ShinyHunters, an extortion-focused threat group, claims to have breached FBI systems by exploiting a previously unknown vulnerability in Oracle PeopleSoft. According to the group's account to BleepingComputer, the flaw enables remote code execution and was used Monday night to gain initial access before the attackers moved laterally into FBI-managed AWS GovCloud infrastructure.

The group asserts it obtained between 2TB and 3TB of data during the intrusion, including records on current and former FBI employees, job applicants, and other internal documents. ShinyHunters also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services. The attackers further state they are now deploying the same alleged zero-day against other targets, including Fortune 500 firms.

BleepingComputer has not independently confirmed the existence of the zero-day, the lateral movement claims, or the volume of stolen data. However, the group provided a screenshot showing the FBI Jobs website at apply.fbijobs.gov defaced with ShinyHunters' Umbreon Pokémon logo and a message stating that FBI employee and applicant information had been compromised.

THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)

message on the defaced FBI Jobs website

Allegedly defaced FBI Jobs website
Allegedly defaced FBI Jobs websiteSource: ShinyHunters

The defacement message claimed that sensitive personally identifiable and health-related information belonging to FBI employees and applicants had been stolen. According to the posted statement, "All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information," and "We have a lot more than what we claim here. Thank you for your attention to this matter."

ShinyHunters told BleepingComputer that the FBI detected the intrusion quickly, took affected systems offline, and that the FBI Jobs site now displays a maintenance message. The group claimed that access to multiple FBI networks was terminated simultaneously following detection. "They literally pulled the plug on everything," ShinyHunters said.

The threat actors shared two sample records with BleepingComputer that they claim were stolen, including data allegedly associated with FBI personnel. One record allegedly belonged to an FBI special agent involved in a previous BreachForums investigation, while another allegedly contained information associated with FBI Director Kash Patel. BleepingComputer is not publishing the personal information and has not independently verified authenticity or source.

404 Media first reported the alleged breach after receiving a sample containing approximately 5,000 purported FBI employee records. The publication verified that some information in the sample was accurate, including phone numbers corresponding to people with matching names and numbers associated with US Department of Justice personnel.

Alleged PeopleSoft zero-day

ShinyHunters claims initial access came through a new, unpatched zero-day vulnerability in Oracle PeopleSoft. "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," ShinyHunters told BleepingComputer.

The group also claims it attempted to erase evidence of its activity from compromised servers to make the zero-day harder to identify. ShinyHunters stated it is now using the same alleged PeopleSoft vulnerability to target corporations and Fortune 500 companies after previously targeting the education sector.

ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise, including the FBI's AWS GovCloud environment, which allegedly stored employee and applicant information. BleepingComputer has contacted Oracle and Google Cloud's Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity.

Retaliation over FBI report

ShinyHunters statement about FBI attack
ShinyHunters statement about FBI attack Source: BleepingComputer

ShinyHunters later published a lengthy statement on its data leak site claiming the attack was retaliation for an FBI FLASH report detailing ShinyHunters that was published in May 2026. The group disputes claims that ShinyHunters actors exaggerate access to sensitive information, harass victims and their relatives, conduct swatting attacks, and falsely claim to possess compromising material.

The threat actors denied those allegations and also rejected claims that the group is part of "The Com," a loose-knit cybercrime community frequently tied to data breaches, cryptocurrency theft attacks, and commonly referenced by law enforcement and security researchers. In its statement, ShinyHunters gave the FBI one week to correct or remove the FLASH report, while claiming the demand was not financially motivated and was not extortion.

When asked whether the group would release the allegedly stolen FBI data if the agency did not make changes to the report, ShinyHunters declined to comment. When BleepingComputer asked the main representative whether they were concerned this would lead to increased pressure from the US government to apprehend them, they responded, "I don't care."

The alleged PeopleSoft zero-day would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability. During Clop's 2025 Oracle E-Business Suite data theft campaign, ShinyHunters was part of a group calling itself "Scattered Lapsus$ Hunters" that leaked a proof-of-concept exploit later confirmed by Oracle to match one used in the attacks.

ShinyHunters later told BleepingComputer that the exploit originally belonged to them and that the Clop ransomware gang obtained it without authorization. That dispute resurfaced last week when ShinyHunters breached and defaced Clop's data leak site, claiming it stole server data and the private keys for its Tor onion service. The group subsequently added Clop to its own leak site and threatened to extort the ransomware operation, saying the attack was retaliation for threats allegedly made during the Oracle E-Business Suite campaign.

BleepingComputer has contacted the FBI, Oracle, and Google Cloud's Mandiant threat intelligence team regarding the alleged breach and PeopleSoft zero-day and will update this story if a response is received.