ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
ShinyHunters claims FBI hack using PeopleSoft zero-day, stealing employee and applicant data.
Summary
The ShinyHunters extortion gang claims to have breached FBI systems using a zero-day vulnerability in Oracle PeopleSoft. They allege to have stolen 2-3TB of sensitive data, including employee and applicant information, and defaced the FBI Jobs website. The group also claims to be exploiting the same vulnerability against other organizations.
Full text
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach By Lawrence Abrams September 22, 2026 03:13 PM 0 The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records. The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion. ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies. BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data. However, ShinyHunters shared a screenshot with BleepingComputer showing the FBI Jobs website at apply.fbijobs.gov defaced with the group's Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised. The defacement stated, "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)". Allegedly defaced FBI Jobs websiteSource: ShinyHunters The message further claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen. "All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information," read a message on the defaced site. "We have a lot more than what we claim here. Thank you for your attention to this matter." ShinyHunters told BleepingComputer that the FBI quickly became aware of the intrusion, immediately took affected systems offline, and that the FBI Jobs site now displays a maintenance message. The group also claimed that access to multiple FBI networks was terminated simultaneously after the agency detected the intrusion. "They literally pulled the plug on everything," ShinyHunters said. The threat actors shared two sample records with BleepingComputer that the group claims were stolen during the attack, including data allegedly associated with FBI personnel. One record allegedly contained information associated with an FBI special agent involved in a previous BreachForums investigation, while another allegedly contained information associated with FBI Director Kash Patel. BleepingComputer is not publishing the personal information contained in those records and has not independently verified their authenticity or source. 404 Media first reported the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records. The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel. Alleged PeopleSoft zero-day ShinyHunters claims they gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched. "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," ShinyHunters told BleepingComputer. The group also claims it tried to erase evidence of its activity from compromised servers to make the zero-day harder to identify. ShinyHunters also told BleepingComputer that it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after targeting the education sector. ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise. These systems allegedly include the FBI's AWS GovCloud environment, which was used to store employee and applicant information. BleepingComputer has contacted Oracle and Google Cloud's Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity. Retaliation over FBI report ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an FBI FLASH report detailing ShinyHunters that was published in May 2026. ShinyHunters statement about FBI attack Source: BleepingComputer The group disputes claims that ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material. The threat actors denied those allegations and also rejected claims that it is part of "The Com," a loose-knit cybercrime community frequently tied to data breaches, cryptocurrency theft attacks, and commonly referenced by law enforcement and security researchers. In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion. When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say. "No comment," the threat actor told BleepingComputer. When BleepingComputer asked the main representative of the ShinyHunters extortion gang whether they were concerned this would lead to increased pressure from the US government to apprehend them, they responded, "I don't care." The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability. During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself "Scattered Lapsus$ Hunters" that leaked a proof-of-concept exploit later confirmed by Oracle to match one used in the attacks. ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization. That dispute resurfaced last week when ShinyHunters breached and defaced Clop's data leak site, claiming it stole server data and the private keys for its Tor onion service. The group subsequently added Clop to its own leak site and threatened to extort the ransomware operation, saying the attack was retaliation for threats allegedly made during the Oracle E-Business Suite campaign. BleepingComputer has contacted the FBI, Oracle, and Google Cloud's Mandiant threat intelligence team regarding the alleged breach and PeopleSoft zero-day and will update this story if we receive a response. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Florida confirms DMV database breached via stolen police accountIDScan confirms breach tied to 153 million stolen driver’s licensesMathspace discloses data breach affecting over 1 million peopleIDScan sued over alleged data breach affecting 153 million driversNovocure data breach affects more than 1,400 cancer patients