← All articles

ShinyHunters claims FBI breach through Oracle PeopleSoft zero-day as agency stays silent

The extortion group ShinyHunters claimed on its dark web site that it breached the FBI and stole data on current and former employees and job applicants, naming Criminal Justice, HR, and Medlink services. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and deface the FBI jobs site. The claim, first reported by 404 Media, is unverified, and the FBI has not confirmed any compromise. ShinyHunters framed it as retaliation for a May FBI advisory about its Canvas targeting, disputing those allegations and rejecting reported ties to the wider criminal collective. Treat the specifics as an attacker claim pending independent confirmation.

Check
Track independent confirmation before acting, and separately prioritize Oracle PeopleSoft patching and exposure review given repeated zero-day claims against that platform.
Affected
Internet-facing Oracle PeopleSoft deployments are the claimed entry point, so unpatched or exposed HR and applicant systems on that platform warrant urgent review.
Fix
Apply current PeopleSoft security fixes, restrict and monitor internet-facing instances, and wait for verified reporting before drawing conclusions about the FBI claim.