ShinyHunters Claims Massive FBI Data Breach via PeopleSoft Zero-Day
Cybercriminal group ShinyHunters claims to have stolen personal data on nearly all FBI employees and applicants, exploiting a zero-day vulnerability in Oracle PeopleSoft. The FBI is investigating the breach, which follows a previous major intrusion this year.
Key points
- ShinyHunters claims to have stolen 'very sensitive' data on almost all FBI agents and job applicants, including names, addresses, phone numbers, and spouse information.
- The group provided a sample of 5,000 records to 404 Media, which verified some phone numbers against open-source tools and DOJ personnel records.
- ShinyHunters states it used a zero-day exploit in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating between two and three terabytes of data.
- The FBI confirmed it is investigating unauthorized activity affecting its jobs portal, which displayed a 'system unavailable' banner and a defacement message from the hackers.
- The breach is described by insiders as a significant counterintelligence failure, potentially exposing agents and their families to threats from criminals or foreign intelligence services.
Background
This incident follows a major breach of an FBI wiretap system in April 2026, linked to Chinese hackers. ShinyHunters has been increasingly active this year, including attacks on the Canvas learning system and the European Commission. In May 2026, the FBI issued a public service advisory warning about ShinyHunters' tactics, which the group claims was the motivation for this retaliatory hack.
How outlets are covering it
Politico reports that two sources with knowledge of the breach consider the claims credible and a significant counterintelligence failure, noting the FBI jobs site was affected. 404 Media verified parts of the sample data using OSINT tools and confirmed the group's claim of using a zero-day in Oracle PeopleSoft to access AWS GovCloud. Axios notes that while cybersecurity researchers confirm the attack appears legitimate, the long-term impact on FBI employees and their families is the primary concern, with experts warning that the data may be sold to other threat actors. ShinyHunters denies financial motivation, stating the hack was a 'coercion' tactic to force the FBI to retract its May advisory about the group's harassment tactics.
Why it matters
The breach exposes the personal information of law enforcement personnel, creating significant safety risks for agents and their families. It highlights vulnerabilities in government HR systems and the potential for cybercriminals to target law enforcement to gather intelligence or retaliate against official advisories. The incident also underscores the ongoing threat posed by groups like ShinyHunters, which have demonstrated the ability to exploit zero-day vulnerabilities in widely used software.
What to watch
The FBI is expected to marshal additional resources to investigate and potentially prosecute the hackers, according to former cyber division officials. Investigators are determining whether the breach used a previously known zero-day that the FBI failed to patch or a new exploit. The long-term impact will depend on whether the stolen data is sold or leaked to other criminal or nation-state actors, potentially leading to harassment or threats against FBI personnel.
- Cybercriminal group claims to steal thousands of FBI employee records Politico
- ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees 404media.co
- ShinyHunters hackers say they breached FBI, stole data on bureau employees Reuters
- FBI investigating claims that a major cybercrime group stole sensitive personnel data Axios
- FBI investigating possible cyber breach of its job application website: Sources ABC News - Breaking News, Latest News and Videos
Want the full story? Read the original reporting
Read on Politico