ShinyHunters Alleges FBI Breach Through an Unknown PeopleSoft RCE Flaw
ShinyHunters claims FBI breach via PeopleSoft zero-day, stealing 2-3TB of employee data. FBI probes FBIjobs.gov activity; claims unverified.
Illustrative image generated with AI
Reports surfaced on September 22, 2026, that ShinyHunters is claiming responsibility for a potentially extensive compromise of Federal Bureau of Investigation systems. The group says it entered through an undisclosed Oracle PeopleSoft vulnerability before moving into FBI-managed AWS GovCloud infrastructure.
According to the attackers, the operation began on Monday night and resulted in the theft of between 2 TB and 3 TB of data. The claimed haul includes records concerning FBI employees, former personnel, job applicants, internal operations, personally identifiable information, and health-related data.
Those assertions remain unverified.
The FBI has acknowledged that it is investigating reports of unauthorized activity involving FBIjobs.gov. It has not confirmed that attackers gained access, exploited PeopleSoft, reached AWS GovCloud, or removed any data.
A claimed PeopleSoft foothold followed by cloud lateral movement
ShinyHunters describes the initial-access mechanism as a previously unknown, unpatched remote-code-execution vulnerability in Oracle PeopleSoft. The group says it discovered the flaw and immediately used it against the FBI.
No technical material has been released to substantiate that account. There is no disclosed CVE identifier, CVSS score, proof-of-concept code, vulnerable PeopleSoft component, authentication requirement, exploit request, or affected version range. Consequently, administrators cannot determine whether a specific PeopleSoft release or configuration is exposed.
Oracle has not issued a cited security advisory or patch for the alleged flaw. No CISA Known Exploited Vulnerabilities catalog entry was reported, and there is no remediation deadline associated with the claim. At present, the incident cannot be treated as confirmed exploitation of a documented Oracle vulnerability.
The alleged attack chain extends beyond PeopleSoft. ShinyHunters says the initial foothold enabled lateral movement into several FBI environments, including AWS GovCloud systems used to hold employee and applicant information. It also claims access to FBI Criminal Justice, Human Resources, Medlink, and other services.
How that movement supposedly occurred is unknown. The group has not disclosed whether it obtained passwords, session tokens, application secrets, cloud credentials, or access keys. There is also no confirmed information about privilege escalation, persistence, or the cloud resources reached.
According to ShinyHunters, the FBI detected the intrusion quickly, took affected systems offline, and cut access to multiple networks. The FBI Jobs website later displayed a maintenance message. These reported response measures have not established the underlying exploit path.
Employee and applicant records form the core of the alleged theft
The attackers place the purported volume of stolen material between 2 TB and 3 TB. They say it covers current and former FBI employees, applicants, internal records, PII, and protected or health-related information.
That figure has not been independently validated. Neither has the origin of the claimed data.
ShinyHunters provided two sample records to BleepingComputer, which reported the claims and the FBI’s response. One record allegedly concerned an FBI special agent associated with an earlier BreachForums investigation. The second purportedly concerned FBI Director Kash Patel. The publication did not expose the personal details and could not authenticate the records or establish where they came from.
Separately, 404 Media received a sample of approximately 5,000 purported FBI employee records. It verified that some details were accurate, including telephone numbers associated with matching names and numbers linked to U.S. Department of Justice personnel.
That limited verification does not prove the alleged breach chain. Accurate records could have originated from another system, an earlier incident, aggregated data, or a source unrelated to PeopleSoft. No available evidence connects the sample conclusively to Monday night’s claimed intrusion.
ShinyHunters also says it tried to erase evidence from compromised servers. If true, artifact deletion could obstruct reconstruction of the initial request, executed commands, credential access, and subsequent movement. That claim is likewise unsupported by published forensic evidence.
A defaced recruitment site is the main visible indicator
The most concrete public-facing sign is a screenshot that allegedly shows apply.fbijobs.gov defaced with ShinyHunters’ Umbreon Pokémon logo and a takeover message.
The displayed text claimed that employee and applicant information had been compromised, including sensitive PII and health-related records. It also suggested that the statements on the page represented only a fraction of what the group possessed.
The FBI said it was aware of claims concerning unauthorized activity affecting FBIjobs.gov and was investigating. Its statement did not confirm that the screenshot represented a successful compromise or that the recruitment platform was the point of entry.
Defacement alone would not demonstrate access to internal FBI environments. A public website, its content-management path, its hosting layer, and connected back-end applications can present separate attack surfaces. Without logs or architecture details, the relationship between the alleged defacement and the claimed PeopleSoft exploit remains unknown.
Publicly described indicators are therefore limited to:
- The affected service name, FBIjobs.gov.
- The hostname
apply.fbijobs.gov. - The Umbreon branding used in the alleged defacement.
- References to FBI employees, former employees, and applicants.
- The samples presented as stolen records.
No malicious IP addresses, domains, file hashes, command lines, payloads, exploit signatures, or named tools have been disclosed. Defenders cannot yet build high-confidence detections around a specific PeopleSoft exploit.
The group frames the operation as retaliation, not profit-seeking
ShinyHunters says the alleged FBI operation was retaliation for an FBI FLASH report published in May 2026. The group disputes descriptions of its members as exaggerating access, harassing victims and relatives, conducting swatting attacks, or making false claims about possessing compromising material.
It also denies membership in “The Com,” the loosely organized criminal ecosystem associated with data breaches, cryptocurrency theft, and other offenses.
The group gave the FBI one week to amend or withdraw the FLASH report. It characterized the demand as non-financial and rejected the description of its conduct as extortion.
That label does not resolve the practical threat. A demand backed by claimed theft of sensitive data creates coercive pressure regardless of whether money is requested. ShinyHunters did not answer when asked whether it would publish the alleged FBI records if its deadline passed.
A representative also indicated that the group was unconcerned about potentially increasing U.S. efforts to identify and arrest its members.
Claims of broader exploitation raise the risk for PeopleSoft operators
ShinyHunters says the alleged zero-day is now being used against other organizations, including Fortune 500 companies. It claims the activity previously focused on the education sector before expanding to corporate targets.
No victim list, exploitation telemetry, or technical indicators have been released to support those statements. Still, the group has prior involvement in public disputes concerning Oracle exploitation.
During Clop’s 2025 Oracle E-Business Suite data-theft campaign, ShinyHunters participated in a group known as Scattered Lapsus$ Hunters. That collective released proof-of-concept exploit material that Oracle later said matched the exploit used in the campaign.
ShinyHunters subsequently claimed that the exploit had originally belonged to it and that Clop acquired it without permission. Last week, the group said it breached and defaced Clop’s leak site, stole server data and private keys for its Tor onion service, and added Clop to its own leak platform.
That history does not validate the new PeopleSoft claim. It does, however, make rapid technical investigation more appropriate than dismissing the allegation solely because evidence remains incomplete.
Defensive work must proceed without a patch or exploit signature
PeopleSoft administrators currently have no disclosed patch, version-specific workaround, or reliable indicator for the alleged vulnerability. Organizations should monitor Oracle security communications while preserving evidence needed to determine whether exploitation has already occurred.
Priority actions include:
- Inventorying internet-accessible PeopleSoft instances and documenting their exact versions, modules, and authentication exposure.
- Reviewing PeopleSoft application, web-server, operating-system, identity, network, and endpoint logs for unexplained command execution.
- Investigating newly created accounts, unexpected privilege changes, unusual service identities, and anomalous credential use.
- Examining cloud audit records for lateral movement, unfamiliar sessions, new access keys, role assumptions, and bulk access to personnel repositories.
- Searching for attempts to delete logs, clear histories, remove application artifacts, or disable monitoring.
- Reviewing outbound transfers for volumes or destinations inconsistent with normal operations.
- Preserving volatile evidence and relevant logs before rebuilding or isolating suspected systems.
Organizations should not describe the flaw as confirmed or assume that every exposed PeopleSoft deployment is vulnerable. The affected versions have not been disclosed, and even the existence of the alleged zero-day remains unverified.
The appropriate posture is heightened investigation without treating attacker statements as established fact. The FBI inquiry and any subsequent Oracle guidance will be necessary to determine whether this is a genuine PeopleSoft zero-day campaign, a compromise through another route, or an inflated account built around partially authentic data.
Sources
This article is an original reworking based on the sources below.
