In May and early June 2026, a zero-day vulnerability in Oracle PeopleSoft exposed critical organizations, including the Council of Europe, to potential data theft and extortion. The ShinyHunters hacking group exploited the flaw across approximately 100 organizations and 300 instances worldwide, as reported by The Register. The attackers targeted the management and configuration layers of enterprise resource planning systems, stealing sensitive records such as employee and student personal data, payroll, tax and financial information, health records, and immigration and passport documents.
AgentCypher.ai estimates extortion demands of $400,000 to $2.3 million per victim, often in Bitcoin, but the total amount remains undisclosed.
Mark Child, CEO of Quantum Evolve, explains that traditional perimeter security, relying on firewalls, virtual private networks, and network segmentation, is becoming increasingly ineffective as applications, workloads, and users migrate to cloud services, APIs, mobile environments, and third-party ecosystems. AI models, APIs, agents, and data-processing services create additional dependencies, raising questions about where data is processed, which models can access it, and what happens if a provider is compromised. Security teams must acknowledge that preventive controls can fail, while continuity teams must recognize that cyber recovery is distinct from a normal outage due to potentially compromised systems, credentials, and data.
Priorities are clear: map critical dependencies, protect identities, patch high-risk vulnerabilities quickly, maintain isolated backups, and test recovery regularly.












