CTIPilot

ShinyHunters claimed breach of the FBI via an Oracle PeopleSoft zero-day

incident · incident:shinyhunters-fbi-peoplesoft-breach-claim-2026-09

ShinyHunters claims it exploited an undisclosed Oracle PeopleSoft zero-day on 2026-09-21 to compromise the FBI's recruitment site (apply.fbijobs.gov), pivot into FBI-managed AWS GovCloud infrastructure, and steal 2-3TB of employee and applicant data; the FBI confirms only that it is investigating and has not confirmed the breach, its scope, or the claimed vulnerability (BleepingComputer / TechCrunch / 404 Media, 2026-09-22).

Aliases: FBIjobs.gov breach, FBI ShinyHunters PeopleSoft claim

Coverage timeline
1
first 2026-09-24 → last 2026-09-24
Peak priority
high
1 high
Sources cited
7
6 hosts
Sections touched
1
active-threats
Co-occurring entities
3
see Co-occurring entities below
ATT&CK techniques
3
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques
Affected products

ATT&CK techniques

3 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · ATT&CK page ↗

Collection TA0009

T1530Data from Cloud Storage×1

Adversaries may access data from cloud storage.

Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · ATT&CK page ↗

Impact TA0040

T1491.002Defacement: External Defacement×1

An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may ultimately cause users to distrust the systems and to question/discredit the system’s integrity. Externally-facing websites are a common victim of defacement; often targeted by adversary and hacktivist groups in order to push a political message or spread propaganda. External Defacement may be used as a catalyst to trigger events, or as a response to actions taken by an organization or government. Similarly, website defacement may also be used as setup, or a precursor, for future attacks such as Drive-by Compromise.

Evidence: 2026-09-24/shinyhunters-fbi-peoplesoft-breach-claim · ATT&CK page ↗

Story timeline

  1. 2026-09-24ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI confirms only that it is investigating
    active-threatsA serial extortion actor claims it rooted the FBI through an undisclosed Oracle PeopleSoft flaw and pivoted into an AWS-hosted government data store

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com2 (29%)
  • 404media.co1 (14%)
  • axios.com1 (14%)
  • cyberscoop.com1 (14%)
  • techcrunch.com1 (14%)
  • thehackernews.com1 (14%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about ShinyHunters claimed breach of the FBI via an Oracle PeopleSoft zero-day (1)

2026-09-24 · view entry permalink →

HIGHNATOB3

ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI confirms only that it is investigating

The extortion group ShinyHunters claims it breached the FBI's own recruitment infrastructure using a new, undisclosed remote-code-execution zero-day in Oracle PeopleSoft, often used by human resources and recruiters to store job applicants' personal information (TechCrunch, 2026-09-22). "The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure" (BleepingComputer, 2026-09-22). ShinyHunters claims it stole 2-3TB of data, names, agent statuses, emails, phone numbers, home addresses and in some cases spouses' information including Social Security numbers (Axios, 2026-09-22), spanning current and former FBI employees and job applicants, and that it compromised additional internal services including Criminal Justice, HR and Medlink systems along the way (BleepingComputer, 2026-09-22). The group defaced the FBI's careers site, apply.fbijobs.gov, with its Umbreon Pokémon logo and a message claiming the theft; the FBI took the site offline, and it now shows a maintenance page. The FBI's confirmed response is limited to a single statement: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," (FBI, quoted by BleepingComputer, 2026-09-22); the bureau has not confirmed a breach occurred, its scope, or the claimed PeopleSoft zero-day, and "BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data" (BleepingComputer, 2026-09-22).

404 Media first reported the claim after receiving a sample of roughly 5,000 alleged FBI personnel records; "the publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel" (BleepingComputer, relaying 404 Media, 2026-09-22), which supports that some genuine personnel data changed hands without confirming the exploitation mechanism or the full claimed volume. ShinyHunters' own account of the vulnerability is unusually specific but still entirely self-reported: "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," (ShinyHunters, quoted by BleepingComputer, 2026-09-22) and the group says it is now exploiting the same alleged flaw against other organizations, including Fortune 500 companies, after previously targeting the education sector with a PeopleSoft campaign (BleepingComputer, 2026-09-22). ShinyHunters frames the FBI intrusion as retaliation for a May 2026 FBI/IC3 flash report naming the group, demanding a correction within one week rather than a ransom and claiming the demand is not financially motivated (BleepingComputer, 2026-09-22). The same week, ShinyHunters separately defaced the ransomware group Clop's own Tor leak site over an unrelated dispute, using it to extort Clop directly (BleepingComputer, 2026-09-19); a parallel campaign against a different victim that this entry does not otherwise cover.

The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

BleepingComputer 2026-09-22

The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,

FBI, quoted by BleepingComputer

BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

BleepingComputer 2026-09-22

The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.

BleepingComputer, relaying 404 Media's own verification

ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.

Axios 2026-09-22
incident24 Sep 04:50Zmulti-sourceOpen finding ↗