Back Infosecurity-Magazine ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
The prolific hacking group ShinyHunters has claimed to have breached the FBI via a zero-day exploit and stolen data on “all FBI employees and applicants.”
The group posted the news on its data leak site, reasoning it took action in retaliation for what it claims to be inaccuracies in an FBI Public Service Announcement (PSA) published on May 15.
ShinyHunters seemed to take offense at claims in the PSA that it exaggerates access to sensitive information in order to extract payment, that the group harasses victims and their families, conducts swatting attacks, and falsely claims to possess sensitive/compromising material on victims. It also denied being a part of “The Com.”
The group shared a sample of the compromised data with 404 Media, which first reported the story. It apparently contained personally information (PII) on 5000 FBI employees including addresses, phone numbers, dates of birth and in some cases details on spouses.
The goal appears not financial extortion but to force the FBI to take down or amend the PSA.
ShinyHunters also defaced the FBI jobs website on September 22.
The site was still down ‘for maintenance’ at the time of writing.
PeopleSoft a Popular Target
An FBI spokesperson told 404 Media that the group exploited a zero-day vulnerability in Oracle PeopleSoft before pivoting to AWS GovCloud servers and downloading 2-3TB of data.
If true, it wouldn’t be the first time the group has targeted the Oracle software. Between May and June it exploited a zero day in PeopleSoft's Environment Management component to hit dozens of education institutions.
“When ShinyHunters burned this vulnerability to hit more than 100 organizations, most of them universities, they later said their original goal had been an FBI PeopleSoft server, and that attempt failed,” explained Steve Povolny, VP of AI strategy & security research at Exabeam.
“The education sector was collateral damage from a failed shot at the bureau. Three months later they claim a new PeopleSoft zero-day. That points to a group systematically mining ERP platforms that hold HR, payroll, applicant, and health data.”
PeopleSoft customers should assume compromise, ensure the fix for the zero day is applied and disable the Environment Management Hub or remove the PSEMHUB application, Povolny said.
“Take PeopleSoft admin and integration interfaces off the internet. Then hunt instead of waiting for a signature that doesn't exist yet,” he advised.
“Look for suspicious POST activity in WebLogic access logs, unauthorized files in PSEMHUB directories, XMLDecoder-based persistence, and outbound traffic on port 445, along with remote-management agents like the MeshCentral tooling used for command and control in June.”
Povolny also urged customers to evaluate the PeopleSoft host and its service identities and look for unusual API calls, bulk data queries, or authentications.
“Ship logs off-host, since the attackers claim they wipe local evidence,” he concluded. “Know who owns PeopleSoft on the IR team. Be ready to rotate every secret reachable from those servers, and have authority pre-approved to isolate systems fast.”
2016 : Two Steps Forward, Three Steps Back Editorial 27 December 2016
2016 : Two Steps Forward, Three Steps Back
Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day News 30 June 2026
Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day
Allianz Life Data Breach Exposes Personal Data of 1.1 Million Customers News 19 August 2025
Allianz Life Data Breach Exposes Personal Data of 1.1 Million Customers
Chanel and Pandora Breached as Salesforce Campaign Continues News 6 August 2025
Chanel and Pandora Breached as Salesforce Campaign Continues
ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign News 10 March 2026
ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign
What’s Hot on Infosecurity Magazine?
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
Revolut Customers Targeted with New Wave of Phishing Attacks
Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
From APIs to Agents: How to Secure AI at Enterprise Scale
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
