Skip to content
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

Infosecurity-Magazine • September 23, 2026

The prolific hacking group ShinyHunters has claimed to have breached the FBI via a zero-day exploit and stolen data on “all FBI employees and applicants.”

The group posted the news on its data leak site, reasoning it took action in retaliation for what it claims to be inaccuracies in an FBI Public Service Announcement (PSA) published on May 15.

ShinyHunters seemed to take offense at claims in the PSA that it exaggerates access to sensitive information in order to extract payment, that the group harasses victims and their families, conducts swatting attacks, and falsely claims to possess sensitive/compromising material on victims. It also denied being a part of “The Com.”

The group shared a sample of the compromised data with 404 Media, which first reported the story. It apparently contained personally information (PII) on 5000 FBI employees including addresses, phone numbers, dates of birth and in some cases details on spouses.

The goal appears not financial extortion but to force the FBI to take down or amend the PSA.

ShinyHunters also defaced the FBI jobs website on September 22.

The site was still down ‘for maintenance’ at the time of writing.

PeopleSoft a Popular Target

An FBI spokesperson told 404 Media that the group exploited a zero-day vulnerability in Oracle PeopleSoft before pivoting to AWS GovCloud servers and downloading 2-3TB of data.

If true, it wouldn’t be the first time the group has targeted the Oracle software. Between May and June it exploited a zero day in PeopleSoft's Environment Management component to hit dozens of education institutions.

“When ShinyHunters burned this vulnerability to hit more than 100 organizations, most of them universities, they later said their original goal had been an FBI PeopleSoft server, and that attempt failed,” explained Steve Povolny, VP of AI strategy & security research at Exabeam.

“The education sector was collateral damage from a failed shot at the bureau. Three months later they claim a new PeopleSoft zero-day. That points to a group systematically mining ERP platforms that hold HR, payroll, applicant, and health data.”

PeopleSoft customers should assume compromise, ensure the fix for the zero day is applied and disable the Environment Management Hub or remove the PSEMHUB application, Povolny said.

“Take PeopleSoft admin and integration interfaces off the internet. Then hunt instead of waiting for a signature that doesn't exist yet,” he advised.

“Look for suspicious POST activity in WebLogic access logs, unauthorized files in PSEMHUB directories, XMLDecoder-based persistence, and outbound traffic on port 445, along with remote-management agents like the MeshCentral tooling used for command and control in June.”

Povolny also urged customers to evaluate the PeopleSoft host and its service identities and look for unusual API calls, bulk data queries, or authentications.

“Ship logs off-host, since the attackers claim they wipe local evidence,” he concluded. “Know who owns PeopleSoft on the IR team. Be ready to rotate every secret reachable from those servers, and have authority pre-approved to isolate systems fast.”

2016 : Two Steps Forward, Three Steps Back Editorial 27 December 2016

2016 : Two Steps Forward, Three Steps Back

Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day News 30 June 2026

Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day

Allianz Life Data Breach Exposes Personal Data of 1.1 Million Customers News 19 August 2025

Allianz Life Data Breach Exposes Personal Data of 1.1 Million Customers

Chanel and Pandora Breached as Salesforce Campaign Continues News 6 August 2025

Chanel and Pandora Breached as Salesforce Campaign Continues

ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign News 10 March 2026

ShinyHunters Targets Hundreds of Websites in New Salesforce Campaign

What’s Hot on Infosecurity Magazine?

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

Revolut Customers Targeted with New Wave of Phishing Attacks

Attackers Abuse npm Trusted Publishing in GHAPPIER Campaign

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

North Korean Attackers Hit 30,000 Devices and Steal $10.7m

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

AI Agent Carries Out Multi-Stage Data Theft Attack

Most Firms Unable to Recover Quickly from Ransomware

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

From APIs to Agents: How to Secure AI at Enterprise Scale

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust