Skip to main content
Data Breaches

ShinyHunters Breach FBI, Exposes Employee Data

Federal government building facade with architectural details in daylight.

“ShinyHunters demanding that the FBI drop its ‘financially motivated’ characterization sounds like reputation management through intimidation,” Kevin Kirkwood, CISO at Exabeam, said.

ShinyHunters' claim and the FBI response

The cybercriminal group ShinyHunters says it hacked the FBI and exposed information belonging to employees and applicants after exploiting what the group described as a zero-day in Oracle PeopleSoft. According to the group, the compromised fields include names, home addresses, phone numbers and spouse information. ShinyHunters told reporters the action was retaliation for a FLASH report that, in the group's view, misstated its activities and tactics.

The FBI has confirmed it is investigating the matter but has not said whether ShinyHunters' claims are true.

Alleged Oracle PeopleSoft zero-day and technical indicators

ShinyHunters said the intrusion exploited a vulnerability in Oracle PeopleSoft. Denis Calderone, CTO at Suzu Labs, recounted elements of the group’s public postings: they displayed a screenshot that suggested administrative components such as the /PSEMHUB/ path were reachable externally and asserted an applicant portal led into GovCloud. Calderone urged PeopleSoft operators to take immediate containment steps: remove PeopleSoft instances from the public internet where possible, put required public elements behind a web application firewall (WAF), and ensure admin components are not reachable from outside.

Calderone also recommended active hunting for the group’s June indicators and monitoring for SSH attempts against the psoft and oracle accounts. ShinyHunters says it plans to use the claimed zero-day more broadly, making those detection and containment steps urgent for PeopleSoft operators and administrators connected to applicant portals.

Reputation, extortion history, and the Clop/Cl0p feud

ShinyHunters framed the FBI intrusion as corrective — pressuring the agency to change language in an advisory that the group disputed — and said the breach was not financially motivated. Security practitioners quoted in the reporting urged caution before accepting that description at face value.

Kevin Kirkwood noted the group’s demand that the FBI not label it as financially motivated “sounds like reputation management through intimidation,” and added that “[a] particular attack can be driven by revenge or publicity without erasing a history of financial extortion.” Kirkwood pointed to a reported prior demand: “demanded an eight-figure payment from Clop,” which he described as an awkward backdrop for protesting the label.

Denis Calderone placed the claimed FBI incident in the context of a recent feud: ShinyHunters “took over Cl0p’s leak site and put up a ‘seized by ShinyHunters’ banner,” and by the following Tuesday the same banner reportedly appeared on the FBI’s jobs portal. Calderone warned that despite ShinyHunters’ protestations, the group’s recent behavior — taking on rival gangs and making public seizures — fits a pattern of using breaches to escalate reputation and leverage.

Calderone also observed that “Foreign intelligence services would love to have it,” referring to the potential value of terabytes of FBI personnel data if the theft is real.

What this means for PeopleSoft operators, federal IT teams, and FBI employees

  • PeopleSoft operators: Remove exposed PeopleSoft instances from the public internet where feasible, place public-facing components behind a WAF, and verify admin paths such as /PSEMHUB/ are unreachable from outside. Hunt for June indicators and monitor SSH login attempts against psoft and oracle accounts.
  • Federal IT and cloud teams: Audit applicant portals for lateral access into GovCloud environments and limit the blast radius of applications that accept external uploads. Calderone warned that an applicant portal “allegedly led straight into GovCloud,” a configuration that operators should verify and, if necessary, segment immediately.
  • FBI employees and applicants: The data the group says it exposed includes names, home addresses, phone numbers and spouse information. The FBI is investigating but has not confirmed the claims; Calderone cautioned that “agents and their spouses could have their home addresses posted publicly within a week if this threat is followed through.”

Investigation, verification, and mitigation priorities

The immediate next steps, as reflected in the voices quoted here, are investigative verification and defensive containment. The FBI’s investigation will need to establish whether the claims are accurate and, if so, identify the exploited PeopleSoft vulnerability and the scope of data access. Calderone emphasized isolation and hardening of PeopleSoft instances, while Kirkwood urged defenders to prioritize protecting potentially affected people over accepting attackers’ chosen motive narratives: “Whether the demanded payment is cash or a public correction, stolen information remains the bargaining chip.”

How quickly the FBI can validate the claim, stop any further exposure of personal data and patch or mitigate an exploited zero-day will determine whether the episode becomes a short-lived provocation or a wider operational crisis for personnel and affiliated services.

Source: Security Magazine — FBI Hacked, Employee Data Reportedly Exposed