ShinyHunters Claims FBI Breach Used an Oracle PeopleSoft Zero-Day
The ShinyHunters extortion group claims it exploited a new, unpatched vulnerability in Oracle PeopleSoft to breach FBI systems, access internal services, and steal sensitive information belonging to FBI employees and job applicants.
The attackers told BleepingComputer that the alleged PeopleSoft zero-day allowed remote code execution. They claim they used it Monday night to gain initial access to FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.
ShinyHunters claims to have stolen between 2TB and 3TB of data, including information about current and former FBI employees, job applicants, and other internal records.
The group also claims it compromised the FBI’s Criminal Justice Division, Office of Human Resources, Medlink, and other services during the alleged breach.
ShinyHunters further claims to have exploited the same alleged zero-day against other organizations, including Fortune 500 companies.
BleepingComputer has not independently verified the alleged PeopleSoft vulnerability, the claimed lateral movement, or the amount and authenticity of the data allegedly stolen.
FBI job website allegedly defaced
ShinyHunters shared a screenshot with BleepingComputer that appears to show the FBI recruiting website, apply.fbijobs.gov, defaced with the group’s Umbreon Pokémon logo.
The message claimed that information belonging to FBI employees and job applicants had been compromised.
The defacement read:
“This site has been taken over by SHINYHUNTERS. I have rooted my system since ’19;).”

Source: ShinyHunters
The message also claimed that sensitive personally identifiable information (PII) and health-related information (PHI) belonging to FBI employees and applicants had been stolen.
“All FBI data has been compromised, including sensitive PII/PHI of current and former FBI employees and all applicant information,” the defaced website message said.
“We have more than we claim here. Thank you for bringing this issue to our attention.”
ShinyHunters told BleepingComputer that the FBI quickly detected the intrusion and took affected systems offline. A maintenance message was reportedly displayed on the FBI job website after the incident.
The group also claimed that access to multiple FBI networks was suspended after the intrusion was detected.
“They literally pulled the plug on everything,” ShinyHunters said.
Attackers share alleged FBI personnel records
The attackers shared two sample records with BleepingComputer that they claimed were stolen during the alleged attack. The records allegedly contained information related to FBI personnel.
One record allegedly concerned an FBI special agent involved in a previous BreachForums investigation. The other allegedly contained information related to FBI Director Kash Patel.
BleepingComputer does not publicly display the personal information contained in the samples and has not independently verified their authenticity or source.
404 Media first reported the alleged breach after receiving samples containing approximately 5,000 records purportedly belonging to FBI agents.
The publication said it confirmed that some information in the sample appeared accurate, including phone numbers corresponding to people with the same names and phone numbers associated with U.S. Department of Justice officials.
ShinyHunters claims PeopleSoft zero-day enabled access
ShinyHunters claims it gained initial access through a new, unpatched zero-day vulnerability in Oracle PeopleSoft.
“The Oracle product we exploited in our zero-day was PeopleSoft. We discovered another product yesterday and immediately exploited it with the FBI,” ShinyHunters told BleepingComputer.
The group also claims it attempted to erase evidence of its activity from compromised servers, which it said could make the alleged zero-day exploitation more difficult to identify.
ShinyHunters told BleepingComputer that it is targeting enterprises and Fortune 500 companies using the same alleged PeopleSoft vulnerability. The group has also claimed attacks targeting the education sector. Google Cloud details activity targeting the education sector.
According to ShinyHunters, the allegedly stolen FBI data came from systems accessed after the initial PeopleSoft intrusion.
Those systems allegedly included an FBI AWS GovCloud environment used to store employee and applicant information.
BleepingComputer contacted Oracle and Google Cloud’s Mandiant threat intelligence team to ask whether they are aware of a new PeopleSoft vulnerability or related exploitation activity.
ShinyHunters claims attack was retaliation for FBI report
ShinyHunters later published a statement on its data leak site claiming that the alleged attack was carried out in retaliation for an FBI report about the group. The FBI FLASH report on ShinyHunters was published in May 2026.

Source: BleepingComputer
The group disputed claims that ShinyHunters members may exaggerate their access to sensitive information, harass victims and their relatives, conduct swatting attacks, or falsely claim to possess dangerous material.
The attackers also denied claims that the group is part of “The Com,” a loosely organized cybercrime community frequently linked to data breaches and cryptocurrency theft attacks and often referenced by law enforcement and security researchers.
In its statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report. The group maintained that its demand was not financially motivated and did not constitute extortion.
When asked whether it would release the allegedly stolen FBI data if the report was not changed, ShinyHunters declined to comment.
“No comment,” the threat actor told BleepingComputer.
When BleepingComputer asked representatives of the ShinyHunters extortion group whether they were concerned that the alleged attack could increase pressure from the U.S. government to arrest them, they said they “don’t care.”
ShinyHunters’ history of alleged Oracle exploitation
The alleged PeopleSoft zero-day is not the first time ShinyHunters has been linked to the exploitation of previously unknown Oracle vulnerabilities.
During Clop’s 2025 Oracle E-Business Suite data theft campaign, ShinyHunters, as part of a group calling itself “Scattered Lapsus$ Hunters,” leaked a proof-of-concept exploit that Oracle later confirmed matched the exploit used in the attack.
ShinyHunters later told BleepingComputer that the exploit originally belonged to the group and had been obtained by the Clop ransomware operation without permission.
The dispute resurfaced last week when ShinyHunters claimed to have infiltrated and defaced Clop’s data leak site, stealing server data and private keys for Tor onion services.
The group then added Clop to its own leak site and threatened to coerce the ransomware operation, saying the alleged attack was retaliation for threats made during the Oracle E-Business Suite campaign.
BleepingComputer has contacted the FBI, Oracle, and Google Cloud’s Mandiant threat intelligence team regarding the alleged FBI breach and the claimed PeopleSoft zero-day. This article will be updated if the organizations respond.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



