Oracle Shares Fell Amid PeopleSoft Hacking Attacks

The company's stock declined 2.76% as security researchers reported renewed exploitation of unpatched PeopleSoft systems.

Updated on Sept. 28, 2026 in Cybersecurity

Modern server rack cabinets arranged in a repeating industrial data center aisle with status lights.
Oracle shares fell 2.76% to $133.31 on Monday as security researchers reported renewed exploitation of unpatched vulnerabilities in the PeopleSoft platform. AI Illustration. Upload story photo >

Live Poll

Do you believe current market conditions make now a good time to invest in technology stocks?

Oracle shares dropped to $133.31 on Monday, marking a 10.8% decline over the past week as the hacking group ShinyHunters reportedly renewed large-scale attacks on the PeopleSoft platform. The campaign specifically targets organizations that updated firewall configurations but failed to install Oracle's designated security patches.

Why it matters

The security vulnerability creates company-specific pressure, compounding broader market concerns as rising Treasury yields and oil prices weaken investor sentiment toward growth-oriented technology stocks. This intersection of operational risk and macroeconomic headwinds has placed significant volatility on Oracle’s valuation in recent trading sessions.

Oracle shares closed at $133.31 on Monday, representing a 2.76% drop that contributes to a 10.8% decline over the past week. The volatility coincides with broader market shifts, including a five-year Treasury yield rise of 7 basis points to 5.06% and Brent crude reaching approximately $108 a barrel.

The players

Oracle

An enterprise software and cloud computing company known for its database management systems and enterprise resource planning software like PeopleSoft.

ShinyHunters

A hacking collective known for executing large-scale data exfiltration attacks and targeting enterprise software vulnerabilities.

Google

A global technology firm and owner of the Mandiant unit, which provides threat intelligence and specialized cybersecurity services.

The details

The attacks involve ShinyHunters exploiting known vulnerabilities in the PeopleSoft platform—a suite of enterprise software for human capital and financial management—by targeting systems where firewall rules were updated without applying the necessary security patches. By bypassing perimeter defenses, attackers leverage these unpatched entry points to gain unauthorized access to institutional environments. The mechanism relies on the gap between administrative firewall changes and the completion of patch deployment across legacy enterprise modules.

Timeline

  1. July saw core PCE inflation rise 3.3% year-over-year.

  2. Monday marked the 2.76% decline in Oracle share prices.

  3. Wednesday is the scheduled release date for the latest PCE inflation report.

The Tech Race

This activity follows the pattern of the Log4j vulnerability disclosure, where attackers targeted organizations that failed to update dependencies despite the availability of fixes. It highlights the ongoing struggle for IT teams to maintain security parity with persistent threat actors targeting enterprise infrastructure.

Organizations running Oracle PeopleSoft must verify that their security patches are applied, as updating firewall rules alone does not protect against these ongoing exploitation attempts. While the immediate financial impact is reflected in stock performance, the operational risk remains for any entity that has not completed the required patch deployment.

What happens next

Investors and IT administrators should monitor the PCE inflation report scheduled for release this Wednesday, which is expected to influence broader technology sector performance.

Further reading

For more on evolving threat landscapes, visit Cybersecurity.

Live Poll

Do you believe current market conditions make now a good time to invest in technology stocks?