// 4 ZERO-DAY · 5 CVE · 7 EXPLOIT · 1 ADVISORY IN THE LAST 24H
The criminal group claims it breached the FBI by exploiting a zero-day in Oracle PeopleSoft. No confirmation has come from the FBI, Oracle, or security vendors, leaving the industry paralyzed between immediate alarm and legitimate skepticism.

On September 22, 2026, the criminal group ShinyHunters publicly claimed an attack on FBI systems, asserting it exploited a zero-day vulnerability in Oracle PeopleSoft to exfiltrate roughly 2–3 terabytes of data and deface the recruiting portal apply.fbijobs.gov. The claim, spread across multiple technical outlets, has received no confirmation from the FBI, Oracle, or security vendors as of publication, creating decision paralysis across the industry between immediate alarm and legitimate skepticism.

Key Takeaways
  • ShinyHunters claims it compromised the FBI via a zero-day RCE in Oracle PeopleSoft, with lateral movement into AWS GovCloud infrastructure
  • The group defaced the apply.fbijobs.gov portal with the message "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS" and posted screenshots of a system under the /PSEMHUB/ path as the alleged entry point
  • 404 Media partially verified a sample of roughly 5,000 records: phone numbers match names identified via OSINT Industries and are associated with the Department of Justice on Darkside
  • The NAIC campaign precedent (June 2026) shows ShinyHunters already exploited a PeopleSoft zero-day for 14 days before Oracle patched it

The Attack Chain According to ShinyHunters

The group described a full sequence to BleepingComputer: zero-day exploit with remote code execution in Oracle PeopleSoft, initial access to FBI servers, lateral movement in AWS GovCloud, and massive exfiltration. The representative stated: "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI."

According to CyberInsider, compromised services in the early stages included CJ, HR, and Medlink modules, all components of the PeopleSoft suite. The /PSEMHUB/ path shown in screenshots corresponds to a known servlet in the PeopleSoft ecosystem, though its specific vulnerability is not documented in public advisories.

The group asserts it exfiltrated data on current employees, former employees, and FBI applicants, with an estimated volume between 2 and 3 terabytes. BleepingComputer explicitly stated it has not independently verified the zero-day, the lateral movement, or the data volume. The outlet reported the group's assertions without technical validation.

The Defacement as Visible Proof

The only element verifiable without the group's mediation is the defacement of the apply.fbijobs.gov portal, documented by screenshots circulated on Telegram and Twitter/X. The message read: "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.rooting your systems since '19 ;)" and claimed: "All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information."

Following disclosure, the site was taken offline. A ShinyHunters representative told BleepingComputer: "They literally pulled the plug on everything." The portal's unavailability is confirmed, but the official cause is unknown: scheduled maintenance, incident response, or precautionary measure.

"what we plan to do is not something I'd call extortion, maybe coercion"
— ShinyHunters representative to 404 Media, on the non-financial pressure mechanism

404 Media's Partial Verification and Its Limits

404 Media, the first outlet to report the story, conducted the only documented independent verification in the dossier. It analyzed a sample of roughly 5,000 records provided by the group, cross-referencing phone numbers against the OSINT Industries database and verifying associations with government email addresses on Darkside. The phone numbers match the indicated names and are linked to the Department of Justice.

This verification establishes that the records contain plausibly real data, not that they were actually extracted from FBI systems or that the attack origin matches the claim. The group could have obtained the data from other sources, including unrelated prior government breaches. The boundary between sample authenticity and attack-chain authenticity remains uncrossed.

The Non-Financial Threat and Political Context

ShinyHunters explicitly stated it is not financially motivated. The claimed objective is the removal of an FBI FLASH report within one week. The group denies being part of "The Com," the informal network linking operators like Scattered Spider and LAPSUS$, and contests the accusations contained in the government document.

A representative added, regarding government pressure: "I don't care." If authentic, this posture marks a deviation from the group's historical operational pattern, traditionally oriented toward monetizing stolen data through sales on forums or extortion of corporate victims.

The NAIC Precedent: When PeopleSoft Has Already Fallen

In June 2026, the National Association of Insurance Commissioners confirmed unauthorized access to its Oracle PeopleSoft systems, with attribution to ShinyHunters by Mandiant. In that case, the vulnerability was exploited as a zero-day for 14 days before Oracle released the patch on June 10, 2026. The group subsequently published 3.1 terabytes of NAIC data.

This precedent establishes that ShinyHunters genuinely possesses zero-day exploitation capability in PeopleSoft and has already operated successfully against government targets. It does not, however, prove the same mechanism was replicated against the FBI in September 2026: the technical overlap is plausible, the factual overlap is undocumented.

What to Do Now

  • Government agencies using Oracle PeopleSoft must immediately audit access logs for servlets under /PSEMHUB/ and check for anomalies in HR, CJ, and Medlink modules
  • Organizations with an AWS GovCloud footprint must strengthen monitoring of lateral flows between on-premise and cloud environments, with particular attention to IAM roles and privileged sessions
  • Threat intelligence teams must track ShinyHunters' sample publications to correlate any new releases with known databases, verifying the uniqueness of exfiltrated data
  • Security leads for HR/ERP platforms must escalate explicit requests to Oracle for advisories on PeopleSoft vulnerabilities, given that no patch or CVE had been published as of September 22, 2026

The Theater of Verification and the Risk of Overreaction

ShinyHunters' strategy combines visible elements (defacement) and verifiable ones (samples with real metadata) with untestable claims (zero-day, data volume, AWS GovCloud). This mix builds credibility without exposing the group to definitive debunking, exploiting the institutional communication vacuum.

For the cybersecurity industry, the operational dilemma is concrete: acting on an unverified claim risks alert fatigue and misdirected defensive spending; waiting for official confirmation exposes organizations to a potentially active exposure window. The absence of a CVE, advisory, or vendor acknowledgment as of September 22, 2026 does not rule out the vulnerability, but it prevents structured management.

The lack of response from the FBI, Oracle, and Mandiant amplifies the effect. Under normal conditions, a breach of this magnitude would generate at least indirect acknowledgment: a security advisory, partner notification, or stealth recommendations to government clients. Total silence fuels both panic and skepticism, resolving neither.

Frequently Asked Questions

Why is there no CVE assigned to the vulnerability?
No source in the dossier reports a CVE identifier. The absence is consistent with zero-day dynamics: if real, the vulnerability has not been publicly disclosed or submitted to the MITRE process prior to the group's claim.
Does the data published by 404 Media prove an FBI origin?
No. 404 Media's verification confirms that phone numbers in the sample match real names and are associated with the Department of Justice, not that the records were extracted from an FBI system or that the attack occurred as described.
Has ShinyHunters demanded a ransom?
The group explicitly stated it is not financially motivated. The pressure exerted demands the removal of an FBI FLASH report, not a payment.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. infosecurity-magazine.com
  3. cyberinsider.com
  4. blog.netmanageit.com
  5. 404media.co
  6. techcrunch.com
  7. insurancebusinessmag.com