Cybersecurity

ShinyHunters Claims to Have Breached FBI Systems Through a PeopleSoft Zero-Day Vulnerability

The ShinyHunters group claims it exploited a previously unknown vulnerability in Oracle PeopleSoft to access systems belonging to the Federal Bureau of Investigation and steal data belonging to employees and job applicants. The FBI has not confirmed the breach or data theft and said it is investigating claims related to FBIjobs.gov.

2026-09-22
4 min read
7 views
certi.news Editorial Team
ShinyHunters Claims to Have Breached FBI Systems Through a PeopleSoft Zero-Day Vulnerability

The cyber extortion group ShinyHunters said it breached systems belonging to the U.S. Federal Bureau of Investigation (FBI) using an alleged zero-day vulnerability in Oracle PeopleSoft, then moved from the initial systems to an AWS GovCloud infrastructure managed by the bureau. The group claims it stole between 2 and 3 terabytes of data, including information concerning current and former employees, job applicants, and other internal records.

However, this account has not been independently verified. The FBI confirmed to BleepingComputer that it was aware of claims concerning unauthorized activity affecting FBIjobs.gov and was investigating them, without confirming that its systems had been breached or that data had been stolen from them.

What does the group claim happened?

ShinyHunters said it obtained initial access through a new vulnerability in PeopleSoft that allows remote code execution, and that it exploited the vulnerability on Monday evening before moving to internal services and the bureau’s AWS GovCloud environment. It also claimed to have breached services including Criminal Justice, HR, and Medlink, along with other systems.

The group published a screenshot of apply.fbijobs.gov displaying its logo and a message claiming that it had taken over the site, along with a claim that it had stolen personally identifiable information and health data belonging to FBI employees and job applicants. It said the bureau isolated the affected systems and halted access to multiple networks after discovering the activity, while the site currently displays a maintenance message, according to its account.

The group also provided two sample records that it said were stolen during the attack, one associated with an FBI employee and the other with FBI Director Kash Patel. BleepingComputer did not publish the personal data contained in the two records and did not verify their authenticity or source. 404 Media had previously reported on a sample containing approximately 5,000 records attributed to FBI employees and said some of the information matched phone numbers and data associated with employees at the U.S. Department of Justice.

Unconfirmed vulnerability and claims of targeting other organizations

ShinyHunters claims that the PeopleSoft vulnerability remains unpatched, and that it found another vulnerability in the product and then immediately used it against the FBI. It added that it was attempting to remove traces of its activity from the servers and had begun using the same vulnerability against other organizations, including companies on the Fortune 500 list, after targeting the education sector.

BleepingComputer contacted Oracle and Google Cloud’s Mandiant threat intelligence team for information about the alleged PeopleSoft vulnerability and any related exploitation, and the source did not report confirmation from either company.

Why does this matter?

The claim is significant because it combines three sensitive elements: an alleged zero-day vulnerability in an enterprise platform, potential access to a government cloud environment, and personal and health data belonging to employees and job applicants. Nevertheless, the available information does not yet establish that the breach actually occurred or that the amount of stolen data equals the figure announced by the group. The details of the attack and the published samples should therefore be treated as claims under investigation, not as established facts.

Background to the escalation

ShinyHunters said the attack was carried out in response to a FLASH report published by the FBI in May 2026 that discussed the group, and gave the bureau one week to correct or delete the report, while rejecting the description of the move as financial extortion. When asked whether it would publish the alleged data if the FBI did not respond, it did not provide an answer.

The source also links the group to a 2025 Oracle E-Business Suite data-theft campaign and to subsequent disputes with the Clop group. However, this background does not confirm the validity of the current claim, while the central question remains open: Was a new PeopleSoft vulnerability actually exploited, and what scope of access and data can be substantiated?

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news