
Security teams gain an immediate test case for zero-day response as the ShinyHunters extortion gang claims it breached FBI systems through a new Oracle PeopleSoft vulnerability, accessed internal services, and stole between 2TB and 3TB of data on employees and job applicants. The group says it used the remote code execution flaw on Monday night to reach FBI systems and then moved laterally into FBI-managed AWS GovCloud infrastructure. The claims have not been independently verified, and the FBI has confirmed only that it is investigating.
What the group claims was taken
ShinyHunters says the stolen data includes information on current and former FBI employees, job applicants, and other internal records. The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion. Two sample records shared with reporters allegedly belong to FBI personnel, including an agent involved in a previous BreachForums investigation and the FBI Director. The personal information in those records has not been verified or published.
What the defacement showed
A screenshot shared by the group shows the FBI Jobs website at apply.fbijobs.gov defaced with an Umbreon Pokemon logo and a message claiming employee and applicant information had been compromised. The message stated that sensitive personally identifiable and health-related information belonging to FBI employees and applicants was stolen. ShinyHunters said the FBI quickly detected the intrusion, took affected systems offline, and terminated access to multiple FBI networks at the same time. The FBI Jobs site now displays a maintenance message.
How the alleged zero-day works
ShinyHunters claims initial access came through an unpatched zero-day vulnerability in Oracle PeopleSoft. The group said it found one flaw and immediately used it against the FBI, then found another the following day. It also claims it tried to erase evidence from compromised servers to make the vulnerability harder to identify. The group says it is now using the same alleged PeopleSoft flaw to target corporations, including Fortune 500 companies, after previously targeting the education sector.
What the reporting shows
A separate report on the alleged breach received a sample containing roughly 5,000 purported FBI employee records. That publication said it verified some information in the sample was accurate, including phone numbers that matched people with the same names and numbers associated with US Department of Justice personnel. The stolen data is said to have come from systems reached after the initial PeopleSoft compromise, including the FBI’s AWS GovCloud environment used to store employee and applicant information.
Why the group says it acted
ShinyHunters published a statement on its data leak site claiming the attack was retaliation for an FBI FLASH report about the group issued in May 2026. The group disputes claims in that report that its members exaggerate access to sensitive information, harass victims, conduct swatting attacks, and falsely claim to hold compromising material. It also rejected the idea that it is part of “The Com,” the loose cybercrime community often tied to data breaches and cryptocurrency theft. ShinyHunters gave the FBI one week to correct or remove the report while saying the demand was not financially motivated. Asked whether it would release the allegedly stolen data if the report stayed unchanged, the group declined to answer, and its representative said increased pressure from the US government did not concern them.
The group’s history with Oracle vulnerabilities
The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to a previously unknown Oracle flaw. During the 2025 Oracle E-Business Suite data theft campaign tied to Clop, ShinyHunters was part of a group calling itself “Scattered Lapsus$ Hunters” that leaked a proof-of-concept exploit Oracle later confirmed matched one used in the attacks. ShinyHunters said the exploit originally belonged to it and that Clop obtained it without authorization. That dispute resurfaced last week when ShinyHunters breached and defaced Clop’s data leak site and claimed it stole server data and the private keys for its Tor onion service.
FAQ
Did the FBI confirm the ShinyHunters breach?
The FBI said it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating. It has not confirmed whether its systems were breached or data was stolen.
What vulnerability did ShinyHunters claim to exploit?
The group claims it used an unpatched zero-day vulnerability in Oracle PeopleSoft that allows remote code execution. Neither the vulnerability nor the exploitation has been independently verified.
How much data does ShinyHunters claim it stole from the FBI?
ShinyHunters claims it stole between 2TB and 3TB of data, including information on current and former FBI employees, job applicants, and other internal records. The amount has not been independently verified.
This article summarizes reporting from bleepingcomputer.com.
