1 of 6

CISO ADVISORS · SECURITY BRIEFING

PeopleSoft

Data Breach:

Lessons Learned

Legacy ERP Vulnerabilities & Mitigation Strategies

Oracle PeopleSoft breaches have exposed millions of employee, student, and financial records worldwide

Ed Moore, CISSP · CISM · C-CISO · CEH | CISO Advisors | cisoadvisors.com

CISO Advisors · cisoadvisors.com · Confidential

1 / 11

2 of 6

CA

THREAT CONTEXT

Why PeopleSoft Is a High-Value Target

PeopleSoft systems contain the most sensitive data in any organization — attackers know this

CISO Advisors · cisoadvisors.com · Confidential

2 / 11

Crown Jewel Data

PeopleSoft contains SSNs, salaries, bank accounts, tax data, performance reviews, medical leave records, student records — all in one database

Legacy Architecture

Many PeopleSoft deployments are 10–20+ years old with unpatched code. Legacy code paths contain vulnerabilities that have never been reviewed.

Directly Internet-Facing

PeopleSoft HR and Student Information Systems are often exposed directly to the internet for employee self-service — broad attack surface

Under-Resourced Administration

PeopleSoft often administered by HR/Finance technical staff, not security-trained engineers. Security patching is deprioritized against business continuity.

3 of 6

CA

BREACH HISTORY

Notable PeopleSoft Breaches & Exposures

Real incidents that demonstrate the severity and consistency of PeopleSoft vulnerabilities

CISO Advisors · cisoadvisors.com · Confidential

3 / 11

US Universities (Multiple) · 2014–2023

Method: SQL injection and credential stuffing against PeopleSoft Student Information Systems (SIS). Repeated across 60+ universities.

→ Default PeopleSoft configurations are insecure; custom code often introduces SQL injection

Healthcare Organizations · Ongoing

Method: PeopleSoft HR systems targeted for employee SSNs and bank account data to enable tax fraud, identity theft, and W-2 fraud schemes.

→ HR data in PeopleSoft is as sensitive as clinical data — requires equivalent protection

State Government Agencies · 2016–2022

Method: Exploitation of unpatched PeopleSoft vulnerabilities; some via phishing of PeopleSoft admin credentials; others via SQL injection.

→ Government PeopleSoft instances are chronically under-patched due to change control complexity

Financial Services Firms · 2018–Present

Method: Compromised PeopleSoft admin credentials via phishing or credential stuffing; used to exfiltrate employee compensation and banking data.

→ Privileged PeopleSoft admin access requires MFA and session monitoring without exception

4 of 6

CA

VULNERABILITY ANALYSIS

Common PeopleSoft Security Vulnerabilities

The same vulnerabilities appear repeatedly across PeopleSoft environments

CISO Advisors · cisoadvisors.com · Confidential

4 / 11

Critical

Unpatched PeopleSoft Critical Patches (CPU)

Oracle releases quarterly CPUs. Many organizations are 2–6+ years behind on patches due to upgrade complexity and fear of breaking customizations.

Critical

Default / Weak PeopleSoft Admin Passwords

PSADMIN, PS, and other default accounts are well known. Many deployments never change defaults during initial setup.

High

SQL Injection in Custom PeopleCode

Custom PeopleCode developed over years often lacks parameterized queries. Legacy code predates modern secure coding awareness.

High

Excessive PeopleSoft Role Assignments

Role bloat over years results in users with far more access than needed. Terminated employees sometimes retain access.

High

PeopleSoft Internet Architecture (PIA) Exposed

PIA directly internet-facing without WAF or network segmentation. Enables unauthenticated attacks against login and integration endpoints.

Medium

Unencrypted PeopleSoft Database Connections

Some deployments use unencrypted connections between the application tier and database — susceptible to network interception.

5 of 6

CA

MITIGATION ROADMAP

PeopleSoft Security Hardening — Priority Actions

Ordered by risk reduction impact — start with the top three immediately

CISO Advisors · cisoadvisors.com · Confidential

5 / 11

P1

Apply Oracle Critical Patch Updates (CPU) — catch up to current

Create a PeopleSoft patching runbook; establish quarterly CPU application cycle

P1

Enable MFA for all PeopleSoft admin and privileged user accounts

PeopleSoft supports SAML SSO — integrate with Entra ID or Okta and enforce MFA

P1

Change all default passwords — PSADMIN, PS, application server accounts

Rotate immediately; store in approved secrets manager (CyberArk, HashiCorp Vault)

P2

Deploy WAF in front of PIA internet-facing components

Block OWASP Top 10 attack patterns; rate limit authentication endpoints

P2

Conduct PeopleSoft role access review — remove excessive and terminated user access

Quarterly access certification; use PeopleSoft's delivered security audit reports

P2

Enable PeopleSoft activity monitoring and audit logging

Ship logs to SIEM; alert on admin account access, bulk data queries, and failed auth

P3

Engage Oracle/PeopleSoft security assessment — custom code review

Review PeopleCode for SQL injection; remediate or disable unused integrations

P3

Network segment PeopleSoft application and database tiers

Database tier must not be directly accessible from general network; use bastion/jump server

6 of 6

KEY TAKEAWAYS

Action Items & Next Steps

PeopleSoft holds your most sensitive employee data — treat it like a crown jewel system

Patching lag is the #1 PeopleSoft risk — establish a quarterly CPU patch cycle

Default credentials and no MFA = open door for any threat actor

Custom PeopleCode is an untested attack surface — conduct a code security review

Network segmentation and WAF are table stakes for any internet-facing ERP

CISO Advisors · Ed Moore

emoore@cisoadvisors.org · cisoadvisors.com

CISO Advisors · cisoadvisors.com · Confidential

11 / 11