — that had to notify students, face regulatory scrutiny, and manage the reputational fallout. Third-party software doesn't mean third-party liability. The organization that holds the data owns the risk, full stop.
Are we ready when — not if — something goes wrong? Two weeks of zero-day exposure. That's 14 days where no patch existed, no vendor advisory had been issued, and the only defense was whether your organization had compensating controls in place — network segmentation, monitoring for unusual data movement, restricting outbound traffic from database servers. Most of the victims didn't.
What to Ask Your CISO This Week
If your organization runs enterprise software from a major vendor — and it almost certainly does — here are the conversations that need to happen now:
Do we know our crown jewels, and do we know which vendor systems touch them? Not at a high level. Specifically. Which databases hold your most sensitive records, and what third-party platforms have access?
What is our detection posture for data exfiltration? If someone compressed tens of gigabytes of student records and uploaded them to an external server, would your security team see it? Many organizations can detect malware and ransomware deployment. Far fewer can detect large-scale data theft in progress.
What does our vendor management program actually verify? Not what the contract says. What your team actually tests. Do you validate that vendor-supplied systems are patched within your risk tolerance? Do you have compensating controls for the gap between vulnerability disclosure and patch deployment?
Have we stress-tested our incident response plan against a data-theft-only scenario? If your tabletop exercises assume systems go down, they aren't preparing you for the attack that leaves everything running while your data walks out the door.
The Uncomfortable Truth
The ShinyHunters campaign didn't succeed because universities are uniquely bad at security. It succeeded because the attack exploited a pattern that is universal: organizations trust the software they buy, they assume the vendor is handling security, and they focus their defenses on the threats they've seen before rather than the ones that are emerging now.
That gap — between where organizations look for threats and where threats now arrive — is the defining risk of 2026. Closing it starts in the boardroom, not the server room.