
The ShinyHunters extortion gang has claimed responsibility for a breach of FBI systems, saying it exploited a previously unknown vulnerability in Oracle PeopleSoft to gain initial access. The group told BleepingComputer it used the zero-day on Monday night to access FBI internal services, then moved laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters claims to have stolen between 2TB and 3TB of data, including records on current and former FBI employees, job applicants, and internal agency information.
As evidence, the group defaced the FBI Jobs website at apply.fbijobs.gov, replacing it with their Umbreon Pokémon logo and a message reading “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.” A screenshot shared with BleepingComputer showed the defacement, and 404 Media, which also received a sample, reported that some information in the roughly 5,000-record sample appeared accurate — including phone numbers corresponding to named US Department of Justice personnel. BleepingComputer has not independently verified the zero-day, the lateral movement claim, or the volume of stolen data, and the FBI has not publicly confirmed the breach. ShinyHunters says the FBI became aware of the intrusion quickly and pulled affected systems offline. The group also claims it is now exploiting the same PeopleSoft zero-day against other targets, including Fortune 500 companies. Oracle has not yet issued an advisory or patch for the reported vulnerability.
