Incident
Published 2026-09-22
Verified 2026-09-27

ShinyHunters claims FBI breach via alleged Oracle PeopleSoft zero-day; FBI investigating; sample agent PII partially verified by 404 Media

ShinyHunters (22 September 2026) claims it breached FBI systems using an alleged Oracle PeopleSoft remote-code-execution zero-day, accessed FBI-managed AWS GovCloud, and stole 2–3 TB including employee/applicant PII/PHI (Criminal Justice, HR, Medlink and related services claimed). The group shared a screenshot of apply.fbijobs.gov allegedly defaced with its Umbreon logo; the jobs/special-agent portals later showed maintenance. 404 Media reports receiving a sample of agent names, home addresses, and phone numbers (including spouses) and verifying a portion against public records; TechCrunch and BleepingComputer relay the claim. BleepingComputer states it has not independently verified the alleged zero-day, lateral movement, or volume of stolen data. UPDATE 26 Sep 2026: BleepingComputer reports the FBI confirmed it is investigating the claims without confirming a breach or data theft; ShinyHunters also claims it is exploiting the same alleged flaw against other orgs including Fortune 500s. Separate Google Mandiant/GTIG report the same week documents renewed UNC6240 mass exploitation of already-patched CVE-2026-35273 (PeopleSoft PeopleTools PSEMHUB) with WAF-bypass encoding and SIDEEYE — desk tracks that campaign on card cve-2026-35273; unclear if the FBI claim is that CVE or a distinct flaw. Primary wire: BleepingComputer; corroboration: 404 Media / TechCrunch. Switch primary_url if FBI or Oracle publishes a confirmed notice.

Product
Alleged Oracle PeopleSoft (HR/applicant) → FBI-managed AWS GovCloud / FBI Jobs (apply.fbijobs.gov)
Exploited in Australia?
unknown
Patch to
No Oracle/FBI patch notice yet: treat PeopleSoft internet-facing HR/applicant portals as high risk; enforce network exposure review, MFA, and monitoring for PeopleSoft RCE patterns; watch Oracle Security Alerts / FBI statements for confirmed CVE and fixes; rotate credentials if org shares PeopleSoft stack patterns with the alleged path

Primary: BleepingComputer — ShinyHunters claims FBI / PeopleSoft breach (22 Sep 2026) · Vendor: TechCrunch — ShinyHunters FBI claim (cites 404 Media sample verification) · CVE: CVE-2026-35273 · 404 Media — sample agent/spouse PII partially verified vs public records

breaches identity cloud