What Happened: ShinyHunters Breach Oracle PeopleSoft at Scale
In the first two weeks of June 2026, the ShinyHunters cybercrime group executed a coordinated campaign against Oracle PeopleSoft servers exposed to the internet. The group exploited known but unpatched vulnerabilities in PeopleSoft Internet Architecture (PIA) and PeopleTools components to gain initial access, then moved laterally through PeopleSoft application servers to reach backend Oracle databases containing HR records, payroll data, financial transactions, and personally identifiable information of hundreds of thousands of employees.
Oracle published a security advisory on June 10, 2026, confirming that more than 100 organisations across finance, government, healthcare, aviation, and energy sectors had been compromised. The advisory detailed the specific CVEs exploited, provided indicators of compromise, and urged all PeopleSoft customers to apply the June 2026 Critical Patch Update immediately. Oracle also recommended a full forensic review of PeopleSoft environments dating back to April 2026, when preliminary reconnaissance by ShinyHunters is believed to have begun.
This is not ShinyHunters' first enterprise software campaign. The group rose to prominence with large-scale breaches of Microsoft GitHub, Tokopedia, and Wattpad starting in 2020. In 2024, they orchestrated the Snowflake customer data theft campaign that affected 165 organisations, including AT&T, Ticketmaster, and Santander Bank. In early 2025, they pivoted to Salesforce environments. The PeopleSoft campaign in June 2026 represents an escalation to on-premise enterprise resource planning systems, a category of software that many organisations assumed was less exposed than cloud SaaS platforms.
The uncomfortable truth is that PeopleSoft servers are often the least-patched systems in enterprise IT. They run critical HR and financial processes that make downtime expensive, so patching gets deferred. Many PeopleSoft instances still run on older versions of PeopleTools with known vulnerabilities that have had patches available for months or years. ShinyHunters recognised this gap and exploited it methodically.
💡 Expert Take
ShinyHunters went after PeopleSoft because the group understands enterprise patching reality better than most CISOs want to admit. ERP systems are the last to get patched and the first to hold sensitive data. In the UAE, where PeopleSoft runs payroll for some of the largest employers in the country, this breach should be treated as a board-level incident, not an IT operations ticket.
The Compounding Factor: Microsoft's Record-Breaking June 2026 Patch Tuesday
The ShinyHunters PeopleSoft campaign did not happen in a vacuum. On June 11, 2026, one day after Oracle's advisory, Microsoft released the largest Patch Tuesday in the company's history: 200 vulnerabilities, including 33 rated Critical and 6 actively exploited zero-days. The zero-days affected Windows kernel components, Microsoft Office, and Azure Active Directory, meaning they touched virtually every enterprise environment on the planet.
For UAE security teams, June 2026 became a two-front war. On one side, they needed to assess whether their PeopleSoft environments had been compromised by ShinyHunters and apply the Oracle Critical Patch Update. On the other side, they needed to triage and deploy 200 Microsoft patches, prioritising the six zero-days that were already being exploited in the wild. The security operations centres at UAE banks, government entities, and large enterprises were overwhelmed. Staffing gaps that were manageable in Q1 2026 became critical overnight.
💡 Expert Take
The convergence of the PeopleSoft breach and the largest Patch Tuesday ever in the same week is the kind of scenario that exposes whether your security team is properly staffed or running on adrenaline. Most UAE security operations centres I have spoken with this month are running on adrenaline. That is not sustainable, and it is driving the fastest hiring surge I have seen in the Dubai security market since the pandemic.
Why the UAE Is Particularly Exposed to the PeopleSoft Breach
Oracle PeopleSoft has deep roots in the UAE enterprise landscape. It was the dominant HR and payroll platform for large UAE organisations through the 2000s and 2010s, and while many companies have migrated to Oracle Cloud HCM or Workday, a substantial installed base remains. PeopleSoft continues to run HR, payroll, and financial management at several UAE federal government agencies, two of the five largest UAE banks, at least three major real estate development groups, two UAE-based airlines, and multiple oil and gas operators.
The data held in these PeopleSoft systems is extraordinarily sensitive in the UAE context. Payroll data includes salary details, bank account numbers, Emirates ID numbers, and visa status for expatriate employees. HR records contain performance reviews, disciplinary actions, and in some cases medical leave histories. Financial modules hold accounts payable and receivable data, vendor payment details, and budget allocations. A breach of this data in the UAE has implications under the UAE Data Protection Law (Federal Decree-Law No. 45 of 2021), which requires controllers to notify the UAE Data Office and affected individuals without unreasonable delay.
The UAE Cyber Security Council issued guidance on June 12, 2026, two days after Oracle's advisory, urging all UAE organisations running PeopleSoft to apply the Critical Patch Update immediately, conduct a forensic review of their PeopleSoft environments for indicators of compromise, and prepare breach notification materials if employee data may have been affected. The Central Bank of the UAE followed with a notice to licensed financial institutions on June 13, requiring confirmation of remediation status within seven business days.
ShinyHunters' Enterprise Breach Pattern: From Snowflake to PeopleSoft
Understanding ShinyHunters' evolution explains why the PeopleSoft campaign was inevitable. The group has followed a clear progression in targeting enterprise software:
| Year | Target Platform | Victims | Data Type | Attack Vector |
|---|---|---|---|---|
| 2020 | GitHub / SaaS APIs | Microsoft, Tokopedia, Wattpad | Source code, user credentials | Credential stuffing, API abuse |
| 2024 | Snowflake | AT&T, Ticketmaster, Santander (165 total) | Customer records, financial data | Stolen credentials, no MFA |
| 2025 | Salesforce | Multiple enterprises | CRM data, customer PII | OAuth token theft, session hijacking |
| 2026 | Oracle PeopleSoft | 100+ orgs across sectors | HR, payroll, financial, employee PII | Unpatched CVEs, internet-facing PIA |
The pattern is clear. ShinyHunters identifies enterprise software platforms where organisations are slow to patch or where basic security hygiene like multi-factor authentication is not enforced. They then execute at scale, hitting dozens or hundreds of organisations in a compressed timeframe before defenders can coordinate a response. Each campaign has been larger and more damaging than the last.
The pivot to PeopleSoft is particularly concerning because it represents a move from cloud-hosted platforms, where the vendor controls infrastructure and can force patching, to on-premise systems where the customer is entirely responsible for patching. Oracle provides patches. Oracle cannot force customers to apply them. And as every Oracle DBA knows, applying Critical Patch Updates to PeopleSoft environments requires extensive testing against custom PeopleCode, integrations, and bolt-on applications. That testing takes weeks, sometimes months. ShinyHunters exploited that gap.
💡 Expert Take
Every ShinyHunters campaign teaches the same lesson: enterprise software that you are not actively patching is enterprise software that someone else is actively exploiting. The move from Snowflake to PeopleSoft shows the group is expanding from cloud SaaS to on-prem ERP. That should alarm every UAE CISO running SAP, Oracle E-Business Suite, or any legacy enterprise platform. You are on the target list. It is a question of when, not if.
The Dubai Security Engineer Hiring Surge: Numbers and Context
The HireDeveloper.ae security hiring pipeline has tracked a 35 to 40 percent increase in new security engineering requisitions from UAE employers between April and June 2026. This is the steepest quarterly acceleration since we began tracking the market in 2023. The surge is not driven by a single event. It is the cumulative effect of the ShinyHunters PeopleSoft breach, the record Microsoft Patch Tuesday, the Cisco Webex CVE-2026-20184 SSO bypass in April, and an increasingly demanding regulatory environment from the UAE Cyber Security Council and Central Bank of the UAE.
The roles in highest demand are not generic security analysts. UAE employers are hiring specialists:
- Application security engineers with Oracle ERP experience, specifically PeopleSoft, E-Business Suite, and Oracle Cloud. These engineers can assess PeopleCode custom code for vulnerabilities, harden PeopleSoft Internet Architecture configurations, and build security monitoring for Oracle application layers.
- ERP security specialists who understand PeopleSoft security architecture: row-level security, permission lists, roles, and integration broker configurations. These are rare profiles, and UAE employers are recruiting globally.
- Detection engineers who can build and tune SIEM detection rules specifically for ERP telemetry. Most SOC playbooks do not include ERP-specific detection. After ShinyHunters, they need to.
- Incident responders with enterprise software forensics capability. Investigating a PeopleSoft breach requires understanding Oracle database forensics, PeopleSoft audit logging, and web server log analysis for PIA components.
- Vulnerability management engineers to run continuous patching programmes for complex enterprise software environments. The reactive, quarterly patching approach has failed. Continuous vulnerability management is now the expectation.
June 2026 Dubai Security Engineer Salary Benchmarks
| Role | Mid (3-5 yrs) | Senior (6-9 yrs) | Staff/Principal |
|---|---|---|---|
| Application security engineer (Oracle) | AED 30,000-45,000 | AED 50,000-72,000 | AED 75,000-105,000 |
| ERP security specialist (PeopleSoft) | AED 32,000-48,000 | AED 52,000-75,000 | AED 78,000-110,000 |
| Detection engineer (SIEM / ERP) | AED 28,000-40,000 | AED 44,000-62,000 | AED 65,000-88,000 |
| Incident responder / DFIR | AED 30,000-44,000 | AED 48,000-68,000 | AED 70,000-95,000 |
| Vulnerability management engineer | AED 26,000-38,000 | AED 40,000-58,000 | AED 60,000-82,000 |
All figures are monthly, tax-free under UAE law. Candidates with direct ShinyHunters incident response experience or Oracle PeopleSoft security certifications are commanding a 15 to 20 percent premium over these benchmarks. Senior ERP security specialists are the single most difficult profile to source in the UAE market right now, with typical time-to-fill exceeding 12 weeks.
Need Security Engineers After the PeopleSoft Breach?
HireDeveloper.ae runs a dedicated UAE cybersecurity hiring desk. We place application security, ERP security, detection, and incident response engineers in Dubai and Abu Dhabi. Fractional contractors available within 10 days for active breach response.
Start Hiring →Immediate Response Playbook for UAE PeopleSoft Operators
Based on conversations with six UAE CISOs and three Oracle security consultants between June 12 and June 22, the following response playbook has emerged as the consensus approach for UAE organisations running PeopleSoft:
- Day 1 to 3: Apply the Oracle June 2026 Critical Patch Update to all PeopleSoft environments, starting with production. Test against critical PeopleCode customisations first. Do not wait for a full regression cycle. The risk of exploitation exceeds the risk of a minor regression.
- Day 1 to 3 (parallel): Network isolation. Restrict PeopleSoft Internet Architecture access to known IP ranges. If your PIA is exposed to the open internet, take it behind a VPN or zero-trust access broker immediately. This should have been done years ago.
- Day 3 to 7: Forensic review. Review PeopleSoft audit logs, Oracle database audit trails, and web server logs for the PIA tier from April 1, 2026 onwards. Look for unusual queries against HR and payroll tables, new user accounts or elevated privileges, and data export activity.
- Day 7 to 14: Indicator of compromise sweep. Cross-reference Oracle's published indicators of compromise against your environment. Engage a qualified incident responder if anomalies are found.
- Day 14 to 30: Regulatory notification. If employee data may have been exfiltrated, prepare notifications under the UAE Data Protection Law. Notify the UAE Data Office, affected individuals, and sector regulators as required.
- Day 30 to 90: Structural remediation. Implement continuous vulnerability management for PeopleSoft. Harden PIA configurations per Oracle's security hardening checklist. Deploy application-layer monitoring and alerting. Consider accelerating your Oracle Cloud HCM migration if one is planned.
How UAE Employers Can Win the Security Hiring Race
The security engineers you need right now are in demand everywhere. Every UAE bank, government entity, and large enterprise is competing for the same profiles. Here is how to differentiate your offer and close candidates faster:
Lead with the mission, not just the compensation. Security engineers are motivated by high-impact work. Responding to an active ShinyHunters breach, hardening a PeopleSoft environment that serves 50,000 employees, building detection capability for ERP systems from scratch: these are genuinely compelling engineering problems. Make them the centrepiece of your pitch.
Use the full UAE immigration toolkit. Golden Visa sponsorship for senior hires and Green Visa for mid-level talent materially improve your competitiveness against offers from Singapore, London, and the US. A ten-year residency visa attached to a security engineering role is a powerful differentiator that most competing markets cannot match.
Hire fractional contractors first, permanent staff second. The PeopleSoft breach demands immediate response capability. A senior application security contractor can be onboarded in 7 to 10 days and absorb 70 percent of the incident response workload while you run a permanent search. At HireDeveloper.ae, our security engineer bench includes Oracle ERP specialists available on 10-day notice.
Compress your hiring timeline. The employers closing security engineers in under four weeks are running three-stage interview processes: one technical screen, one system design session focused on ERP security architecture, and one final with the CISO. Four stages or more is losing candidates to faster-moving competitors.
💡 Expert Take
I keep telling UAE CISOs the same thing: the security engineer you did not hire in May is not available in July. This market moves in one direction. After the PeopleSoft breach and the record Patch Tuesday, every qualified ERP security specialist and application security engineer in the region has three to five active conversations. If your process takes eight weeks, you are not in the race. You are watching it.
90-Day Security Hiring Plan for Post-Breach UAE Teams
A practical 90-day hiring plan for UAE organisations responding to the ShinyHunters PeopleSoft breach:
Days 1 to 30: Stabilise with contractors. Bring in one to two fractional senior security engineers with Oracle ERP and incident response experience. Deploy them immediately on forensic review, patch validation, and PIA hardening. In parallel, define the two to three permanent roles you need, not the six you would like. Focus on application security engineer, detection engineer, and vulnerability management engineer as the core triad.
Days 30 to 60: Run an intentional permanent search. Source through warm introductions via the UAE security community, Gulf Information Security Expo and Conference alumni networks, and the HireDeveloper.ae security pipeline. Keep interviews to three stages. Close offers within seven days of final interview. Use Golden Visa as a differentiator.
Days 60 to 90: Onboard, retain, build. Convert contractors to permanent where appropriate. Onboard permanent hires with a structured 30-60-90 plan focused on building sustainable ERP security capability, not just firefighting. Invest in retention: certification budgets for OSCP, Oracle Security certifications, and SANS ERP security training. Set written promotion criteria and a hybrid-work policy.
Teams that follow this rhythm are signing permanent hires by September 2026. Teams that do not are still screening in November, by which point the next enterprise software CVE has pushed rates up another cycle.
Frequently Asked Questions
What happened in the ShinyHunters Oracle PeopleSoft attack?▼
In June 2026, the ShinyHunters cybercrime group compromised Oracle PeopleSoft servers at more than 100 organisations worldwide by exploiting known but unpatched vulnerabilities in PeopleSoft Internet Architecture and PeopleTools. The group exfiltrated HR records, payroll data, financial transactions, and employee PII. Oracle published a security advisory on June 10, 2026 confirming the campaign and providing remediation guidance. ShinyHunters followed the same playbook used in their 2024 Snowflake campaign and 2025 Salesforce campaign, targeting enterprise software where patching is slow and security monitoring is thin.
Are UAE companies affected by the PeopleSoft breach?▼
Yes. Oracle PeopleSoft is deployed at multiple UAE banks, federal government agencies, real estate developers, airlines, and oil and gas operators for HR, payroll, and financial management. The UAE Cyber Security Council issued guidance on June 12, 2026 urging all PeopleSoft operators to patch immediately and conduct forensic reviews. The Central Bank of the UAE followed with a notice to licensed financial institutions on June 13, requiring remediation confirmation within seven business days.
Why is Dubai seeing a security engineer hiring surge in June 2026?▼
The convergence of the ShinyHunters PeopleSoft breach, Microsoft's record-breaking June 2026 Patch Tuesday with 200 vulnerabilities and 6 zero-days, and tightening UAE regulatory expectations has created a 35 to 40 percent quarter-over-quarter increase in security engineering requisitions from UAE employers. Application security engineers, ERP security specialists, and incident responders are the most in-demand profiles, with senior salaries up 15 to 20 percent year-over-year.
What security roles should UAE companies hire after the PeopleSoft breach?▼
The five highest-priority roles are: (1) application security engineers with Oracle ERP experience, (2) ERP security specialists who understand PeopleSoft architecture, PeopleCode, and permission models, (3) detection engineers who can build SIEM rules for ERP telemetry, (4) incident responders with enterprise software forensics capability, and (5) vulnerability management engineers to run continuous patching programmes. Senior candidates with Oracle security experience command AED 50,000 to 75,000 per month in Dubai, tax-free.
Related Reading
For deeper context on the broader UAE security hiring landscape and related enterprise software security topics, see these resources:
- Cisco Webex CVE-2026-20184: UAE Security Engineer Hiring Playbook - the April 2026 SSO bypass that began the current security hiring acceleration.
- Hire Security Engineers in Dubai - our vetted security engineer bench, including Oracle ERP specialists available on 10-day notice.
- Oracle Security Alerts - official Oracle security advisories and Critical Patch Updates.
Partner with HireDeveloper.ae
We close senior UAE security hires in under 21 days. Dedicated cybersecurity desk, Oracle ERP security specialists on our bench, Golden Visa support, fractional contractors for active breach response, and post-hire retention tracking.
Book a Hiring Consult →