ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

FBI Hit with Massive Data Breach via Unpatched Zero-Day Vulnerability in PeopleSoft System

A massive data breach affecting the US Federal Bureau of Investigation (FBI) has been claimed by the notorious extortion gang ShinyHunters, who say they exploited a previously unknown vulnerability in Oracle’s PeopleSoft system to gain unauthorized access to sensitive information. According to the group, the breach resulted in the theft of between 2TB and 3TB of data, including personal details of current and former FBI employees, job applicants, and other internal records.

The incident is believed to have occurred on Monday night, when ShinyHunters allegedly used the zero-day vulnerability to access the FBI’s PeopleSoft system, allowing them to move laterally into the agency’s AWS GovCloud infrastructure. The group claims that they compromised multiple services, including those related to Criminal Justice, HR, Medlink, and others.

ShinyHunters has taken credit for defacing the FBI Jobs website, apply.fbijobs.gov, with a screenshot showing the site displaying the group’s Umbreon Pokémon logo and a message claiming that sensitive information had been stolen. The group also claims to have stolen personally identifiable and health-related information belonging to FBI employees and applicants.

The involvement of ShinyHunters in this incident is concerning, given their history of targeting large organizations, including education sector institutions. It appears that the same alleged zero-day vulnerability is being exploited against other Fortune 500 companies, raising questions about the effectiveness of cybersecurity measures in place at these organizations.

While the FBI has confirmed to BleepingComputer that it is investigating the claims, it did not confirm whether its systems were breached or data was stolen. However, ShinyHunters shared screenshots and sample records with BleepingComputer, which appear to corroborate their claims.

The alleged PeopleSoft zero-day vulnerability remains unpatched, allowing attackers to execute malicious code remotely. This type of vulnerability is particularly concerning, as it can be exploited by threat actors without the need for any authentication or authorization.

For organizations using Oracle’s PeopleSoft system, this incident serves as a stark reminder of the importance of timely patching and regular security audits. It also highlights the need for robust cybersecurity measures to prevent lateral movement and data exfiltration.

As we continue to learn more about this incident, one thing is clear: organizations must prioritize their cybersecurity posture and take immediate action to address vulnerabilities in their systems. Failure to do so can have devastating consequences, as seen in this high-profile breach affecting the FBI.


Source: Bleeping Computer — 2026-09-22