Oracle has alerted customers to a critical vulnerability in PeopleSoft after the hacking group ShinyHunters claimed to have breached more than 100 organisations running the decades-old enterprise software. Affected companies were urged to patch immediately, but the bigger story here is not the patch itself, it is why so many large organisations are still running PeopleSoft in the first place.
PeopleSoft, Oracle's human resources and finance management platform, dates back to the 1980s and was acquired by Oracle in 2005. Software that old rarely makes headlines unless something goes badly wrong, which is exactly what happened here.
Why enterprise software this old is still everywhere
Large organisations, particularly government agencies, universities and big corporations, tend to keep core administrative systems running for decades because replacing them is expensive, disruptive and risky. Payroll, HR and financial data live inside these systems, and migrating that data to newer platforms carries its own security and continuity risks. The result is that software originally built for a pre-cloud, pre-smartphone world often keeps running quietly in the background of institutions that most people would assume run on modern infrastructure.
ShinyHunters, a hacking group with a long track record of large-scale data theft rather than ransomware-style disruption, appears to have exploited exactly this gap. Old software accumulates unpatched vulnerabilities over years, and attackers who specialise in data theft have every incentive to find and exploit them before defenders catch up.
What ShinyHunters typically does with stolen data
ShinyHunters has historically monetised breaches by selling stolen databases on underground forums or using stolen credentials for follow-on attacks like credential stuffing against other services. A breach spanning 100 or more organisations running PeopleSoft could expose sensitive HR and financial records at a scale that plays out over months, since stolen data of this kind tends to surface gradually on criminal marketplaces rather than all at once.
"Affected companies were urged to patch immediately," Oracle said in its customer alert.
What this means for India
Indian organisations are not immune to this exposure. PeopleSoft has a long installed base among Indian public sector undertakings, universities and large enterprises that adopted it during earlier decades of IT modernisation and have not fully migrated away since. Any organisation running PeopleSoft in India should treat Oracle's patch notice as urgent rather than routine, particularly given how attractive Indian HR and payroll databases are to data-theft groups given the country's scale.
The incident is also a useful reminder for India's broader digital infrastructure push. As government offices and public institutions continue digitising records under various e-governance initiatives, the temptation is often to bolt new services onto existing legacy systems rather than fully replacing them, extending the lifespan of software that was never designed with today's threat landscape in mind. This breach is a preview of what happens when that trade-off goes wrong.
What this means for you
If your organisation runs PeopleSoft in any capacity, the practical step is straightforward: confirm with your IT or vendor management team that Oracle's patch has been applied, and ask whether your organisation has checked for signs of prior compromise rather than assuming the patch alone resolves the exposure. If you work at an organisation that has never disclosed whether it uses PeopleSoft, it is worth asking directly, since payroll and HR systems are rarely visible to most employees until something goes wrong with them.
What to watch
The number of confirmed affected organisations will likely grow as more institutions audit their systems and disclose findings, a pattern common to ShinyHunters-linked breaches. Watch for whether any Indian institutions appear on breach disclosure lists in the coming weeks, and whether Oracle releases further guidance beyond the initial patch for organisations that may have already been compromised before patching.
Published July 25, 2026. Gadgets365 will update this article as more information becomes available.