FBI Data Breach Analysis: ShinyHunters Exploit Oracle PeopleSoft Zero-Day to Exfiltrate Employee and Applicant Data

FBI Data Breach Analysis: ShinyHunters Exploit Oracle PeopleSoft Zero-Day to Exfiltrate Employee and Applicant Data

Executive Summary

On September 22–23, 2026, the cybercriminal group ShinyHunters publicly claimed responsibility for a breach of the Federal Bureau of Investigation (FBI), asserting that they had stolen sensitive data on current and former FBI employees as well as job applicants. The group stated they exploited a previously unknown zero-day vulnerability in Oracle PeopleSoft to gain remote code execution, subsequently defacing the FBI’s jobs site and exfiltrating between two and three terabytes of data. The compromised data reportedly includes names, home addresses, phone numbers, and family information for nearly 5,000 individuals associated with the FBI. The FBI confirmed awareness of unauthorized activity affecting FBIjobs.gov and launched an investigation. The breach follows a pattern of ShinyHunters targeting high-profile organizations using advanced exploitation techniques and leveraging psychological extortion tactics. At the time of writing, the full scope of the breach and the authenticity of all stolen data remain under investigation. All technical details and claims in this report are based on direct statements from primary sources, with explicit evidence assessment and confidence levels.

Technical Information

The attack on the FBI was executed by exploiting a previously unknown (zero-day) vulnerability in Oracle PeopleSoft, a widely used enterprise resource planning (ERP) platform. According to statements from ShinyHunters and corroborated by multiple independent news outlets, the attackers achieved remote code execution (RCE) on FBI infrastructure, specifically targeting the agency’s jobs portal. The group referenced a similar flaw, CVE-2026-35273, which they had weaponized in June 2026, but indicated that the FBI breach involved a new, as-yet-undisclosed pre-authenticated RCE zero-day.

After initial access, the attackers reportedly moved laterally to access servers hosted in Amazon Web Services (AWS) GovCloud, a cloud environment designed for U.S. government workloads. The group claims to have exfiltrated between two and three terabytes of sensitive data, including personal information of nearly 5,000 FBI employees and applicants. Journalistic verification of some names in the leaked data confirmed employment with the FBI, but the entire dataset has not been independently validated.

The attackers also defaced the FBI jobs site, replacing its content with a seizure notice and later a maintenance message. The group issued public demands, including a request for the FBI to retract a May 2026 public service announcement (PSA) that described ShinyHunters’ tactics, and threatened to release sensitive data if their demands were not met.

Technical mapping to the MITRE ATT&CK framework indicates the following techniques were likely used: T1190 (Exploit Public-Facing Application) for the initial PeopleSoft exploit, T1537 (Transfer Data to Cloud Account) and T1005 (Data from Local System) for data exfiltration, T1567 (Exfiltration Over Web Service) for possible use of AWS as an exfiltration vector, T1499 (Endpoint Denial of Service) for the site defacement and outage, and T1657 (Data Manipulation) for psychological impact operations.

No specific malware families, implants, or command-and-control (C2) infrastructure were identified in the available sources. The primary tool was the zero-day exploit for Oracle PeopleSoft. There is no evidence of commodity malware or ransomware deployment in this incident.

ShinyHunters is a well-established cybercriminal group known for large-scale data breaches and extortion campaigns, previously targeting sectors such as technology, finance, retail, and education. Their tactics include abusing trusted identity paths (such as help-desk social engineering and malicious OAuth applications), harassment, and psychological pressure, including threats and swatting. The group’s recent operations have demonstrated resilience against law enforcement takedowns and a preference for high-value, high-profile targets.

Attribution to ShinyHunters is assessed with high confidence based on direct claims, historical tactics, and public data leak site activity. The use of an Oracle PeopleSoft zero-day is also assessed with high confidence, while claims of AWS GovCloud access and the full extent of data exfiltration are assessed with medium confidence due to partial verification.

Affected Versions & Timeline

The breach specifically targeted the FBI’s Oracle PeopleSoft deployment, exploiting a previously unknown pre-authenticated RCE zero-day vulnerability. While the group referenced CVE-2026-35273 as a similar flaw, the actual vulnerability used in this incident has not been publicly disclosed or assigned a CVE at the time of writing.

The attack reportedly occurred on the night of September 21, 2026, with public claims and site defacement observed on September 22–23, 2026. The FBI issued a statement acknowledging unauthorized activity affecting FBIjobs.gov and initiated an investigation. The group’s demands referenced a May 15, 2026, FBI PSA related to earlier ShinyHunters activity targeting an online learning management system.

The full scope of affected systems and data remains under investigation. The compromised data set reportedly includes personal information on nearly 5,000 FBI employees and applicants, but the authenticity and completeness of the data have not been independently verified.

Threat Activity

ShinyHunters is a cybercriminal group specializing in large-scale data breaches and extortion. Their historical activity includes targeting major companies in the technology, finance, retail, and education sectors, often stealing millions of customer records at once. The group’s tactics have evolved to include the exploitation of zero-day vulnerabilities, abuse of cloud infrastructure, and sophisticated social engineering.

In this incident, ShinyHunters exploited a zero-day vulnerability in Oracle PeopleSoft to gain initial access to FBI infrastructure. Post-exploitation, they reportedly accessed AWS GovCloud servers and exfiltrated large volumes of sensitive data. The group defaced the FBI jobs site and issued public demands, including threats to release sensitive data and requests for the FBI to retract public statements about their tactics.

ShinyHunters’ extortion methods often involve psychological pressure, including harassment, threatening communications, and swatting. The group has denied some of these tactics in public statements but has a documented history of using them in previous campaigns. Their operations demonstrate a preference for high-profile targets and a willingness to engage in public confrontation with law enforcement agencies.

The group’s recent playbook emphasizes abusing trusted identity paths, such as help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than relying solely on technical perimeter breaches. This approach increases the risk to organizations with complex identity and third-party trust relationships.

Mitigation & Workarounds

Mitigation recommendations are prioritized by severity:

Critical: Organizations using Oracle PeopleSoft should immediately review their deployments for signs of compromise, especially any unexplained access or changes to public-facing applications. Apply all available security patches and monitor for updates regarding the specific zero-day vulnerability referenced in this incident.

High: Review and restrict access to cloud environments, particularly AWS GovCloud or similar sensitive workloads. Implement strict identity and access management (IAM) controls, enforce multi-factor authentication (MFA), and monitor for unusual access patterns or large data transfers.

High: Conduct a comprehensive audit of user accounts, privileged access, and third-party integrations. Pay particular attention to help-desk workflows, OAuth applications, and SaaS integration tokens, as these are known targets for ShinyHunters.

Medium: Enhance monitoring and alerting for defacement, unauthorized changes to web applications, and suspicious outbound network traffic. Ensure that incident response plans include procedures for rapid containment and communication in the event of a breach.

Medium: Educate employees about social engineering tactics, including phishing, vishing, and impersonation attempts. Encourage verification of urgent or unusual requests through secondary communication channels.

Low: Regularly review and update data retention and backup policies to minimize the impact of potential data exfiltration.

All organizations should remain vigilant for public disclosures of new vulnerabilities in Oracle PeopleSoft and related platforms, and subscribe to vendor and government advisories for timely updates.

Indicators of Compromise

The following indicators are provided as a point-in-time reference and should be validated in your environment before enforcement. Indicators may change as investigations progress.

Type

Indicator

Reported (date)

Source

 

Domain

fbijobs[.]gov

2026-09-22

https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/?oref=ng-author-river

Domain

fbi[.]gov

2026-05-15

https://www.ic3.gov/PSA/2026/PSA260515

Domain

www[.]fbi[.]gov

2026-05-15

https://www.ic3.gov/PSA/2026/PSA260515

Domain

www[.]ic3[.]gov

2026-05-15

https://www.ic3.gov/PSA/2026/PSA260515

Domain

coping-with-crime-one-pager-april-2026[.]pdf

2026-05-15

https://www.ic3.gov/PSA/2026/PSA260515

No malware hashes, C2 domains, or IP addresses were disclosed in the available sources.

References

The Hacker News, "ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants", 2026-09-23 https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html

Nextgov/FCW, "ShinyHunters claims FBI data theft, demands bureau retract cyber warning", 2026-09-22 https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/?oref=ng-author-river

FBI Public Service Announcement, "ShinyHunters: Cyber Criminal Group Attacks Learning Management System", 2026-05-15 https://www.ic3.gov/PSA/2026/PSA260515

About Rescana

Rescana provides a Third-Party Risk Management (TPRM) platform that enables organizations to continuously assess and monitor the security posture of their vendors and partners. Our platform supports rapid identification of supply chain exposures, facilitates evidence-based risk analysis, and helps organizations respond to emerging threats by integrating threat intelligence and vulnerability data relevant to incidents such as the one described in this report.

We are happy to answer questions at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.