ShinyHunters Claims PeopleSoft Zero-Day Breach Exposes FBI Data
The ShinyHunters extortion gang claims it has breached FBI systems by exploiting a new zero-day vulnerability in Oracle PeopleSoft. The group says the flaw allows remote code execution and that it used it to access FBI systems on Monday night before moving laterally into FBI-managed AWS GovCloud infrastructure. ShinyHunters claims it steals between 2TB and 3TB of data during the intrusion.
The stolen data allegedly includes sensitive personally identifiable and health-related information on current and former FBI employees, as well as job applicants. The group says it also compromises FBI Criminal Justice, HR, and Medlink services during the breach. ShinyHunters shares a screenshot with BleepingComputer showing the FBI Jobs website defaced with the group's Umbreon Pokémon logo and a message claiming all FBI data is compromised.
The FBI confirms it is aware of the claims and is investigating, though it does not confirm whether a breach or data theft occurs. BleepingComputer does not independently verify the alleged zero-day, the lateral movement, or the amount of stolen data. ShinyHunters claims it is now exploiting the same vulnerability against other organizations, including Fortune 500 companies, and says the FBI quickly takes affected systems offline after discovering the intrusion.