securityonline.info 24 Sept 2026, 08:18 UTC

ShinyHunters Claims FBI Breach Exploited Oracle PeopleSoft Zero Day

ShinyHunters Claims FBI Breach Exploited Oracle PeopleSoft Zero Day
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor

SHINYHUNTERS has claimed that it breached the US Federal Bureau of Investigation (FBI), exploiting what it describes as an undisclosed, unpatched zero-day vulnerability in Oracle PeopleSoft. The group alleges that the compromise began through the FBI’s recruitment portal, which stores candidates’ CVs and other application documents, before attackers moved laterally into an AWS GovCloud environment managed by the Bureau.

The attackers claim to have taken between two and three terabytes of data, including records relating to current and former FBI employees and people who had applied for jobs. They also say the operation was retaliation for an FBI security alert about ShinyHunters issued in May, rather than a financially motivated attack. However, the claims have not been independently verified. The article says the FBI, Amazon Web Services and Oracle had not issued official statements at the time of publication.

An FBI spokesperson reportedly acknowledged awareness of the allegations but said an investigation was under way and that the agency could not yet confirm whether its networks had been breached or sensitive information compromised.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline