ShinyHunters Claims FBI Breach Through Oracle PeopleSoft Zero-Day

The ShinyHunters extortion gang claims it breached FBI systems using an unpatched Oracle PeopleSoft zero-day and stole up to 3TB of employee and applicant data.

Readers tracking high-impact infrastructure breaches now have a new case to evaluate: the ShinyHunters extortion gang claims it used an unpatched Oracle PeopleSoft zero-day to breach FBI systems, move laterally into an AWS GovCloud environment, and steal between 2TB and 3TB of data covering current and former employees, job applicants, and internal records. The FBI has confirmed it is investigating the claims, while the group says it is now targeting other organizations with the same exploit. BleepingComputer has not independently verified the alleged zero-day, lateral movement, or volume of stolen data, and the FBI has not confirmed whether its systems were breached.

What the attackers claim they accessed

ShinyHunters says the vulnerability allows remote code execution and was used on Monday night to reach FBI systems. From that initial foothold, the group claims it moved laterally into FBI-managed AWS GovCloud infrastructure used to store employee and applicant information. The alleged compromise included FBI Criminal Justice, HR, Medlink, and additional services.

The group shared a screenshot showing the FBI Jobs website at apply.fbijobs.gov defaced with an Umbreon Pokemon logo and a message stating the site had been seized. The defacement claimed that sensitive personally identifiable information and health-related information on incumbent and former FBI employees and all applicant information had been stolen.

As evidence, ShinyHunters provided two sample records. One allegedly belonged to an FBI special agent involved in a previous BreachForums investigation, and another was said to be associated with FBI Director Kash Patel. Personal information from those records has not been published or independently verified. The FBI Jobs site now shows a maintenance message after the agency detected the intrusion, and the group claims the FBI terminated access to multiple networks simultaneously.

What the reported data sample showed

404 Media first reported the alleged breach after receiving a sample containing roughly 5,000 purported FBI employee records. The publication said it verified that some information in the sample was accurate, including phone numbers matching people with the same names and numbers tied to US Department of Justice personnel. That verification does not confirm the full scope of the breach, but it adds a concrete signal to the extortion group’s claims.

The alleged Oracle PeopleSoft zero-day

ShinyHunters says initial access came through a new zero-day in Oracle PeopleSoft that remains unpatched, and that a second vulnerability found the next day was immediately exploited against the FBI. The group also claims it attempted to erase evidence on compromised servers to make the zero-day harder to identify.

The same alleged PeopleSoft vulnerability is reportedly being used against corporations and Fortune 500 companies after an earlier focus on the education sector. Oracle and Google Cloud’s Mandiant threat intelligence team have been contacted about the alleged breach and the zero-day, and no response has been reported yet.

Retaliation for an FBI report

ShinyHunters published a lengthy statement on its data leak site describing the attack as retaliation for an FBI FLASH report about the group released in May 2026. The statement disputes claims that the group exaggerates access to sensitive information, harasses victims and their relatives, conducts swatting attacks, or falsely claims to hold compromising material. It also denies being part of The Com, a loose cybercrime community frequently tied to data breaches and cryptocurrency theft.

The group gave the FBI one week to correct or remove the FLASH report and said the demand was not financially motivated. When asked whether stolen FBI data would be released if the agency did not act, the group declined to comment. Asked about the risk of increased US government pressure, the main representative responded, “I don’t care.”

Prior Oracle exploitation links

This would not be the first time ShinyHunters has been linked to a previously unknown Oracle vulnerability. During the 2025 Oracle E-Business Suite data theft campaign attributed to Clop, ShinyHunters took part in a group calling itself Scattered Lapsus$ Hunters that leaked a proof-of-concept exploit. Oracle later confirmed that exploit matched one used in the attacks. ShinyHunters then claimed the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization.

That dispute resurfaced last week when ShinyHunters breached and defaced Clop’s data leak site, claiming it stole server data and private keys for the Tor onion service. The group added Clop to its own leak site and threatened to extort the ransomware operation, describing the action as retaliation for threats made during the Oracle E-Business Suite campaign.

FAQ

What did ShinyHunters claim to steal from the FBI?

ShinyHunters claims it stole between 2TB and 3TB of data including information on current and former FBI employees, job applicants, personally identifiable information, health-related information, and internal records from services such as Criminal Justice, HR, Medlink, and AWS GovCloud infrastructure.

Did the FBI confirm the breach?

No. The FBI confirmed it is investigating claims of unauthorized activity affecting FBIjobs.gov but has not confirmed whether its systems were breached or data was stolen. BleepingComputer has not independently verified the alleged zero-day, lateral movement, or stolen data volume.

What vulnerability was allegedly used in the FBI attack?

ShinyHunters says it used a new unpatched zero-day in Oracle PeopleSoft that allows remote code execution. The group claims it exploited a second PeopleSoft vulnerability the following day and is now using the same attack against Fortune 500 companies and other organizations.


This article summarizes reporting from bleepingcomputer.com. See our editorial disclaimer for how our articles are produced.

🤖
Is your business visible to AI assistants?

Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.

Check Your Score →