The ShinyHunters extortion group claims it exploited a new Oracle PeopleSoft zero-day to breach FBI systems, gain remote access to internal services and steal between 2TB and 3TB of data, including sensitive personally identifiable and health-related information on current and former FBI employees and job applicants. The FBI said, “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” The agency did not confirm whether systems were breached or data were stolen.
PeopleSoft zero-day and alleged intrusion
ShinyHunters told a security publication the vulnerability allows remote code execution and that the group used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure. The group claims to have compromised multiple FBI services, naming Criminal Justice, HR, Medlink and other internal systems. ShinyHunters also said it attempted to erase evidence on compromised servers to make the zero-day harder to identify.
The group shared a screenshot showing the FBI Jobs website at apply.fbijobs.gov defaced with ShinyHunters’ Umbreon Pokémon logo and the message: “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since ’19 ;)” A message on the defaced site additionally claimed that “All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information,” and added, “We have a lot more than what we claim here. Thank you for your attention to this matter.” The FBI Jobs site was later reported to display a maintenance message after the agency took affected systems offline.
Samples, reporting and scope claims
ShinyHunters provided two sample records that it says were stolen, including one record allegedly linked to an FBI special agent previously mentioned in a breach investigation and another allegedly linked to FBI Director Kash Patel; the publisher did not publish the personal information in those records and has not independently verified their authenticity or source. Another outlet first reported the alleged breach after receiving a sample said to contain approximately 5,000 purported FBI employee records; that outlet said it verified some items in the sample, including phone numbers corresponding to people with the same names and numbers associated with U.S. Department of Justice personnel.
ShinyHunters claims the stolen FBI data originated from systems accessed after the initial PeopleSoft compromise, including the agency’s AWS GovCloud environment. The group also asserts it is now exploiting the same alleged PeopleSoft vulnerability against other organizations, including Fortune 500 companies, after previously targeting the education sector.
Motives, demands and past claims
On its data leak site, ShinyHunters published a statement saying the attack was retaliation for an FBI FLASH report about the group that was published in May 2026. The group disputed prior allegations that its actors exaggerate access to sensitive information, harass victims, conduct swatting or falsely claim compromising material. It denied being part of a wider cybercrime community described by law enforcement and security researchers, and gave the FBI one week to correct or remove the FLASH report while saying the demand was not financially motivated and was not extortion. When asked whether it would release the allegedly stolen FBI data if the agency did not act, the group declined to comment.
ShinyHunters has previously been linked by the group itself to exploitation of an Oracle vulnerability during a 2025 campaign that targeted Oracle E-Business Suite; the group said a proof-of-concept exploit used in that campaign originally belonged to them and that it later breached and defaced the ransomware gang Clop’s data leak site, claiming to have stolen server data and private keys.
Journalists contacted Oracle and Google Cloud’s Mandiant threat intelligence team to determine whether they were aware of a new PeopleSoft vulnerability or related exploitation activity. The claims of a PeopleSoft zero-day, lateral movement into AWS GovCloud and the amount of stolen data have not been independently verified. The FBI has said it is investigating the claims.

