ShinyHunters' stated motive and demand
ShinyHunters claims it compromised an FBI website and stole between about 2 TB and 3 TB of data tied to current, former, and prospective FBI employees. Unlike prior operations by the group that included multimillion-dollar ransom demands, the spokesperson told The Register the group is not seeking extortion payments from the FBI. Instead, ShinyHunters said it wants the Feds to retract statements made in a May 15 FBI bulletin that followed the group's break‑in of Instructure's Canvas platform. “We want the FBI to correct or retract their statements they made, which included substantial false allegations,” the spokesperson said.
Alleged vulnerability: Oracle PeopleSoft preauth RCE on the FBI jobs webpage
According to the ShinyHunters spokesperson, the intrusion began through an Oracle PeopleSoft zero‑day vulnerability on the FBI jobs webpage that allowed remote code execution (RCE) on the servers. The Register received an image of the site defacement; ShinyHunters said the page was replaced with a “This site has been seized by ShinyHunters” banner. At press time the site reportedly displayed a message that it was “currently down for maintenance but will be back up soon!”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleLateral movement and AWS GovCloud managed servers
ShinyHunters told The Register it moved laterally from the compromised jobs site onto the FBI’s managed servers on AWS GovCloud and downloaded the reported 2–3 TB of employee data. The group said the compromised FBI services include human resources, MedLink, and Criminal Justice Information Services. The Register reached out to Oracle and AWS asking whether Oracle is aware of a PeopleSoft preauth RCE zero‑day and whether AWS has insight into the alleged data theft; neither vendor immediately responded to inquiries. The FBI also did not immediately respond to The Register’s request for comment.
FBI bulletin on ShinyHunters and the group's denial
The FBI’s May 15 bulletin — issued shortly after the Canvas incident — warned that ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The same security alert said extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” ShinyHunters told The Register those allegations are false and said it has “been doing my very best to combat these allegations,” framing the FBI intrusion claim as part of that effort.
What this means for technologists, policymakers, and affected employees
- Technologists and security teams: expect immediate scrutiny of Oracle PeopleSoft deployments and any available mitigations for a reported preauth RCE; defenders will also need to examine the claimed lateral movement into AWS GovCloud managed environments.
- Policymakers and regulators: the dispute centers on a federal security bulletin and downstream consequences for victims; attention will fall on vendor‑cloud responsibilities and whether public advisories accurately characterize groups and tactics.
- Affected employees and applicants: according to ShinyHunters, the stolen files include records from human resources, MedLink, and Criminal Justice Information Services — the kinds of data that, if confirmed, could expose personal and employment-related details for current, former, and prospective FBI staff.
The immediate record is short and sharply contested: ShinyHunters says it seized and downloaded terabytes of employee data after exploiting a PeopleSoft RCE on the FBI jobs site and then moved into AWS GovCloud‑hosted servers; the FBI and the named vendors have not publicly confirmed or denied those claims as of The Register’s reporting. The central, tangible demand from the intruders is narrow and specific — a retraction of the May 15 bulletin — and that keeps the next steps tightly focused on three concrete responses the public expects to see: comment or confirmation from the FBI, technical guidance or patch information from Oracle, and cloud‑side visibility from AWS.




