Skip to main content
Emerging ThreatsData Breaches

ShinyHunters Breaches FBI via PeopleSoft Zero-Day Exploit

Neatly organized office with filing cabinets and scattered papers hinting at a data breach.

“all FBI employees and applicants,” the hacking group ShinyHunters wrote on its data leak site, claiming it had taken personnel records from the bureau and posting the assertion as a direct rebuke to an FBI Public Service Announcement published on May 15.

ShinyHunters’ claim: "all FBI employees and applicants"

The group posted its claim on its data leak site and shared a sample of the stolen material with 404 Media, which first reported the story. In that sample — described to 404 Media — ShinyHunters reportedly showed personally identifiable information on about 5,000 FBI employees, including addresses, phone numbers, dates of birth and, in some cases, details on spouses. The group said the action was retaliation for what it described as inaccuracies in the FBI's May 15 PSA.

Sample data and stated motive: 5,000 records and the PSA

ShinyHunters said it was responding to specific claims in the FBI PSA that the group exaggerates access to sensitive information to extract payment, harasses victims and their families, conducts swatting attacks, and falsely claims to possess sensitive or compromising material. The group also denied being part of “The Com.” According to the reporting, the apparent goal of the release was not financial extortion but to force the FBI to take down or amend the PSA.

Attack path: PeopleSoft zero-day to AWS GovCloud — 2–3TB exfiltrated

An FBI spokesperson told 404 Media that the intruders exploited a zero‑day vulnerability in Oracle PeopleSoft and then pivoted to AWS GovCloud servers, downloading roughly 2–3 TB of data. The same reporting says ShinyHunters defaced the FBI jobs website on September 22; at the time of writing the site remained down with a “for maintenance” notice.

Prior PeopleSoft campaign and Exabeam analysis

ShinyHunters has targeted PeopleSoft before. Between May and June, the group exploited a zero‑day in PeopleSoft's Environment Management component to strike dozens of education institutions. Steve Povolny, VP of AI strategy & security research at Exabeam, described that earlier activity this way: “When ShinyHunters burned this vulnerability to hit more than 100 organizations, most of them universities, they later said their original goal had been an FBI PeopleSoft server, and that attempt failed.”

Povolny interprets the September claim as part of a pattern: “Three months later they claim a new PeopleSoft zero‑day. That points to a group systematically mining ERP platforms that hold HR, payroll, applicant, and health data.” He warned PeopleSoft customers to assume compromise and listed concrete detection and mitigation steps.

What this means for PeopleSoft customers, the FBI, and affected employees

  • PeopleSoft customers and security teams: Follow the specific guidance Povolny offered — ensure the fix for the previous zero‑day is applied, disable the Environment Management Hub or remove the PSEMHUB application, and take PeopleSoft admin and integration interfaces off the internet. He urged teams to “hunt instead of waiting for a signature that doesn't exist yet,” to look for suspicious POST activity in WebLogic access logs, unauthorized files in PSEMHUB directories, XMLDecoder‑based persistence, outbound traffic on port 445, and remote‑management agents such as the MeshCentral tooling used for command and control in June. He also advised to “ship logs off‑host, since the attackers claim they wipe local evidence,” evaluate the PeopleSoft host and its service identities for unusual API calls or bulk queries, and be prepared to rotate every secret reachable from those servers.
  • The FBI and its HR/recruiting systems: The FBI spokesperson’s account to 404 Media describes a lateral move from PeopleSoft into AWS GovCloud and a large data download. The bureau also faced a public-facing defacement of its jobs website on September 22 and had the site offline “for maintenance” at the time of reporting — immediate operational priorities include containment, forensic verification of what was taken, and deciding whether to amend the May 15 PSA that ShinyHunters cited as the motive for the action.
  • Affected employees and applicants: The sample shown to 404 Media reportedly included addresses, phone numbers, dates of birth and in some cases spouse details for roughly 5,000 people. Povolny’s advice to defenders — ship logs off‑host, rotate secrets, and prepare to isolate systems quickly — underscores the risk that attackers could attempt to remove local traces, complicating efforts to confirm the full scope of any exposure.

ShinyHunters’ public framing makes the incident as much a contest over narrative as over data: the group says it acted to correct a government PSA it disputes, while the FBI spokesperson described exploitation of a PeopleSoft zero‑day and a subsequent 2–3 TB download from AWS GovCloud. The immediate, concrete steps outlined by Exabeam’s Steve Povolny are focused and technical — apply fixes, isolate vulnerable interfaces, hunt for indicators Povolny named, and be prepared to rotate credentials — but the broader question the facts leave open is whether the bureau will alter the PSA that the group says prompted the breach.

https://www.infosecurity-magazine.com/news/shinyhunters-fbi-hack-peoplesoft/