UNC6240 is ShinyHunters
Assessment
Google's Threat Intelligence Group tracks this campaign as the activity cluster UNC6240 and links it to ShinyHunters, whose established pattern is data-theft extortion. This is a well-supported vendor assessment, but two caveats keep it short of a definitive identification. First, 'UNC' designations are by definition uncategorised, provisional clusters that GTIG has not fully graduated to a named group. Second, 'ShinyHunters' is itself a loose, overlapping label used across a shifting set of actors and aliases rather than a single fixed organisation. So 'ShinyHunters did this' is an accurate shorthand for GTIG's assessment, but a reader should understand it as an attribution of behaviour to a fuzzy-edged label, not a precise, courtroom-grade identification of specific individuals.
Where this claim appeared
BleepingComputer · 2026-09-26
https://www.bleepingcomputer.com/news/security/shinyhunters-uses-waf-bypass-trick-in-oracle-peoplesoft-attacks/What “Assessed, Not Confirmed” means
A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.
4 of 5 · rating scale
Assessed in
ShinyHunters (UNC6240) bypass a WAF with one URL-encoded character to mass-exploit PeopleSoft CVE-2026-35273Think this assessment is wrong? Report an error.