ShinyHunters is back inside Oracle PeopleSoft, the software many large employers use to run payroll and personnel records
The hackers who stole payroll and employee records from universities, carmakers and public bodies this summer have returned. This time they are breaking into organizations that believed they had already closed the gap.
Google's security unit Mandiant said on Friday that the extortion group ShinyHunters had started a new round of attackson Oracle PeopleSoft. Dozens of systems have been hit worldwide, in higher education, healthcare, government and other sectors.
Most of the victims had responded to the first attacks with a temporary workaround rather than Oracle's fix, and the hackers found a way around it. Mandiant said such workarounds "are not a substitute for patching."
What's at stake for employees
PeopleSoft's HR and payroll software stores staff bank details, tax records and ID numbers. After the first wave, Nissan told employees in the US, Canada, Mexico and Brazil that their Social Security numbers and bank details may have been stolen. ShinyHunters also claimed it took payroll and medical records from the Council of Europe.
Read next: SickKids data breach exposes cybersecurity risk for employee information
Mandiant's warning came just days after ShinyHunters said it had hacked the FBI's recruitment website and taken data on agents and job applicants. The FBI said it was "actively and aggressively investigating,"
In May, the FBI warned that the group sometimes harasses victims and their relatives with threatening calls and texts. In some cases, it has used swatting.
Read next: Employee data potentially exposed in Asahi cyberattack
What HR can do
The first step is to ask IT whether the organization installed Oracle's fix or relied on a workaround, and to get the answer in writing. Payroll and benefits vendors that run PeopleSoft should be asked the same thing.
Stolen bank details are often used to redirect wages. Nissan now lets staff change direct deposit details only from company networks. A phone call to confirm any change to where pay is sent adds another check.
Scam emails that pose as HR tend to follow breaches. In KnowBe4's phishing tests, HR-themed messages accounted for 42.5% of failures, HRD reported. Employees should know how HR will contact them and what it will never ask for.
HR teams should also decide in advance who will notify current staff, former staff and job applicants, and who will deal with a ransom demand.
Read next: Hackers impersonating IT teams to steal Salesforce data, Google warns