ShinyHunters Claims a PeopleSoft Zero-Day Breached the FBI
Security / news
ShinyHunters Claims a PeopleSoft Zero-Day Breached the FBI
The extortion group says it took 2 to 3 terabytes of personnel data on the night of Sept. 21, but the bureau has confirmed only that it is investigating a claim.

The extortion group ShinyHunters says it broke into FBI systems on the night of Sept. 21, 2026, using a previously unknown flaw in Oracle PeopleSoft that needed no stolen credentials, then moved from there into the bureau's AWS GovCloud infrastructure to take 2 to 3 terabytes of data. CyberInsider first reported the claim on Sept. 22, and BleepingComputer separately confirmed the group's account through its own contact with ShinyHunters.
The FBI has not confirmed the intrusion. Its statement, reported by both outlets, says only that the bureau "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." That statement does not concede that PeopleSoft was the entry point, that AWS GovCloud was reached, or that any data left the network. Oracle has not published a security advisory naming a new PeopleSoft flaw tied to the incident, and no CVE has been assigned as of this writing.
What ShinyHunters claims it took, service by service
The group's own claims, relayed by both outlets, name four internal FBI systems it says it accessed. None of the figures below have been independently verified.
| FBI service named | What ShinyHunters claims was exposed |
|---|---|
| Criminal Justice (CJ) | Case-linked personnel records |
| Human Resources | Employee and applicant PII |
| Medlink | Health-related employee records |
| apply.fbijobs.gov | The claimed entry point; applicant data |
ShinyHunters posted a screenshot of a page under apply.fbijobs.gov's /PSEMHUB/ path that it says displays Linux system information, calling it the entry point into the FBI's network. The site displayed a maintenance notice after the incident became public.
Why the FBI, and why now
Steve Povolny, vice president of AI strategy and security research at Exabeam, told Infosecurity Magazine that this is not ShinyHunters' first run at an FBI PeopleSoft server. Between May and June 2026, the group exploited a different zero-day in PeopleSoft's Environment Management component and hit more than 100 organizations, mostly universities, an attack Povolny said the group later described as collateral damage from a failed first attempt at breaching the FBI.
The motive this time is not money. ShinyHunters told The Register that "this is NOT financially motivated," and that it wants the FBI to retract a May 15, 2026 public advisory describing the group's harassment tactics, including swatting and threats against victims' families, which ShinyHunters calls false. The group gave the bureau a one-week deadline to comply before it would leak the data.
What happens next
Until Oracle publishes an advisory or the FBI confirms specifics, the only verified facts are the defacement of a page on apply.fbijobs.gov, the FBI's acknowledgment that it is investigating, and the absence of a named CVE. CISA has moved faster on other flaws this month, adding a 9.8-severity bug in lwIP's MQTT client to its exploited-vulnerabilities catalog within a day of disclosure and requiring federal agencies to patch a Windows bug that reaches SYSTEM privileges through Avast's own sandbox on a similarly short clock. No comparable federal deadline exists here, because no agency owns PeopleSoft the way it owns its own Windows fleet.
The one-week deadline ShinyHunters set in its Sept. 22 post falls in the last week of September. Whether it leaks anything on schedule is the next thing to check, not whether its claims are true today.
Sources
More in Security
- 01CISA Gives Agencies 3 Days to Patch an Exploited SharePoint BugMicrosoft rated the flaw a low-risk spoofing issue for 16 days after patching it, and a honeypot logged the first attack four weeks after the correction upgraded it to an 8.8.
- 02CISA Adds a Fourth MikroTrick Bug to Its Exploited ListCVE-2026-67279 joins two other bugs from the same six-flaw MikroTik batch already on CISA's list, but Bishop Fox says it, not the pair flagged in September, is the one that actually opens the door.
- 03OpenClaw's New Scanners Agree on Just 0.69% of Risky SkillsFour audits since February have counted between 341 and 1,467 malicious or flawed skills on ClawHub, and NVIDIA's scanner disagrees with the other two on all but 468 of 67,453 skills checked.
- 04CISA Lists 14 Botslab Dashcam Flaws With No Fix in SightThe worst of the bugs lets a network attacker push firmware with no cryptographic signature onto the device, and Botslab has not told CISA whether it plans to fix any of the 14.