MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-22 · via BleepingComputer

Extortion group alleges FBI breach via Oracle PeopleSoft flaw, steals employee and applicant data

Image via BleepingComputer
Image via BleepingComputer

The ShinyHunters extortion group claims it exploited an unpatched Oracle PeopleSoft vulnerability to break into FBI systems, gaining remote code execution and moving laterally into AWS GovCloud infrastructure. The group says it stole 2-3 TB of data, including personal and health information on current and former FBI employees and job applicants, and defaced the FBI Jobs website with a seizure message. BleepingComputer has not independently verified the claims, but the FBI reportedly took affected systems offline after detecting the intrusion.

Expanded Detail

The alleged intrusion reportedly began with an unpatched Oracle PeopleSoft flaw enabling remote code execution, after which the attackers claim to have pivoted into FBI-managed AWS GovCloud environments. ShinyHunters says it accessed services tied to criminal justice, HR, and medical systems, and that it also targeted other sectors, including education and Fortune 500 firms. The group shared sample records, including one tied to FBI Director Kash Patel, though verification remains incomplete. The FBI reportedly detected the activity quickly and disconnected affected systems, with the jobs portal now showing a maintenance notice.

The incident highlights recurring risks in legacy enterprise software, particularly when patches lag. Oracle PeopleSoft is widely used in government and large organizations, making zero-day claims especially concerning. The group’s stated intent to reuse the vulnerability against other targets suggests potential broader exposure, though the technical details and data authenticity have not been confirmed by independent sources.

Context

If confirmed, this breach could erode public trust in federal cybersecurity practices, especially regarding sensitive personnel and health data. Affected individuals—current and former FBI employees and applicants—may face identity theft, doxxing, or targeted harassment. The alleged lateral movement into cloud infrastructure also raises questions about segmentation and monitoring across government systems. While the group’s claims remain unverified, the incident underscores how a single unpatched flaw can cascade into large-scale exposure, potentially influencing future federal procurement and patch-management policies.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
ShinyHunters alleges FBI hack, stealing personal data of agents and applicants · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach.” Browse more stories.