Google says the ShinyHunters hacking group is targeting the education sector using an exploit against Oracle products. Both Google’s account and reporting from multiple outlets describe ShinyHunters as a threat actor with a history of going after organisations globally, including for extortion. The reports say the group’s activity involves exploiting vulnerabilities in Oracle software to gain access to victims and then leveraging that access as part of its broader criminal activities.
The coverage focuses on the specific target area—education—rather than on any single country or specific institution. It also frames the claim within the group’s prior behaviour, emphasising that ShinyHunters has previously been associated with ransomware and extortion campaigns. While the sources cite Google’s assessment, they do not provide new technical details beyond the use of an Oracle exploit and the targeting of education organisations.
Overall, the information indicates Google’s attribution of the attacks to ShinyHunters and highlights Oracle exploitation as the entry vector, with education institutions being among the affected sector.