Skip to main content
Emerging ThreatsMalware & Ransomware

ShinyHunters Breach FBI Systems with Oracle PeopleSoft Zero-Day

Dimly lit server room with rows of computer equipment, symbolizing a breached government IT infrastructure.

ShinyHunters claims it stole between 2TB and 3TB of data from FBI systems after exploiting an unpatched Oracle PeopleSoft zero-day, including "sensitive PII/PHI on incumbent and former FBI employees and all applicant information," the group told BleepingComputer.

How ShinyHunters says it gained access

The extortion gang told BleepingComputer it used what it described as a new Oracle PeopleSoft zero-day that allows remote code execution to access FBI systems on a Monday night, then moved laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters said it exploited the vulnerability immediately after finding it and that it attempted to erase evidence on compromised servers "to make the zero-day harder to identify."

BleepingComputer has not independently verified the alleged zero-day, the group's claimed lateral movement, or the volume of stolen data. The outlet contacted Oracle and Google Cloud's Mandiant threat intelligence team and the FBI to determine whether they were aware of the vulnerability or related exploitation activity.

What ShinyHunters says it took and where

The group claims the theft included between 2TB and 3TB of material spanning FBI Criminal Justice, HR, Medlink, and "additional services." ShinyHunters told BleepingComputer that employee records, information on job applicants, and health-related records were among the data accessed.

ShinyHunters shared two sample records with BleepingComputer that it said were taken during the attack — one allegedly associated with an FBI special agent involved in a previous BreachForums investigation and another allegedly associated with FBI Director Kash Patel. BleepingComputer is not publishing the personal information contained in those records and has not independently verified their authenticity or source.

404 Media first reported the alleged breach after receiving a sample of roughly 5,000 purported FBI employee records; that publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.

Defacement, detection, and the FBI's immediate response

ShinyHunters shared a screenshot with BleepingComputer showing the FBI Jobs site at apply.fbijobs.gov defaced with the group's Umbreon Pokémon logo and a message stating, "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)" The defacement included a claim that "All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information" and the line, "We have a lot more than what we claim here. Thank you for your attention to this matter."

The threat actors told BleepingComputer the FBI "quickly became aware of the intrusion, immediately took affected systems offline," and that the FBI Jobs site now displays a maintenance message. ShinyHunters added that access to multiple FBI networks was terminated simultaneously after the agency detected the activity, saying, "They literally pulled the plug on everything."

Retaliation over an FBI FLASH report and related claims

ShinyHunters later published a lengthy statement on its data leak site framing the alleged attack as retaliation for an FBI FLASH report about the group published in May 2026. The group denied allegations commonly made against it — that actors exaggerate access to sensitive information, harass victims and relatives, conduct swatting attacks, or falsely claim compromising material — and rejected being part of "The Com," a community the statement said is frequently tied to data breaches and other criminal activity.

In the statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report and asserted the demand was not financially motivated and "was not extortion." When BleepingComputer asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to say, responding "No comment." When asked whether the incident would lead to increased pressure from the US government to apprehend them, one representative told BleepingComputer, "I don't care," while an affiliate said, "I dont think they have much room to do anything to me personally," adding they were prepared to accept whatever consequences might follow.

What this means for technologists, policymakers, and affected applicants and employees

  • Technologists and security teams: The group's claim centers on an unpatched PeopleSoft remote code execution zero-day and subsequent lateral movement into AWS GovCloud. Teams using PeopleSoft or hosting sensitive HR and applicant systems in cloud environments should watch for confirmation from vendors and intelligence teams and examine logs for indicators consistent with the intrusion method ShinyHunters described.
  • Policymakers and agency decision-makers: The incident, as framed by ShinyHunters, is tied to a dispute over an FBI FLASH report and includes a public demand to alter that report. Policy officials will need to weigh remedial actions and communications strategies while vendor and cloud-provider engagement proceeds.
  • Affected applicants and employees: The group claims access to PII and PHI on incumbent and former FBI employees and to applicant records. Media outlets and security researchers have received samples and verified elements of some records, but outlets that received samples—BleepingComputer and 404 Media—noted they had not independently validated the full scope or provenance of the alleged dataset.

The claims, if true, describe a substantial compromise targeting an agency's HR and applicant systems via an unpatched Oracle PeopleSoft vulnerability and subsequent movement into cloud-hosted infrastructure. Key facts from BleepingComputer's reporting remain unverified: whether the zero-day exists, the exact volume and provenance of the stolen data, and how broadly the group has used the same vulnerability against other organizations. Oracle, Google Cloud's Mandiant team, and the FBI were contacted by BleepingComputer; responses will determine whether the technical details behind ShinyHunters' claims are corroborated.

Original reporting: BleepingComputer