Join Nostr
2026-09-22 20:07:08 UTC

oxhak on Nostr: The ShinyHunters extortion group claims it breached FBI systems by exploiting a ...

The ShinyHunters extortion group claims it breached FBI systems by exploiting a previously unknown remote-code-execution vulnerability in Oracle PeopleSoft. The group says it moved into FBI-managed AWS GovCloud infrastructure, accessed internal services, and stole between 2 TB and 3 TB of data involving FBI employees and job applicants. It claims to have accessed Criminal Justice, HR, and Medlink services, and says it is using the same alleged flaw against other organizations.

The FBI Jobs website was defaced with a ShinyHunters message, and the group shared sample records that it said came from the intrusion. A separate report said a sample contained about 5,000 purported employee records and that some details appeared accurate. However, BleepingComputer has not independently verified the zero-day, the lateral movement, the stolen-data volume, or the authenticity of the samples. The FBI reportedly took affected systems offline, while Oracle and Mandiant were contacted for comment.

https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/