Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    September 22, 2026

    ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

    September 22, 2026

    People Training OpenAI’s AI Fired for Using AI to Train the AI

    September 22, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
    News

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    adminBy adminSeptember 22, 2026No Comments6 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    FBI

    The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.

    The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

    ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.

    The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion.

    ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies.

    BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

    However, ShinyHunters shared a screenshot with BleepingComputer showing the FBI Jobs website at apply.fbijobs.gov defaced with the group’s Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised.

    The defacement stated, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since ’19 ;)”.

    Allegedly defaced FBI Jobs website
    Allegedly defaced FBI Jobs website
    Source: ShinyHunters

    The message further claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen.

    “All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information,” read a message on the defaced site.

    “We have a lot more than what we claim here. Thank you for your attention to this matter.”

    ShinyHunters told BleepingComputer that the FBI quickly became aware of the intrusion, immediately took affected systems offline, and that the FBI Jobs site now displays a maintenance message.

    The group also claimed that access to multiple FBI networks was terminated simultaneously after the agency detected the intrusion.

    “They literally pulled the plug on everything,” ShinyHunters said.

    The threat actors shared two sample records with BleepingComputer that the group claims were stolen during the attack, including data allegedly associated with FBI personnel.

    One record allegedly contained information associated with an FBI special agent involved in a previous BreachForums investigation, while another allegedly contained information associated with FBI Director Kash Patel.

    BleepingComputer is not publishing the personal information contained in those records and has not independently verified their authenticity or source.

    404 Media first reported the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records.

    The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.

    Alleged PeopleSoft zero-day

    ShinyHunters claims they gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched.

    “The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI,” ShinyHunters told BleepingComputer.

    The group also claims it tried to erase evidence of its activity from compromised servers to make the zero-day harder to identify.

    ShinyHunters also told BleepingComputer that it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after targeting the education sector.

    ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise.

    These systems allegedly include the FBI’s AWS GovCloud environment, which was used to store employee and applicant information.

    BleepingComputer has contacted Oracle and Google Cloud’s Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity.

    Retaliation over FBI report

    ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an FBI FLASH report detailing ShinyHunters that was published in May 2026.

    ShinyHunters statement about FBI attack
    ShinyHunters statement about FBI attack
     Source: BleepingComputer

    The group disputes claims that ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material.

    The threat actors denied those allegations and also rejected claims that it is part of “The Com,” a loose-knit cybercrime community frequently tied to data breaches, cryptocurrency theft attacks, and commonly referenced by law enforcement and security researchers.

    In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion.

    When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say.

    “No comment,” the threat actor told BleepingComputer.

    When BleepingComputer asked the main representative of the ShinyHunters extortion gang whether they were concerned this would lead to increased pressure from the US government to apprehend them, they responded, “I don’t care.”

    When another ShinyHunters member involved in the attack was asked the same questions, the threat actor appeared unconcerned.

    “I dont think they have much room to do anything to me personally,” the affiliate told BleepingComputer.

    “If im wrong, then so be it. I made my choices knowing exactly what could come with them, and Im prepared to accept whatever consequences follow (if any).”

    The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability.

    During Clop’s 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself “Scattered Lapsus$ Hunters” that leaked a proof-of-concept exploit later confirmed by Oracle to match one used in the attacks.

    ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization.

    That dispute resurfaced last week when ShinyHunters breached and defaced Clop’s data leak site, claiming it stole server data and the private keys for its Tor onion service.

    The group subsequently added Clop to its own leak site and threatened to extort the ransomware operation, saying the attack was retaliation for threats allegedly made during the Oracle E-Business Suite campaign.

    BleepingComputer has contacted the FBI, Oracle, and Google Cloud’s Mandiant threat intelligence team regarding the alleged breach and PeopleSoft zero-day and will update this story if we receive a response.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
    admin
    • Website

    Related Posts

    News

    ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

    September 22, 2026
    News

    People Training OpenAI’s AI Fired for Using AI to Train the AI

    September 22, 2026
    News

    InfoSec News Nuggets – 09/22/2026

    September 22, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    September 22, 2026

    ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees

    September 22, 2026

    People Training OpenAI’s AI Fired for Using AI to Train the AI

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.