Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    September 23, 2026

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Discord’s age verification era is upon us, despite community backlash
    • Only 13% of OT Network Segments Are Fully Isolated: Analysis
    • Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says
    • Reptiles, gold and money: How Australia is cracking down on wildlife trafficking
    • Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott
    • Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales
    • UK to fight Russian disinformation and push new global AI standards, Burnham says
    • Data centres: Developers hope fibre optics will cut power use
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Update: Added the FBI’s statement below.

    The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.

    The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

    ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.

    The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion.

    ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies.

    BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

    The FBI confirmed to BleepingComputer that it is investigating the claims but did not confirm whether its systems were breached or data was stolen.

    “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the FBI told BleepingComputer.

    However, ShinyHunters shared a screenshot with BleepingComputer showing the FBI Jobs website at apply.fbijobs.gov defaced with the group’s Umbreon Pokémon logo and a message claiming that FBI employee and applicant information had been compromised.

    The defacement stated, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since ’19 ;)”.

    Allegedly defaced FBI Jobs website
    Allegedly defaced FBI Jobs website
    Source: ShinyHunters

    The message further claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen.

    “All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information,” read a message on the defaced site.

    “We have a lot more than what we claim here. Thank you for your attention to this matter.”

    ShinyHunters told BleepingComputer that the FBI quickly became aware of the intrusion, immediately took affected systems offline, and that the FBI Jobs site now displays a maintenance message.

    The group also claimed that access to multiple FBI networks was terminated simultaneously after the agency detected the intrusion.

    “They literally pulled the plug on everything,” ShinyHunters said.

    The threat actors shared two sample records with BleepingComputer that the group claims were stolen during the attack, including data allegedly associated with FBI personnel.

    One record allegedly contained information associated with an FBI special agent involved in a previous BreachForums investigation, while another allegedly contained information associated with FBI Director Kash Patel.

    BleepingComputer is not publishing the personal information contained in those records and has not independently verified their authenticity or source.

    404 Media first reported the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records.

    The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.

    Alleged PeopleSoft zero-day

    ShinyHunters claims they gained initial access through a new zero-day vulnerability in Oracle PeopleSoft that remains unpatched.

    “The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI,” ShinyHunters told BleepingComputer.

    The group also claims it tried to erase evidence of its activity from compromised servers to make the zero-day harder to identify.

    ShinyHunters also told BleepingComputer that it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after targeting the education sector.

    ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise.

    These systems allegedly include the FBI’s AWS GovCloud environment, which was used to store employee and applicant information.

    BleepingComputer has contacted Oracle and Google Cloud’s Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity.

    Retaliation over FBI report

    ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an FBI FLASH report detailing ShinyHunters that was published in May 2026.

    ShinyHunters statement about FBI attack
    ShinyHunters statement about FBI attack
     Source: BleepingComputer

    The group disputes claims that ShinyHunters actors may exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material.

    The threat actors denied those allegations and also rejected claims that it is part of “The Com,” a loose-knit cybercrime community frequently tied to data breaches, cryptocurrency theft attacks, and commonly referenced by law enforcement and security researchers.

    In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion.

    When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say.

    “No comment,” the threat actor told BleepingComputer.

    When BleepingComputer asked the main representative of the ShinyHunters extortion gang whether they were concerned this would lead to increased pressure from the US government to apprehend them, they responded, “I don’t care.”

    The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability.

    During Clop’s 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself “Scattered Lapsus$ Hunters” that leaked a proof-of-concept exploit later confirmed by Oracle to match one used in the attacks.

    ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization.

    That dispute resurfaced last week when ShinyHunters breached and defaced Clop’s data leak site, claiming it stole server data and the private keys for its Tor onion service.

    The group subsequently added Clop to its own leak site and threatened to extort the ransomware operation, saying the attack was retaliation for threats allegedly made during the Oracle E-Business Suite campaign.

    BleepingComputer has contacted Oracle and Google Cloud’s Mandiant threat intelligence team regarding the alleged breach and PeopleSoft zero-day and will update this story if we receive a response.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    breach claims data FBI hack PeopleSoft ShinyHunters theft ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    Data centres: Developers hope fibre optics will cut power use

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Snorkel AI triples valuation to $3.5B as demand for AI training data booms

    Rogue external MFA providers can steal passwords during logins

    A proposed data center is changing the conversation in this Indiana farming community

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    September 23, 2026

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Discord’s age verification era is upon us, despite community backlash

    September 23, 2026

    Only 13% of OT Network Segments Are Fully Isolated: Analysis

    September 23, 2026

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.