Hackaday ShinyHunters Breaches FBI, Steals Sensitive Employee Data
Article Content
- •ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to breach the FBI.
- •2 TB of sensitive employee data was stolen, including PII of FBI personnel.
- •The FBI is investigating the breach and working to mitigate risks.
The ShinyHunters hacking group exploited a zero-day vulnerability in Oracle PeopleSoft to breach the FBI's jobs portal, FBIJobs.gov, and accessed AWS GovCloud instances. They claimed to have stolen 2 TB of sensitive data, including personally identifiable information (PII) of current, former, and prospective FBI employees. The breach was confirmed by the FBI, which is investigating the incident. ShinyHunters stated their motive was to protect their business reputation amidst ongoing allegations of harassment and extortion tactics. They threatened to release the stolen data if the FBI did not retract previous statements about their activities. The FBI is actively working to assess the breach and mitigate risks associated with the compromised data. The FBIJobs.gov portal remains down as of the latest reports.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track ShinyHunters and Carnival Cruise Lines in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
Kiteworks Issues Urgent Shutdown Advisory Amid Zero-Day Threat Kiteworks has alerted its customers to shut down their servers due to credible threat intelligence indicating an imminent cyberattack exploiting a zero-day vulnerability. The advisory, which applies globally, recommends a six-hour shutdown window starting September 26, 2026. This precautionary measure comes as…