Security1 publisher2 min readPublished
ShinyHunters calls its FBI ultimatum a marketing campaign
ShinyHunters says it will never publish or sell the 2TB to 3TB of FBI data it claims to hold and calls its one-week ultimatum a marketing campaign. The pledge leaves standing its unverified claim that an Oracle PeopleSoft zero-day got it in.
The Watch · Security desk

What happened
- On September 22 the group defaced the FBI Jobs portal and said it had also compromised other FBI systems.
- It told Hackread.com that apply.fbijobs.gov was its entry point and that it moved laterally into other services, including AWS GovCloud infrastructure.
- The FBI confirmed it is investigating claims of unauthorized activity affecting FBIJobs.gov and alleged exposure of employee personal data.
- The group's message to Director Kash Patel and Cyber Division assistant director Brett Leatherman gave the FBI "a time of 1 week" to correct or remove allegations it calls false.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure If the group's claim is accurate, the flaw is in Oracle's product, so every internet-facing PeopleSoft deployment faces the entry point used against the FBI jobs site.
- contradiction The FBI's published view is that ShinyHunters may exaggerate its access. The GovCloud movement and the 2TB to 3TB haul rest on the group's word alone.
- cost If the files were taken, FBI employees and job applicants carry the risk, with only the group's word that their records stay unpublished.
The only source for the zero-day is the group's own account of how it got in [4]. Hackread's report does not include a CVE number, an Oracle advisory or technical detail on the flaw [4]. What is public is not enough to rate how exploitable it is. The group's plans for the FBI files have no bearing on whether the flaw works, or on whether anyone else is using it [1].
According to the group, it made the ultimatum ambiguous on purpose. Its original message said its threats and claims were real and "never a bluff," and denied that the action was financially motivated or an extortion attempt [10]. It did not say what would happen when the week ran out [10]. "We worded our statements very carefully and we never clarified nor specifically stated what we would do if the victim entity did not comply within what the public interpreted as a 'deadline'," the group told Hackread.com [11]. It said it deliberately declined to answer journalists who asked, and never called the week a deadline itself [15].
The group put its motive in commercial terms. It said the whole thing was a marketing campaign to protect its business and actively combat disinformation, and that a normal statement would never have drawn such widespread attention to its words and intentions [12]. What it calls disinformation is the FBI's account of its methods, which describes harassment that includes threatening victims and their family members, and swatting [16]. The group denies using those tactics and rejects any association with "The Com" [16].
It also conceded that its record of operations involving stolen corporate data explains why people expected the FBI files to be published or sold [14]. "This was not a threat. It may have been worded like a threat, but ultimately the public has driven this story out of context and made their own wild assumptions and speculations," the group said [13].
What to watch
- An Oracle security advisory or CVE for PeopleSoft that matches the group's account of its entry.
- FBI employee or applicant data surfacing for sale or on a leak site after the one-week period ends.
- FBI findings on whether the intrusion reached AWS GovCloud infrastructure and how much data left.