AIO APEX

ShinyHunters claims 2–3TB FBI breach via Oracle PeopleSoft zero-day, now targeting Fortune 500

BleepingComputer
Share:
ShinyHunters claims 2–3TB FBI breach via Oracle PeopleSoft zero-day, now targeting Fortune 500

The ShinyHunters extortion gang has claimed responsibility for a breach of FBI systems, alleging it used an unpatched Oracle PeopleSoft zero-day vulnerability to gain remote code execution access Monday night (September 22). The group says it stole between 2TB and 3TB of data before the FBI detected the intrusion and pulled systems offline.

According to ShinyHunters, the initial access came through a PeopleSoft zero-day that allows unauthenticated remote code execution. From there, the group says it moved laterally into FBI-managed AWS GovCloud infrastructure, compromising FBI Criminal Justice, HR, and Medlink services among others. As evidence, it provided BleepingComputer with screenshots showing the FBI Jobs website defaced with the group's Umbreon Pokémon logo and a message reading: "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19."

The FBI confirmed to BleepingComputer it is investigating the claims, stating: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." The agency did not confirm whether systems were breached or data was stolen, and the FBI Jobs site now displays a maintenance message.

404 Media, which first reported the alleged breach, said it received a sample containing approximately 5,000 purported FBI employee records and verified that some phone numbers in the sample corresponded to people with matching names and DOJ-associated numbers. BleepingComputer separately received two sample records — one allegedly associated with an FBI special agent involved in a prior BreachForums investigation, and one allegedly containing data tied to FBI Director Kash Patel. BleepingComputer declined to publish the personal information and has not independently verified authenticity.

The wider threat is the critical detail: ShinyHunters told BleepingComputer it is actively using the same unpatched Oracle PeopleSoft zero-day against Fortune 500 companies and says it found a second exploitable vulnerability in the product the day after the FBI breach. The group has historically followed FBI-targeted operations by releasing stolen data publicly or attempting extortion — it was responsible for, among others, the 2024 Ticketmaster breach affecting 560 million customers.

Oracle PeopleSoft is widely deployed in enterprise HR, finance, and government systems. As of publication, Oracle had not issued an advisory, and no CVE has been assigned to the alleged vulnerability. Organizations running PeopleSoft should review access logs and apply network-level controls while awaiting an official response from Oracle.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share:
ShinyHunters claims 2–3TB FBI breach via Oracle PeopleSoft zero-day, now targeting Fortune 500 | AIO APEX