Sep 23 / Latest News

ShinyHunters Claims FBI Breach Using Alleged PeopleSoft Zero‑Day in Escalating Extortion Campaign

The cyber extortion group ShinyHunters claims it breached the U.S. Federal Bureau of Investigation, saying it accessed data belonging to current and former employees as well as job applicants across multiple FBI services.

In a statement posted on its dark web site, the group asserted it compromised systems tied to Criminal Justice, HR, Medlink and other internal functions. ShinyHunters framed the attack as retaliation for a May 2026 FBI public service announcement that described the group’s targeting of the Canvas LMS and urged victims not to pay. The group dismissed the PSA as disinformation and issued its own counter‑message criticizing the agency.

ShinyHunters also rejected claims linking it to The Com decentralized collective, calling those allegations industry‑driven propaganda. A spokesperson told reporters the breach was achieved through a previously unknown Oracle PeopleSoft zero‑day that enabled remote code execution. The attackers said they used the flaw to deface the FBI’s jobs site with a takeover banner before the page was replaced with a maintenance notice.

There is no public confirmation of a new pre‑authentication PeopleSoft RCE, though ShinyHunters previously weaponized a similar vulnerability (CVE‑2026‑35273) to infiltrate enterprise networks earlier this year. The FBI said it is aware of the claims involving FBIjobs.gov and is investigating.

The disclosure follows the group’s recent hijacking of the Clop ransomware crew’s leak site, part of a pattern of increasingly provocative actions. ShinyHunters has issued aggressive ransom demands and taunts, positioning itself as a resilient brand that has survived arrests, takedowns and forum seizures by continually adapting its methods.

Security researchers note that the group’s recent operations emphasize identity‑based intrusion paths — including help‑desk social engineering, malicious OAuth applications and stolen SaaS integration tokens — rather than purely technical perimeter breaches. Analysts warn that organizations, including public‑sector agencies, must strengthen identity and third‑party trust controls as attackers increasingly exploit these pathways.