Alleged ShinyHunters member Saif al-Din Khader, detained in Jordan on Tuesday, is helping the FBI find other members, two sources told Reuters. A new ShinyHunters leak site went up two days later, suggesting other members still run the extortion.
Perspective Coverage
8 publishers
- Builder
- Builder 16%
- Operator
- Operator 71%
- Investor
- Investor 13%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence62
FBI's Brett Leatherman urged ShinyHunters members to surrender after the Dutch arrest of an alleged leader of a group tied to $70 million in extortion. Dutch police have not ruled out more arrests, though the public record so far shows one suspect in custody.
Perspective Coverage
9 publishers
- Builder
- Builder 17%
- Operator
- Operator 68%
- Investor
- Investor 15%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence64
FBI told staff in an internal memo to assume hacking group ShinyHunters stole data on every employee after a claimed 2 to 3 terabyte breach of FBIjobs.gov. Until the bureau confirms the scale, staff and the job applicants the hackers say are also in the files have reason to treat their home addresses as exposed.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence40
ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 58%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives58
- Confidence74
ShinyHunters says it will never publish or sell the 2TB to 3TB of FBI data it claims to hold and calls its one-week ultimatum a marketing campaign. The pledge leaves standing its unverified claim that an Oracle PeopleSoft zero-day got it in.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+45
- Incentives70
- Confidence40
Mandiant says ShinyHunters has planted web shells on dozens of Oracle PeopleSoft systems by URL-encoding one character to get past firewall rules. Employers that treated June's stopgap as the fix now have to patch and also look for any access the attackers left behind.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives20
- Confidence70
ShinyHunters is again exploiting Oracle PeopleSoft flaw CVE-2026-35273, getting past WAF rules by URL-encoding one letter of the path, Mandiant reported. The servers now in reach are the ones whose operators filtered the endpoint and never applied Oracle's patch.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence55
ShinyHunters says the two to three terabytes it took from the FBI include psychiatric and medical evaluations of bureau staff. Beside a Reuters sample tying named staff to counterintelligence jobs, those files are exposure no password reset can fix.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence40
ShinyHunters is exploiting an unpatched CVSS 9.8 pre-login flaw in Oracle PeopleSoft, encoding one URL character to slip past WAF rules matching the raw path. Mandiant has confirmed JSP web shells on dozens of systems.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
ShinyHunters claims 623GB from a July social-engineering campaign and leaked part of it. Have I Been Pwned confirmed 1.6 million account records. Both the vendor and the crew can be telling the truth.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 62%
- Investor
- Investor 16%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
ShinyHunters is mass-exploiting PeopleSoft systems that added firewall rules after the summer breaches but skipped Oracle's patch, Mandiant said. For operators that wrote a filter and stopped, the remedy in the report is the patch Oracle already shipped.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
The FBI says it is investigating unauthorized activity affecting FBIjobs.gov. 404 Media reports the intruders came in through an Oracle PeopleSoft applicant server and then reached a government cloud holding agent data.
Perspective Coverage
4 publishers
- Builder
- Builder 19%
- Operator
- Operator 69%
- Investor
- Investor 12%
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+35
- Incentives75
- Confidence60
The extortion crew defaced apply.fbijobs.gov on September 22 and told reporters it got remote code execution from a new Oracle PeopleSoft flaw, the same one it says it is now using against Fortune 500 targets. No technical details are public.
Perspective Coverage
14 publishers
- Builder
- Builder 20%
- Operator
- Operator 67%
- Investor
- Investor 13%
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+40
- Incentives75
- Confidence60
The bureau has not confirmed a breach and says it cannot yet tell whether its own systems or a third-party provider were the way in, while Reuters and 404 Media report that sample records match real personnel.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 63%
- Investor
- Investor 15%
Reality
- Evidence55
- Adoption45
- Hype gap+30
- Incentives80
- Confidence60
The group told The Register it took more than 2TB of HR records and wants a retraction from the FBI, not a ransom. Everyone else running self-hosted PeopleSoft HCM has an extortion group's word and no Oracle advisory.
Reality
- Evidence25
- Adoption20
- Hype gap+40
- Incentives85
- Confidence60
BleepingComputer confirmed a defaced page and an uploaded file on Cl0p's infrastructure. Everything past that is a criminal crew's own inventory, and the route it describes runs through the content layer.
Reality
- Evidence40
- Adoption30
- Hype gap+15
- Incentives82
- Confidence45
Have I Been Pwned traced the 50GB archive to Carhartt's Databricks analytics platform. The exposed fields are emails, names, phone numbers and addresses, which makes this a targeting corpus rather than a credential-stuffing list.
Reality
- Evidence60
- Adoption71
- Hype gap+12
- Incentives66
- Confidence62
ShinyHunters says it voice-phished a RingCentral employee. The vendor sells business telephony, and its core platform never broke. The control that failed was a person.
Reality
- Evidence54
- Adoption71
- Hype gap+16
- Incentives69
- Confidence56