Hacking Group Claims It Stole FBI Staff Data Through an Oracle Flaw
ShinyHunters says it broke in through an unpatched bug in Oracle PeopleSoft. The FBI says it is investigating, and key details are not yet confirmed.

The hacking and extortion group ShinyHunters says it broke into FBI systems and stole data on FBI workers and job applicants. The FBI has said it is looking into the matter. Some of the biggest claims have not been proven, so this story sticks to what is known.
What the Group Claims
ShinyHunters says it used an unpatched flaw, known as a zero-day, in Oracle PeopleSoft. That is business software many large employers use for hiring and HR. The group says the flaw let it run its own code, then move into FBI systems hosted on Amazon's government cloud.
It claims to have taken 2 to 3 terabytes of data on current and former FBI employees and job applicants. It says that includes personal and health details tied to HR, criminal justice and medical services.
What Has Been Confirmed
404 Media first reported the claim. It said some records in a sample it saw were accurate, including phone numbers.
The FBI said it is aware of claims of unauthorized activity affecting FBIjobs.gov and is investigating. The affected systems were reportedly taken offline once the activity was spotted.
BleepingComputer said it could not confirm the zero-day or how much data was taken. Oracle had not commented at the time.
Why It Matters Beyond the FBI
If the flaw is real, it could put other groups that run PeopleSoft at risk too. Leaked personal data on law enforcement staff also raises the risk of harassment and targeted scams.
ShinyHunters said the attack was payback for an FBI report about the group published in May.
What to Do
If you have applied for an FBI job, watch for phishing messages that use your personal details. If your organization runs PeopleSoft, watch for an Oracle advisory and patch as soon as a fix is out.
Questions Readers Ask
Has Oracle released a fix?
Oracle had not commented when the claim was reported on September 22. Groups that run PeopleSoft should watch for an Oracle security notice.
I applied for an FBI job. What should I do?
Be extra careful with emails, texts and calls that use your personal details. Do not click links or share more information, even if the message seems official.
Where This Came From
We confirmed the facts in this story against these reports. The words above are our own.


