Opens in a new tab

ShinyHunters FBI Hack Claim Remains Unverified

ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day

The ShinyHunters FBI hack claim alleges that the group breached an FBI recruitment system and stole between 2 TB and 3 TB of data. As of 22 September 2026, the FBI, Oracle and AWS had not confirmed the claims.

ShinyHunters told The Register that it exploited an Oracle PeopleSoft zero-day vulnerability affecting the FBI’s jobs website. The group says the flaw provided remote code execution without authentication, but no technical evidence, affected version details or indicators of compromise were publicly available in the report.

What the ShinyHunters FBI hack claim alleges

According to a ShinyHunters spokesperson, the initial target was an Oracle PeopleSoft deployment connected to the FBI jobs webpage. The group described the suspected vulnerability as a pre-authentication remote code execution flaw, commonly shortened to pre-auth RCE.

If accurate, this type of vulnerability could allow an attacker to send a specially crafted request to an internet-facing application and make the underlying server execute unauthorised commands. Pre-authentication means the attacker would not first need a valid username, password or authenticated session.

However, the precise entry point remains unknown. ShinyHunters did not publicly identify a vulnerability reference, PeopleSoft component, exploit request, affected configuration or product version. It is therefore not possible to determine from the available information whether the alleged issue affects PeopleSoft broadly, a particular module, or a configuration specific to the targeted environment.

Website defacement and alleged lateral movement

ShinyHunters also claims it defaced the FBI jobs website after gaining access. An image shared with The Register reportedly showed the legitimate page replaced by a banner stating, “This site has been seized by ShinyHunters.”

At the time of the report on 22 September 2026, the website displayed a message saying it was down for maintenance and would return soon. A maintenance page does not independently establish that a compromise occurred, but it is consistent with the affected service being taken offline for investigation or recovery.

The group says it then moved laterally from the compromised recruitment site to FBI-managed servers hosted within AWS GovCloud. Lateral movement refers to using access to one system to reach other connected services, accounts or workloads inside an organisation’s environment.

No public evidence had confirmed that this movement occurred or explained how the alleged attackers crossed from the web application into other infrastructure. The report did not identify compromised credentials, cloud roles, access tokens, server names or security control failures.

Data and services named in the FBI hack claim

The ShinyHunters FBI hack claim includes an allegation that approximately 2 TB to 3 TB of information was downloaded. The spokesperson said the material relates to current employees, former employees and people who have applied to work for the FBI.

The group further claimed that it accessed systems or information associated with several FBI functions:

  • Human resources services containing workforce-related records.
  • MedLink, which the group named among the allegedly compromised services.
  • Criminal Justice Information Services.
  • Recruitment and applicant information connected to the FBI jobs service.

The report did not provide a verified file listing, sample records, data schema or independent measurement supporting the claimed volume. It also did not establish whether the group accessed entire systems, copied selected records, or merely observed service names while navigating the environment.

Claims involving employee and applicant data are potentially significant because recruitment and HR platforms can hold identity, employment and contact information. The exact categories of data allegedly taken have not been established, however, so conclusions about individual exposure would be premature.

No affected PeopleSoft versions confirmed

Oracle had not responded to questions about whether it was aware of a PeopleSoft pre-authentication RCE zero-day at the time of publication. Consequently, there was no Oracle advisory, patch reference or confirmed list of affected PeopleSoft products and versions cited in the report.

AWS also had not responded to questions about the claimed activity in AWS GovCloud. The allegation concerns workloads managed by the FBI within that cloud environment, not a confirmed compromise of AWS infrastructure or the GovCloud service itself.

The FBI did not immediately comment on the reported intrusion, the alleged data theft or the website disruption. The absence of confirmation from all three organisations means the ShinyHunters FBI hack account should currently be treated as an unverified threat actor claim.

Why ShinyHunters says the operation occurred

ShinyHunters told The Register that this alleged operation was not financially motivated. Unlike attacks in which stolen information is used to support a multimillion-dollar ransom demand, the group said it was not requesting payment from the FBI.

Instead, ShinyHunters wants the agency to correct or retract statements included in an FBI bulletin dated 15 May 2026. That bulletin followed the group’s claimed breach of education technology provider Instructure’s Canvas platform, from which it said it had obtained data linked to hundreds of millions of students, teachers and staff.

The FBI bulletin reportedly said ShinyHunters uses harassment tactics, including threatening messages and calls directed at victims and their families, and swatting in some cases. It also stated that extortionists may falsely claim to possess sensitive or embarrassing material that does not exist.

ShinyHunters disputes those descriptions and presented the alleged FBI intrusion as an attempt to force a correction. This claimed motive does not validate the technical allegations, but it helps explain why the group says it is publicising the incident without an associated ransom demand.

Current exploitation status and organisational response

There is no confirmed public evidence that a new PeopleSoft zero-day is being exploited more widely. The only exploitation claim described in the report came from ShinyHunters, and neither Oracle nor the alleged victim had verified it by the time the story was published.

Organisations operating Oracle PeopleSoft should avoid assuming that every deployment is affected. They should nevertheless use the claim as a reason to check controls around any internet-accessible PeopleSoft services while awaiting authoritative technical information.

  • Identify PeopleSoft applications exposed to the internet, particularly recruitment and HR portals.
  • Review web, application, identity and cloud logs for unexplained command execution, new sessions, unusual data transfers or movement between connected systems.
  • Restrict unnecessary external access and confirm that public applications cannot directly reach sensitive internal or cloud workloads.
  • Monitor Oracle security communications for advisories, affected version details, mitigations and patches.
  • Preserve relevant logs and system images if suspicious activity is found, rather than making changes that could remove evidence.

The central issue is uncertainty. The alleged access path, affected PeopleSoft versions, data contents and scale of exfiltration all remain unverified, while the jobs website disruption is the only externally visible element described in the report.

Originally reported by theregister.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call