The ShinyHunters extortion gang claims it breached FBI systems using a previously unknown Oracle PeopleSoft vulnerability, stealing sensitive data on employees and job applicants. The group also defaced the FBI's jobs website.
ShinyHunters stated it exploited an unpatched zero-day flaw in Oracle PeopleSoft to gain access to FBI-related internal services. The gang claims to have obtained employee and job applicant records, including names, addresses, phone numbers, and information about employees' spouses.
According to 404 Media, which reviewed a sample of 5,000 alleged FBI agent records, the stolen data contains personal contact details and family information. The breach also included defacement of the FBI jobs recruitment site.
Oracle PeopleSoft is widely used by government agencies and enterprises for human resources and financial management. A zero-day vulnerability—one unknown to the vendor and unpatched—represents a significant security risk until Oracle issues a fix.
The FBI has not yet publicly confirmed the breach or the validity of ShinyHunters' claims. The agency typically handles such incidents through established incident response procedures.
ShinyHunters has a history of conducting extortion-based cyberattacks against major organizations. The group typically breaches companies, steals data, and demands payment in exchange for not publishing the information or providing technical details to other threat actors.
This incident highlights the ongoing risk posed by zero-day vulnerabilities in widely deployed enterprise software. Security researchers and vendors often face pressure to address such flaws quickly once they become public, particularly when used in active attacks against government targets.
Oracle has not issued a statement regarding the claimed vulnerability. Organizations using PeopleSoft should monitor for official security advisories and apply patches when available.
WordPress disclosed an unauthenticated path traversal vulnerability that could lead to conditional remote code execution. The issue affects WordPress core and has been documented in an official security advisory.
Security researchers have demonstrated an attack allowing hackers with privileged access to register fake MFA providers and harvest user passwords during login. The vulnerability exploits the authentication process itself.
GrapheneOS, a privacy-focused Android fork, is on track to ship preinstalled on commercial devices within three years. The project has gained significant momentum in developer circles.
A Chinese-speaking threat actor has exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to compromise 996 devices and steal over 18,500 database records from government systems.