Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks
Brief
A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May and early June 2026.
The ShinyHunters hacking group exploited the flaw across about 100 organizations and 300 instances worldwide, according to reports cited by The Register.
The attackers targeted the management and configuration layers of enterprise resource-planning systems, stealing sensitive records.
Among these were employees’ and students’ personal data, payroll, tax and financial information, health records and immigration and passport documents.
AgentCypher. ai estimates extortion demands of $400,000 to $2. 3 million per victim – often in Bitcoin although the total remains undisclosed. The Council of Europe refused to negotiate or pay.
Why are traditional perimeter-based security models no longer sufficient?
