PeopleSoft Breaches and the Myth of "Set and Forget" ERP Security

Sep 26, 20263 min

PeopleSoft Breaches and the Myth of "Set and Forget" ERP Security

Enterprise software doesn't age like wine. It ages like infrastructure — quietly, until something breaks.

That's the lesson from the latest wave of attacks on Oracle's PeopleSoft platform. According to Google's Threat Intelligence team, the ShinyHunters hacking group has expanded its attacks on Oracle's PeopleSoft systems, targeting organisations that still rely on the decades-old ERP suite to run payroll, HR, and finance operations.

For Singapore businesses, this isn't a distant headline. It's a direct question about what's sitting underneath your own payroll system.

Why PeopleSoft, Why Now

PeopleSoft has been around since the 1990s. Many organisations — including large enterprises and government-linked entities globally — still run it because migrating away is expensive, disruptive, and politically painful internally.

That longevity is exactly the problem.

Old systems accumulate:

  • Unpatched vulnerabilities that predate modern security standards
  • Custom modifications that make standard patches harder to apply
  • Institutional knowledge gaps, as the engineers who built the system move on
  • Compliance debt, where the system technically works but no longer meets current data protection expectations

ShinyHunters didn't need to invent a new attack method. They found a well-known category of target — legacy ERP — and expanded operations against it because it works.

The Payroll and Tax Data Problem

PeopleSoft installations typically hold some of the most sensitive data a company has: employee salaries, bank details, national ID numbers, and tax records.

In Singapore, payroll data intersects directly with statutory obligations. Employers are required to report income accurately for tax purposes, and IRAS expects that data trail to be clean, traceable, and — implicitly — secure. A breach doesn't just expose employees. It exposes the employer's compliance posture.

If a legacy ERP system handling this data is compromised, the fallout isn't limited to reputational damage. It becomes a regulatory and legal exposure question, on top of the operational chaos of a breach.

"Set and Forget" Was Never a Strategy

There's a common assumption in mid-sized and large organisations: once ERP is implemented, it's done. It runs. It doesn't need active management beyond routine maintenance.

That assumption is the actual vulnerability.

ERP systems — especially ones running payroll, tax, and workforce data — need the same ongoing scrutiny as any customer-facing application. Attackers don't distinguish between "core infrastructure" and "public website." They go where the data is valuable and the defences are outdated.

The ShinyHunters campaign against PeopleSoft is a reminder that attackers actively scan for organisations still running old ERP versions, precisely because those organisations tend to have the weakest ongoing security posture.

What SG Companies Should Actually Do

This isn't a call to panic-migrate everything overnight. It's a call to stop treating legacy ERP as a solved problem. Practical steps:

  1. Audit what you're actually running. Know your PeopleSoft (or equivalent) version, patch status, and customisations.
  2. Map where sensitive data lives. Payroll, tax, and personal data fields need explicit ownership and monitoring.
  3. Patch on a schedule, not a crisis. Waiting for a breach to trigger an update cycle is a losing strategy.
  4. Evaluate modern alternatives. Newer, cloud-native workforce and operations platforms are built with current security practices as a baseline, not an afterthought.
  5. Treat compliance as ongoing, not annual. Tax and payroll data obligations don't pause between audits.

None of this is glamorous. It's maintenance. But maintenance is what prevents the headline.

Key takeaways

  • Legacy ERP systems like PeopleSoft are active, expanding targets for groups like ShinyHunters, not historical risks.
  • Payroll and tax data breaches carry regulatory weight in Singapore, not just reputational cost — IRAS compliance depends on accurate, secure data handling.
  • "Set and forget" ERP management is a security gap, not a stable state.
  • Regular audits, patching, and data mapping are the minimum baseline for any company still running older enterprise systems.
  • Modernising workforce and ERP infrastructure should be evaluated as a security decision, not just an operational one.

Sources