ShinyHunters claims new PeopleSoft zero-day used to breach FBI systems
The ShinyHunters extortion group told BleepingComputer it exploited a new remote-code-execution flaw in Oracle PeopleSoft to access FBI systems and move into FBI-managed AWS GovCloud infrastructure, claiming theft of 2-3TB of data including employee, applicant, HR and Medlink records. The group shared a screenshot showing the FBI Jobs site defaced with its logo and a message asserting sensitive PII/PHI had been stolen, and said the FBI quickly took the affected systems offline.
GoKawiil's interpretation of the reporting above, not reported fact.
BleepingComputer says it has not independently verified the alleged zero-day, the lateral movement, or the volume of stolen data, so the claims remain unconfirmed. If accurate, the group's assertion that it is exploiting the same flaw against other organizations, including Fortune 500 companies, suggests a potentially broad supply-chain-style risk tied to widely used PeopleSoft software.
- ShinyHunters claims to have used an unverified PeopleSoft zero-day to breach FBI systems and AWS GovCloud infrastructure.
- The group alleges theft of 2-3TB of data covering FBI employees, applicants and internal HR/Medlink records.
- The claims, including a defaced FBI Jobs page, remain unconfirmed by BleepingComputer, while ShinyHunters says the exploit is now being used against other organizations.
Source: bleepingcomputer.com, 2026-09-22
Published there as: “ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.