ShinyHunters Strike Again (and Again)

In last month’s newsletter, we covered the ShinyHunters cybercrime group and their role in the widespread Canvas breach. Fortunately, FIT was not impacted but unfortunately, the situation has only escalated. In recent weeks, ShinyHunters has claimed three additional major victims: Oracle PeopleSoft, a platform widely used across higher education; Kodak, a major New York–based technology company; and Madison Square Garden Entertainment, breached just as the Knicks celebrated their championship win. While the city was celebrating, ShinyHunters was already posting samples of MSG’s internal data online and attempting to sell the full dataset. Read more about that here. 

The PeopleSoft breach is especially concerning for colleges and universities. Mandiant and Google Threat Intelligence confirmed that ShinyHunters exploited a vulnerability that required no login and no user interaction, allowing attackers to take over exposed PeopleSoft servers across more than 100 organizations, 68% of which were universities. Read more about that here. Another major method the threat group uses is voice‑phishing (vishing), where attackers impersonate IT staff to steal SSO credentials and intercept MFA codes using adversary‑in‑the‑middle tools. This technique has been repeatedly linked to the group’s broader extortion operations. Higher education remains one of ShinyHunters’ most attractive sectors. Colleges hold vast amounts of sensitive information like student identities, HR records, financial data, research materials, and donor information.  Employees play a critical role in reducing institutional risk. 

How to Stay Safe

  • Be skeptical of unexpected calls or emails claiming to be IT support. 
  • Use multi‑factor authentication everywhere it’s offered. 
  • Watch for unusual login prompts or system behavior.
  • If you suspect a phishing email or any other cyber threat, contact Cybersafe.

 

ShinyHunters’ recent activity is a reminder that cybersecurity threats are evolving quickly and increasingly targeting institutions like ours. Staying vigilant, following best practices, and reporting concerns promptly helps protect not only your own work but the entire college community.