Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label CVE-2026-35273. Show all posts

Council of Europe Data Breach Exposes Records of 10000 Employees After ShinyHunters Leak


 

Council of Europe is investigating a major data breach following the public release of approximately 297 GB of sensitive employee data by cybercriminal group ShinyHunters following the expiration of a ransom deadline. 

An archive has been leaked that contains information regarding more than 10,000 current and former employees, contractors, and job applicants dating from 15 years ago. As one of Europe's leading human rights organizations since 1949, the Council of Europe has been an official observer at the United Nations since 1949. It represents 46 member states and is a central force in promoting democracy, human rights, and the rule of law throughout Europe. 

Since the information it holds is sensitive, the breach of confidentiality is particularly significant. As reported by ShinyHunters, more than 429,000 files, including personnel data, were obtained from multiple Council departments, including human resources and administrative units. This was one of the largest breaches of personal data involving an intergovernmental organization in Europe. 

Information available indicates that payroll records, bank account information, medical information, tax information, social security information, salary histories, personnel files, and thousands of CVs were exposed. Due to the large size of the dataset, identity theft, financial fraud, and highly targeted phishing are significantly more likely to occur. It has been reported that the breach is related to CVE-2026-35273, a critical 9.8-severity zero-day vulnerability affecting Oracle PeopleSoft's Environment Management Hub (PSEMHUB). 

According to security researchers, the vulnerability allowed attackers to execute arbitrary code remotely without authentication. According to Google's Mandiant team, more than 100 organizations had actively exploited the vulnerability prior to Oracle's release of security guidance. Using the zero-day vulnerability in combination with older vulnerabilities, ShinyHunters obtained persistent access, migrated laterally through compromised environments, and exfiltrated data while posing as legitimate users. 

The exploit was conducted between May 27 and June 9, before mitigations were available. ShinyHunters has also altered its extortion strategy significantly following the Council of Europe declining to meet the ransom demand. In response to the Council's refusal to pay the ransom, ShinyHunters announced it would permanently distribute stolen datasets through multiple mirror sites and torrent networks, thereby reducing the likelihood of future takedown efforts.

In addition, the incident adds to the growing number of campaigns involving ShinyHunterS Researchers have recently linked the group to attacks targeting multiple organizations, while Google's threat intelligence team has linked the group's latest activity to widespread exploitation of the Oracle PeopleSoft zero-day vulnerability before mitigations were available. 

According to a brief statement issued by the Council of Europe, the organization was "investigating the matter and assessing the situation." Further comment was not provided. The organization has not yet announced a formal notification process or measures to protect individuals' identities. Zero-day exploitation and data extortion campaigns are becoming increasingly prevalent, with public disclosure increasingly taking precedence over traditional ransomware encryption. 

The threat of persistent leak strategies is increasing, which is why organizations are being urged to strengthen vulnerability management, accelerate patch deployment, and improve incident response to minimize both institutions and individuals' long-term risks.

Nissan Americas Confirms Employee Data Breach After Oracle PeopleSoft Zero-Day Exploited by ShinyHunters

 

iNissan Americas has confirmed a cyberattack that resulted in a data breach affecting current and former employees across the United States, Canada, Mexico, and Brazil. The company said the breach occurred after cybercriminals exploited a critical zero-day flaw in Oracle PeopleSoft software. Security researchers have linked the campaign to the financially motivated hacking group ShinyHunters, also known as UNC6240 or Bling Libra.

The attack leveraged CVE-2026-35273, a critical vulnerability with a CVSS score of 9.8. The flaw exists in the Updates Environment Management (PSEMHUB) component of Oracle PeopleSoft PeopleTools versions 8.61 and 8.62. It allows attackers to move from an unauthenticated Server-Side Request Forgery (SSRF) attack to full Remote Code Execution (RCE) without requiring user interaction or authentication. Because the vulnerability can be exploited over standard HTTP, any exposed and unpatched server is at significant risk.

Oracle released an emergency security update on June 10, 2026, to address the flaw. Two days later, the vulnerability was added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation.

According to security researchers at Mandiant and Google’s Threat Intelligence Group (GTIG), the ShinyHunters group began exploiting the vulnerability as early as May 27, 2026—more than two weeks before Oracle publicly disclosed the issue. During that period, attackers reportedly compromised more than 300 Oracle PeopleSoft instances across over 100 organizations using automated attack tools.

Breach notifications submitted to the California Attorney General’s Office revealed that Nissan Americas was among the organizations impacted during the wider campaign. The company's investigation found that the intrusion occurred between May 27 and June 9, 2026.

The compromised information may include employee contact details, banking information, Social Security Numbers (SSN), Social Insurance Numbers (SIN), National Identification Numbers, financial and tax records, as well as dependent and beneficiary information. The incident affects both current and former employees in the U.S., Canada, Mexico, and Brazil.

Following the discovery of the breach, Nissan activated its incident response procedures, brought in external cybersecurity experts, and coordinated with law enforcement agencies. As part of its containment measures, the company limited payroll system access, allowing employees to view pay slips and modify direct deposit details only through corporate network computers or secure VPN connections. Additional identity verification measures have also been introduced for payroll-related requests. Nissan said it is providing complimentary credit monitoring and dark web monitoring services to eligible affected individuals.

Mandiant's investigation found that attackers installed MeshCentral remote management agents on compromised systems while disguising them as legitimate Microsoft Azure services, including meshagent64-azure-ops.exe. Command-and-control communications were routed through wss://azurenetfiles[.]net:443/agent.ashx.

The attackers also carried out post-compromise activities such as reviewing PeopleSoft configurations, moving laterally across networks, and compressing stolen data using zstd before exfiltration. Infected servers were left with a ransom note named README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.

Cybersecurity firms Rapid7 and Mandiant have urged organizations running Oracle PeopleTools 8.61 or 8.62 to immediately apply Oracle’s security updates. They also recommend disabling or restricting access to the PSEMHUB service, blocking external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector, monitoring outbound SMB traffic for potential NetNTLM hash capture attempts, investigating systems for signs of compromise even after patching, and rotating credentials that may have been exposed.

The incident represents the second major Oracle ERP zero-day vulnerability with a CVSS score of 9.8 to be actively exploited in less than eight months. It follows the exploitation of CVE-2025-61882 in Oracle E-Business Suite by the Cl0p ransomware group in 2025, highlighting the growing focus of organized cybercriminal groups on enterprise resource planning (ERP) platforms.