ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day, Defaces FBIjobs.gov — FBI Says It Is Investigating
ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day, Defaces FBIjobs.gov — FBI Says It Is Investigating
The cyber extortion group known as ShinyHunters claimed on Tuesday that it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees and job applicants. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group wrote on its dark web site, listing the FBI's Criminal Justice (CJ), HR and Medlink services as compromised. A spokesperson told The Register the group exploited a new Oracle PeopleSoft zero-day to gain remote code execution and defaced the FBI's jobs site with a "This site has been seized by ShinyHunters" banner. In a statement shared with Reuters, the FBI said it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." The claim was first reported by 404 Media.
ShinyHunters framed the attack as retaliation for a May 2026 FBI public service announcement that detailed the group's targeting of Canvas, an online learning management system, and urged victims not to pay. In its own counter-PSA, the group called the allegations "substantial false allegations" and dismissed its widely reported ties to The Com collective as "propaganda started by the Information Security Industry."
The technical claim raises questions of its own. No public details exist of a PeopleSoft pre-authenticated RCE zero-day, though ShinyHunters weaponized a similar flaw, CVE-2026-35273, in June 2026 to break into enterprise networks and extort victims. Visitors to the jobs site now see a maintenance message — "We're Sniffing Out Site Updates for You!" — rather than the seizure banner.
Escalation Between Rivals
The FBI claim is the group's second high-profile move in a week. Days earlier, ShinyHunters hijacked the dark web leak site of the Clop (aka Cl0p) ransomware crew and posted an extortion note of its own, demanding a share of its rival's earnings: "2.333% of my net worth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable."
"ShinyHunters' claim of an FBI breach is an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups and should absolutely be taken seriously," said Etay Maor, VP of threat intelligence at Cato Networks. He noted one small operational clue: the September 23 timestamp on the group's post, while the news emerged September 22 in the U.S. — if the timestamp reflects the group's real operating environment, it points toward activity in Asia. Maor also described ShinyHunters as a resilient criminal brand that has outlasted takedowns and arrests by evolving its methods, and said its recent playbook emphasizes "abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter."
What Should You Do?
- If you run PeopleSoft (or any Oracle enterprise suite) with an internet-facing portal, treat this as a prompt to check exposure now — the claimed zero-day is unverified, but the group's June exploitation of CVE-2026-35273 is documented. Restrict admin paths, enable login anomaly alerts, and confirm your patch level for previously fixed PeopleSoft RCEs.
- Assume credential-harvest pressure on HR systems. Job application portals hold identity data on external applicants — people you cannot force through MFA. Limit what those accounts can reach.
- Audit OAuth applications and SaaS integration tokens — the identity paths this group is known to abuse — and review help-desk processes for social-engineering resistance (callback verification, MFA for reset flows).
- Prepare for the leak, not just the breach. Extortion groups escalate to data publication; know in advance which datasets would be damaging and who owns the notification decision if they appear.
The WAF Angle
Whatever the forensics ultimately confirm, the claimed entry path is a familiar one: an unauthenticated RCE in an enterprise application that faces the internet because it must serve the public. Jobs portals, student portals, supplier portals — these are the classic soft spots, because they sit outside the employee SSO perimeter and run heavyweight enterprise software with a long RCE history. A WAF in front of such portals is not a formality: request-inspection rules that block deserialization gadget patterns and known exploit probes buy time while vendor patches catch up. And the ShinyHunters playbook detail worth repeating to leadership: their profitable attacks run through identities and tokens, not just vulnerabilities — so protect the OAuth app inventory and integration tokens with the same rigor as the perimeter they bypass.