What happened
The threat group ShinyHunters (tracked by Mandiant as UNC6240) breached a large North American university's Oracle PeopleSoft human resources and student information system. Attackers used percent-encoded URL sequences to bypass the institution's web application firewall, ultimately exfiltrating data on approximately 6 million students and staff members. The stolen dataset included usernames, hashed passwords, email addresses, and partial Social Security Numbers.
The bypass technique
Oracle PeopleSoft exposes a rich set of web endpoints for HR, payroll, and student services. Many organizations front these with a WAF configured to block common injection strings. ShinyHunters encoded their payloads using double percent-encoding: for example, turning a single quote from %27 to %2527. A WAF that decodes input only once will see %2527 as a literal string and allow it through; the backend application then decodes it a second time, resolving it to the intended injection character. This class of bypass is not new, but PeopleSoft deployments remain systemically under-tested against multi-pass decoding attacks.
Recommended actions
Review your WAF configuration to confirm it performs recursive URL decoding before inspecting payloads. A WAF that decodes only once is vulnerable to double-encoding bypasses. Apply Oracle's most recent PeopleSoft security bundles and enable PeopleSoft's built-in activity monitoring to flag anomalous query volumes on sensitive fields. Rotate any credentials exposed in this event and enforce multi-factor authentication on all PeopleSoft administrator and self-service accounts.
The bottom line
Percent-encoding bypasses have been in the attacker playbook for two decades. The fact that they still succeed against production enterprise systems in 2026 points to a gap between WAF purchasing and WAF configuration. A WAF that ships with default rules is a starting point, not a finished control. Organizations running PeopleSoft should add WAF bypass testing to their annual application security review schedule.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need a second opinion on your enterprise application layer defenses.