The ShinyHunters extortion gang says it compromised FBI systems on Monday night through an unpatched remote code execution flaw in Oracle PeopleSoft, pivoted into FBI-managed AWS GovCloud infrastructure, and stole 2TB to 3TB of employee and applicant data. The FBI says it is investigating claims affecting FBIjobs.gov but has not confirmed a breach, and the alleged zero-day, lateral movement, and theft volume remain unverified.

Claimed initial access and lateral movement

According to statements made to BleepingComputer, the actors describe the issue as a new Oracle PeopleSoft zero-day permitting remote code execution that is still unpatched. They said they exploited it Monday night for first entry into FBI systems and then moved laterally into the agency's AWS GovCloud environment.

ShinyHunters stated:

"The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI,"

The group claims data was taken from systems reached after that PeopleSoft compromise, including the AWS GovCloud environment said to hold employee and applicant information. It also claims it attempted to wipe traces from compromised servers to complicate identification of the flaw.

The claimed scope includes FBI Criminal Justice, HR, Medlink, and additional services. The reported theft total is between 2TB and 3TB, described as covering current and former FBI employees, job applicants, and other internal records. BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

The same actors claim they are now using the alleged PeopleSoft flaw against additional targets, including Fortune 500 companies, after prior activity aimed at the education sector.

Defacement of jobs site and sample data

ShinyHunters provided a screenshot showing the FBI Jobs website at apply.fbijobs.gov altered to display the group's Umbreon Pokémon logo with a notice asserting compromise of employee and applicant information.

The defacement text read:


THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)

A further notice on the altered site read:

"All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information,"

It continued:

"We have a lot more than what we claim here. Thank you for your attention to this matter."

The actors said the FBI rapidly noticed the activity, disconnected impacted systems, and placed the Jobs site into maintenance. They said entry to multiple FBI networks was cut off at once, adding:

"They literally pulled the plug on everything,"

The FBI told BleepingComputer:

"The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,"

The agency did not confirm breach or theft.

Two sample records allegedly taken in the intrusion were shared with BleepingComputer. One was described as linked to an FBI special agent connected to a prior BreachForums investigation, the other as linked to FBI Director Kash Patel. BleepingComputer did not publish personal details from those records and has not independently verified their authenticity or source.

404 Media first reported the alleged breach after obtaining a sample said to hold approximately 5,000 purported FBI employee records. That outlet reported partial corroboration, including phone numbers matching individuals with the same names and numbers tied to US Department of Justice personnel.

Retaliation claim tied to May 2026 FLASH report

ShinyHunters later posted an extended statement on its data leak site describing the operation as retaliation for an FBI FLASH report about ShinyHunters published in May 2026.

The group contested assertions that its members exaggerate access to sensitive information, harass victims and relatives, carry out swatting attacks, and falsely assert possession of compromising material. It denied those assertions and rejected characterization as part of "The Com," described as a loose-knit cybercrime community often associated by law enforcement and security researchers with data breaches and cryptocurrency theft attacks.

In that statement the group set a one-week deadline for the FBI to correct or withdraw the FLASH report, while insisting the demand was not financially driven and was not extortion. Asked if it would publish the allegedly stolen FBI data absent changes to the report, the actor replied:

"No comment,"

Asked if heightened pursuit by the US government was a concern, the primary representative answered:

"I don't care."

BleepingComputer said it contacted Oracle and Google Cloud's Mandiant threat intelligence team about the alleged breach and PeopleSoft zero-day.

Prior Oracle exploitation dispute

The account notes this would not be the first association between ShinyHunters and use of a previously unknown Oracle flaw.

During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters participated in a collective calling itself "Scattered Lapsus$ Hunters" that disclosed a proof-of-concept exploit later confirmed by Oracle to correspond to one used in those attacks. For background, see Oracle patches EBS zero-day exploited in Clop data-theft attacks.

ShinyHunters later said that exploit had originally been theirs and that the Clop ransomware gang had taken it without permission. That conflict re-emerged last week when ShinyHunters breached and defaced Clop's data leak site, asserting theft of server data and private keys for its Tor onion service. Details are in ShinyHunters hacks Clop leak site, threatens to extort ransomware gang. The group then listed Clop on its own leak site and threatened to extort that operation, framing the move as retaliation for threats allegedly issued during the Oracle E-Business Suite campaign.

Related context cited in the source material includes ShinyHunters hacker reportedly detained in Jordan, aiding FBI, Frontline Education data breach impacts school district employees, FBI tells ShinyHunters members to turn themselves in after recent arrest, ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks, and Florida confirms DMV database breached via stolen police account.

Technical background

This section is general background on this vulnerability class, not findings about this specific incident. No PoC, affected versions, patches, or indicators for this alleged PeopleSoft zero-day were supplied in the source.

PeopleSoft deployments typically expose a large HTTP-facing application surface with authentication, integration, and reporting endpoints fronted by web servers and a Web Application Firewall. Historic RCE patterns in such enterprise stacks involve unauthenticated or low-privilege requests reaching deserialization, template evaluation, file upload, or integration handlers, followed by execution in the application-server context.

Illustrative generic defensive checks, not incident-specific, include reviewing externally reachable PeopleSoft endpoints and WAF decisions:


# generic illustration only - list listening app endpoints and recent WAF blocks
ss -tlnp | grep -E ':80|:443|:8000|:9000'
journalctl -u waf --since "7 days ago" | grep -i -E 'block|bypass|peoplesoft' | head -n 50

Operators should inventory internet-facing PeopleSoft hosts, enforce current Oracle Critical Patch Updates, restrict integration and file-upload endpoints, centralize application and WAF logs, and hunt for unexpected child processes, encoded payloads, or post-exploitation cleanup such as log deletion. Any PeopleSoft-specific patch or detection guidance should come from an Oracle advisory or Mandiant update once available.

Detection and mitigation

No vendor fix, affected versions, hashes, IPs, domains, file paths, or detection signatures for this claimed flaw were included in the supplied material. Until Oracle or Mandiant confirms details, treat the claims as unvalidated.

Preserve web, application-server, and AWS GovCloud audit logs, retain images of potentially affected PeopleSoft hosts before rebuilding, monitor apply.fbijobs.gov and internal HR, Criminal Justice, and Medlink services for anomalous accounts or bulk exports, and watch for large outbound transfers consistent with the asserted 2TB to 3TB theft. Isolate rather than delete suspect systems to avoid losing forensic evidence relevant to zero-day identification.