ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

A major US government agency, the Federal Bureau of Investigation (FBI), is embroiled in a high-profile cybersecurity incident. According to claims made by the ShinyHunters extortion gang, their cyberattack on the FBI exploited an unpatched zero-day vulnerability in Oracle’s PeopleSoft software, granting them access to sensitive data and internal services.

The alleged breach, which took place on Monday night, compromised multiple FBI systems, including those related to employee records, job applicants, and other internal services. ShinyHunters claims they stole between 2TB and 3TB of data, including information about current and former FBI employees, as well as job applicants.

The threat actors reportedly used the zero-day vulnerability to remotely execute code on FBI systems, allowing them to move laterally into the agency’s AWS GovCloud infrastructure. ShinyHunters claims they compromised several services, including FBI Criminal Justice, HR, Medlink, and additional services.

In a bizarre twist, ShinyHunters defaced the FBI Jobs website (apply.fbijobs.gov) with their Umbreon Pokémon logo and a message claiming that sensitive personally identifiable information (PII) and protected health information (PHI) belonging to FBI employees and applicants had been stolen. The group also shared sample records allegedly obtained during the attack, which contained data associated with an FBI special agent and Director Kash Patel.

While the FBI has confirmed it is investigating the claims, they have not verified whether their systems were breached or data was stolen. However, ShinyHunters’ claims are bolstered by a report from 404 Media, which stated that it had received a sample containing approximately 5,000 purported FBI employee records and had verified some of the information.

ShinyHunters’ alleged zero-day exploit is particularly concerning as it remains unpatched. The group claims to have discovered another vulnerability in Oracle PeopleSoft just yesterday and has already exploited it on the FBI’s systems. Furthermore, ShinyHunters says they are now targeting other organizations, including Fortune 500 companies, using the same alleged vulnerability.

The incident highlights the ongoing threat posed by cyber extortion groups like ShinyHunters, which have been linked to previous high-profile breaches. As these groups continue to evolve and refine their tactics, it is essential for organizations to prioritize cybersecurity and remain vigilant against emerging threats.

For businesses and individuals, this incident serves as a stark reminder of the importance of staying up-to-date with software patches and maintaining robust cybersecurity measures. It also underscores the need for organizations to have effective incident response plans in place to quickly detect and respond to potential breaches. By taking proactive steps to secure their systems and data, organizations can reduce the risk of falling victim to similar attacks in the future.


Source: Bleeping Computer — 2026-09-22