FBI breach claim tied to PeopleSoft 0day
ShinyHunters says it used an unpatched Oracle PeopleSoft flaw to hit FBI systems, steal terabytes of data, and demand a report retraction.
ShinyHunters, the extortion gang that has spent the past year bouncing between high-profile targets, now claims it walked into FBI systems through a zero-day in Oracle PeopleSoft and walked out with terabytes of employee and applicant data. The group's public story is loud, specific, and — as of this writing — unverified by independent security researchers.
The claim landed alongside a screenshot of a defaced FBI Jobs page, a lengthy statement on the gang's leak site, and a demand that the bureau retract a May 2026 FLASH report. If the intrusion is real, it would be one of the more consequential breaches attributed to the group. If it is exaggerated, it fits a pattern law enforcement has already flagged.
A 0day, a Monday night, and a pulled plug
ShinyHunters told BleepingComputer that the vulnerability allows remote code execution and that the group used it Monday night to access FBI systems, then moved laterally into FBI-managed AWS GovCloud infrastructure. The gang says it took between 2TB and 3TB of data, including records on current and former FBI employees, job applicants, and other internal files.
According to the group, the compromised services included FBI Criminal Justice, HR, Medlink, and additional systems. ShinyHunters also told the outlet that the FBI quickly became aware of the intrusion, took affected systems offline, and that the FBI Jobs site now displays a maintenance message. The gang said access to multiple FBI networks was terminated simultaneously.
They literally pulled the plug on everything.
— ShinyHunters, as told to BleepingComputer
BleepingComputer said it has not independently verified the alleged zero-day, the lateral movement, or the amount of stolen data. The outlet did review a screenshot showing the FBI Jobs website at apply.fbijobs.gov defaced with the group's Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised.
Defacement message and sample records
The defacement stated, "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)". A second message on the page claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen.
"All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information," read the message on the defaced site. "We have a lot more than what we claim here. Thank you for your attention to this matter."
ShinyHunters shared two sample records with BleepingComputer that the group claims were stolen during the attack. One allegedly contained information associated with an FBI special agent involved in a previous BreachForums investigation, while another allegedly contained information associated with FBI Director Kash Patel. BleepingComputer said it is not publishing the personal information in those records and has not independently verified their authenticity or source.
404 Media's sample and what it verified
404 Media first reported the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records. The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.
That verification is partial: it confirms that some of the data points match real people and real DOJ-associated numbers, but it does not confirm the scale of the breach, the method of entry, or the gang's claim to have reached AWS GovCloud. The gap between "some of this looks real" and "ShinyHunters owns the FBI" is where the story currently sits.
The PeopleSoft zero-day claim
ShinyHunters claims it gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched. The group also claims it tried to erase evidence of its activity from compromised servers to make the zero-day harder to identify.
"The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," ShinyHunters told BleepingComputer.
The gang says it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after targeting the education sector. According to ShinyHunters, the stolen FBI data came from systems accessed following the initial PeopleSoft compromise, including the FBI's AWS GovCloud environment, which the group says was used to store employee and applicant information.
BleepingComputer said it has contacted Oracle and Google Cloud's Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity. It also contacted the FBI. No response had been reported at the time of the outlet's coverage.
Retaliation over a May 2026 FBI report
ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an FBI FLASH report detailing the group that was published in May 2026. The gang disputed claims that ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material.
The group denied those allegations and also rejected claims that it is part of "The Com," a loose-knit cybercrime community frequently tied to data breaches, cryptocurrency theft attacks, and commonly referenced by law enforcement and security researchers. In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion.
When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say. "No comment," the threat actor told BleepingComputer. Asked whether they were concerned the attack would lead to increased pressure from the US government to apprehend them, the gang's main representative responded, "I don't care."
The Oracle exploit history behind the claim
The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability. During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself "Scattered Lapsus$ Hunters" that leaked a proof-of-concept exploit later confirmed by Oracle to match one used in the attacks.
ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization. That dispute resurfaced last week when ShinyHunters breached and defaced Clop's data leak site, claiming it stole server data and the private keys for its Tor onion service. The group subsequently added Clop to its own leak site and threatened to extort the ransomware operation, saying the attack was retaliation for threats allegedly made during the Oracle E-Business Suite campaign.
What remains unverified
The central claims in this story come from the gang itself and have not been independently confirmed. BleepingComputer has not verified the alleged zero-day, lateral movement, or amount of stolen data. The outlet reviewed a screenshot of the defaced FBI Jobs page and two sample records but did not authenticate the underlying data. 404 Media's review of a separate sample found some accurate elements, but not a complete picture.
Key open questions include whether the PeopleSoft vulnerability is real and unpatched, whether ShinyHunters actually reached AWS GovCloud, and whether the group's claim of 2TB to 3TB is accurate. ShinyHunters declined to say whether it would release the data. The FBI, Oracle, and Mandiant had not publicly responded at the time of BleepingComputer's reporting.
What this means for defenders
For security teams running Oracle PeopleSoft, the practical takeaway is uncomfortable: the vulnerability described here is unpatched, according to the only party that has spoken about it publicly. That does not mean every PeopleSoft deployment is compromised, but it does mean assumptions about patch coverage are worth re-examining. Organizations that rely on PeopleSoft for HR, finance, or student records should treat the next Oracle advisory cycle as a priority rather than routine maintenance.
The FBI's apparent response — pulling systems offline and terminating access — is the kind of blunt containment that works but carries operational cost. That trade-off is likely to repeat if the same flaw is used against Fortune 500 companies, as ShinyHunters claims it intends to do. The gang's stated pivot from education to enterprise targets is a reminder that zero-day exploitation is not always a targeted, one-off event; sometimes it is a campaign with a known next step.
Finally, the demand that the FBI retract its own FLASH report is a new wrinkle. Extortion usually involves money or data release. Here, the stated goal is a change to a law enforcement document. Whether or not the attack is fully verified, that demand suggests ShinyHunters is trying to shape the public record about itself. For defenders and investigators, that is a signal worth tracking separately from the breach claims.
Sources
- BleepingComputer Original source
Continue Reading
Microsoft Cuts Off AI Phishing Platform
Microsoft and partners disrupted EvilTokens, an AI-assisted phishing service that compromised 12,000 accounts, seizing domains and prompting arrests.
ShinyHunters Hack FBI Jobs Site, Stolen Data Claimed
ShinyHunters claims it breached an Oracle PeopleSoft zero-day on the FBI jobs site, stealing 2-3 TB of employee data and demanding a retraction, not ransom.
Stolen Passwords Expose 1,787 Water Providers
SpyCloud research finds infostealer malware has harvested credentials tied to 1,787 U.S. water and wastewater organizations, some reaching operational networks.