HomeinetShinyHunters: Claiming FBI breach via Oracle PeopleSoft zero-day

ShinyHunters: Claims FBI breach via Oracle PeopleSoft zero-day

The ShinyHunters ransomware group claims to have breached the FBI by exploiting a previously unknown zero-day vulnerability in Oracle PeopleSoft , the software that runs the FBI’s recruitment website. According to the hackers, they extracted 2 to 3 terabytes of employee data, hacked into the FBI’s internal servers on AWS GovCloud, and defaced the site, placing a banner that read “This site has been seized by ShinyHunters.” The FBI has not confirmed any of this.

The case was revealed on Tuesday, September 22, 2026, by Reuters and was technically supplemented by The Register’s exclusive interview with a spokesperson for the group. The most unusual element is that there is no ransom demand: ShinyHunters is asking the FBI to withdraw or correct an official intelligence bulletin it issued against them on May 15.

See also our previous coverage of the same group's claims that it stole 200,000 records from the Florida DMV.

ShinyHunters FBI: 2TB data breach via Oracle PeopleSoft zero-day

The technical chain of the ShinyHunters FBI attack

According to the ShinyHunters, the entry point was a remote code execution (RCE) vulnerability in Oracle PeopleSoft, which did not even require pre-authentication. PeopleSoft is the software that runs the FBI job application page, so it was accessible to anyone over the internet. Oracle itself has not confirmed the existence of such a vulnerability and no CVE has been issued for it.

  • Login: exploiting the vulnerability in Oracle PeopleSoft of the FBI recruitment page, no credentials required.
  • Initial execution: executing shell commands on the application servers, giving full control of the recruitment service.
  • Page distortion: replacing the content with a banner saying "This site has been seized by ShinyHunters", indicating that the attackers had write permissions to the servers.
  • In-network expansion: moving the recruitment page from internal FBI servers to AWS GovCloud, the Amazon region used by US federal agencies.
  • Data extraction: theft of approximately 2 to 3 TB of data allegedly involving all FBI employees and candidates.

The most troubling finding, if confirmed, is precisely this transition from a public recruitment page to production FBI systems hosted on GovCloud. GovCloud is designed for federal systems with high-class requirements (FedRAMP High, ITAR) and is supposed to be strictly segregated from the public internet. Such a transition means that the FBI had serious gaps in network separation and identity boundaries between government agencies and internal systems.

ShinyHunters FBI Technical Chain: from the recruitment page to AWS GovCloud

What data does the team say it obtained?

A ShinyHunters spokesperson told The Register that the group “has access to data on all FBI employees and applicants.” A sample of 5,000 records they shared with reporters included names, addresses, phone numbers, and spouses. The group claims to have reached three critical FBI agencies:

  • Human Resources (HR): employee personal information, files, CVs and candidate data for recruitment.
  • MedLink: FBI's internal medical system for employee health, with sensitive medical data.
  • Criminal Justice Information Services (CJIS): the FBI's central criminal justice database, which federal and local police agencies use daily.

If it is confirmed that the attackers did indeed reach CJIS, the consequences are much more serious than a typical personnel data leak. CJIS manages criminal records, fingerprints, and identification data, which are relied upon by tens of thousands of police officers across the U.S. in their daily work. Precisely to prevent such breaches, the CJIS Security Policy, in its recent version 6.1, requires enhanced encryption and continuous vulnerability testing.

FBI Data Breach: HR, MedLink and CJIS by ShinyHunters

The motive: reputation blackmail, not ransom

The most unusual element of the attack is the motive. ShinyHunters explicitly say that this is not a financially motivated operation: “This is not about money. We want the FBI to correct or retract their statements, which contain serious false allegations against us.” This time, the extortion is aimed at the FBI’s public image, not the group’s financial gain. See also our recent analysis of the massive McKesson breach of 284 million records, where the same group was motivated by its classic financial motives.

The real target of the demand is 's May 15th briefing on the ShinyHunters. The briefing said the group uses harassment tactics, sends threatening texts and phone calls to victims and their relatives, and in some cases goes as far as swatting — fake police calls that send armed units to innocent homes. The briefing also said that extortionists often lie about having incriminating photos or videos that don't actually exist. ShinyHunters denies all of these accusations.

Why verifying claims is not easy

So far, all of ShinyHunters ' claims about the FBI hack are based on a sample of records and an image of the defaced page. There is no independent confirmation from Oracle, Amazon, or the FBI itself. The SecNews technical team identifies three points in the case that need to be cross-examined before they can be treated as fact:

  • The vulnerability in Oracle PeopleSoft itself: there is no CVE, no confirmation from the manufacturer, no technical description of the exploit, nor an indication of which version is affected.
  • The move to AWS GovCloud: such a leap from a recruitment environment to federal systems would be architecturally very difficult. Without confirmation, it remains a mere assertion.
  • The sample of 5,000 records: no one has publicly confirmed whether the records actually correspond to FBI employees or whether they come from another leak.

The FBI has not commented publicly, and neither Oracle nor AWS responded to reporters' questions. The fact that the recruitment page displays the message "currently down for maintenance" indirectly supports the claim of a breach, but it is not proof in itself.

FBI Breach Verification: ShinyHunters vs Oracle AWS

What organizations running Oracle PeopleSoft should check immediately

Regardless of whether the attack is ultimately confirmed, the alleged remote code execution vulnerability in Oracle PeopleSoft requires immediate preventive measures for any organization that has the application accessible over the internet. This is particularly true for public administration and human resource service providers that host PeopleSoft for their clients:

  1. Internet exposure control: identify all publicly accessible PeopleSoft installations and either disable them or place them behind a VPN or zero trust gateway.
  2. WAF and temporary shielding: enable rules in the Web Application Firewall that restrict access to known PeopleSoft endpoints, until an official patch is released from Oracle.
  3. Log file inspection: search logs for suspicious shell commands, new administrative accounts, and bulk data exports in multi-GB sizes.
  4. Review network separation: ensure that PeopleSoft does not have a network path to classified data environments or to production cloud accounts.
  5. Credential Switching: change service account passwords, API keys, and OAuth tokens that may be stored in or alongside PeopleSoft.
  6. Monitor threat intelligence: closely follow any official CVE from Oracle and indicators of compromise (IOCs) that CISA may publish.

Frequently asked questions

Who are ShinyHunters? They are one of the most active data theft and extortion groups globally, with a long list of attacks on multinational and public sector organizations. They have been seen in breaches such as AT&T, Ticketmaster, Santander and Pure Storage, and more recently in a series of attacks on companies leveraging stolen OAuth tokens on platforms such as Salesforce. See also our coverage of the recent McKesson breach by the same group.

What is Oracle PeopleSoft and why was it targeted? PeopleSoft is Oracle's enterprise software for human resources, finance, and supply chain management, which is widely used in the US federal government. The FBI's recruiting services rely on it, so a vulnerability like this gives direct access to huge databases of personal data.

Has the FBI confirmed the breach? No. So far, the FBI has not publicly commented and has not confirmed the existence of the vulnerability, the amount of data allegedly stolen, or the attackers' move to AWS GovCloud. All claims come solely from ShinyHunters.

The case, even if only partially confirmed, shows a new phase in the conflict between cybercriminals and law enforcement agencies: now the public image of the victim itself may be at stake, not just financial gain. The next few hours will show whether the FBI will officially respond and whether Oracle will issue an emergency patch for the reported vulnerability. The SecNews technical team will actively monitor developments.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS