Major HR system hacked again as criminals slip past earlier fixes

ShinyHunters is back inside Oracle PeopleSoft, the software that runs payroll and personnel records for thousands of employers, Google's security team warns

Major HR system hacked again as criminals slip past earlier fixes

The hackers who raided payroll and employee records at universities, carmakers and public bodies earlier this year are back. And this time they're getting in at organisations that thought they had already dealt with the problem. 

On Friday, Google's security unit Mandiant said the extortion group ShinyHunters had launched a fresh wave of attackson Oracle PeopleSoft, one of the most widely used HR and payroll systems among large employers. Dozens of systems worldwide have been hit, across higher education, technology, IT services, healthcare, agriculture, transport and government. Mandiant did not name the victims. 

The attackers are going after one group in particular: organisations that responded to the earlier attacks with a quick workaround instead of installing Oracle's fix. Many had set up a firewall rule to block the attack. The hackers found they could slip past it by disguising a single letter in the web address they used. Mandiant's message to employers was blunt: workarounds "are not a substitute for patching." 

Why this is an HR problem 

PeopleSoft's human capital management software holds exactly the information criminals want: pay, bank details, tax records, benefits, home addresses and ID numbers. The same weakness was first exploited in late May, two weeks before Oracle issued an emergency security alert on 10 June. By then Mandiant had warned more than 100 organisations that they might be exposed. 

The fallout from that first round shows what's at stake for employees. In the UK, records on roughly 454,600 current and former University of Nottingham students were posted online. ShinyHunters also claimed it had stolen more than 297GB of data from the Council of Europe, including payroll records, CVs and staff salary, banking, tax and medical information. The Council said it was investigating. 

Nissan told current and former staff in the US, Canada, Mexico and Brazil that their national ID numbers, bank details, tax records and beneficiary information may have been taken from the system it uses for payroll.  

According to Nissan's notice, Oracle said hundreds of companies were affected. Nissan responded by allowing staff to view payslips or change their pay account details only from company networks or secure VPN connections. 

Read next: SickKids data breach exposes cybersecurity risk for employee information 

Mandiant's advice this time reads a lot like an HR checklist. Organisations should look for signs that HR, payroll or student records were copied in bulk, change the passwords and access keys the system uses, and prepare for ransom demands. Mandiant says demanding payment in exchange for not leaking stolen data is the group's well-established pattern. 

The FBI says it's investigating 

The new warning lands days after ShinyHunters claimed it had broken into the FBI's recruitment website, FBIJobs.gov, and taken 2 to 3 terabytes of data on agents, staff and job applicants. The group says PeopleSoft was its way in. 

The FBI says it is "actively and aggressively investigating" and hasn't yet established whether the breach happened at an outside provider or inside its own systems. Mandiant has not linked the FBI incident to this wave of attacks. ShinyHunters says it used a different PeopleSoft weakness. 

A sample the group shared with reporters appeared to include names, home addresses, phone numbers, dates of birth, Social Security numbers and emergency contacts for about 5,000 employees. Parts of it matched real FBI or Justice Department staff though that doesn't prove where it came from. Cynthia Kaiser, a former deputy cyber director at the FBI and now a senior vice president at security firm Halcyon, told NBC News the information "could be used by criminals to target or physically harm" agents and their families. 

Read next: Employee data potentially exposed in Asahi cyberattack 

That risk isn't limited to law enforcement. In a May public service announcement, the FBI said people linked to ShinyHunters pressure victims with threatening texts and phone calls to them and their families, and in some cases with swatting. When the stolen files include home addresses and emergency contacts, the people on the receiving end are your employees. 

HR data is almost always part of the haul. A Lab 1 analysis covered by HRD found payroll files, CVs and personal details in 82 per cent of the 1,297 breaches it reviewed. 

Read next: Employee computers hacked in Levi's cyberattack 

What HR leaders should do now 

Ask IT one question. Did we install Oracle's fix, or did we rely on a workaround? Get the answer in writing. If it was a workaround, treat your employee data as at risk until IT confirms otherwise. 

LATEST NEWS