www.infosecurity-magazine.com 23 Sept 2026, 10:00 UTC

ShinyHunters Claims FBI Breach Exploited Oracle PeopleSoft Zero-Day

ShinyHunters Claims FBI Breach Exploited Oracle PeopleSoft Zero-Day
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

SHINYHUNTERS has claimed it breached the FBI using a zero-day vulnerability in Oracle PeopleSoft and stole data relating to “all FBI employees and applicants”. The group published the claim on its leak site, saying the attack was retaliation for an FBI public service announcement dated 15 May, which accused it of exaggerating access to sensitive information, harassing victims and their families, carrying out swatting attacks and making false claims.

It also denied being part of “The Com.” The group reportedly shared a sample with 404 Media containing personal information on 5,000 FBI employees, including addresses, telephone numbers, dates of birth and, in some cases, spouses’ details. It also defaced the FBI jobs website on 22 September; the site was reportedly still down for maintenance when the report was written. The stated objective appears to be forcing the FBI to amend or remove the PSA, rather than financial extortion.

An FBI spokesperson told 404 Media that the attackers exploited a PeopleSoft zero-day, then moved to AWS GovCloud servers and downloaded 2–3TB of data. The claim had not been independently confirmed in the supplied report. ShinyHunters previously exploited a zero-day in PeopleSoft’s Environment Management component between May and June against dozens of education organisations, reportedly more than 100 according to Exabeam’s Steve Povolny.

He advised PeopleSoft customers to apply the earlier fix, disable Environment Management Hub or remove the PSEMHUB application, take administrative and integration interfaces off the internet, and investigate WebLogic POST requests, unauthorised PSEMHUB files, XMLDecoder persistence, port 445 traffic, remote-management tools, unusual API calls, bulk queries and authentications. He also recommended off-host logging and preparing to rotate secrets accessible from affected servers.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline