Science1 publisher2 min readPublished
PeopleSoft zero-day claim behind the FBI breach rests on ShinyHunters' word alone
ShinyHunters says a second PeopleSoft zero-day let it steal data on every FBI employee, a claim neither the FBI nor Oracle has confirmed. Two suspects have since been arrested, and PeopleSoft customers are still judging their own exposure from analysts' advice.
The Scientist · Science desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The FBI has confirmed that its employee data was breached but has not described how the attackers got in.
- A suspected ShinyHunters member arrested in Jordan is cooperating with investigators, Reuters reported, a week after Dutch police arrested another suspect.
- No CVE has been assigned to the alleged new flaw, and it has not appeared on CISA's Known Exploited Vulnerabilities catalog, IDC's Philip Harris said.
- The same group found an earlier PeopleSoft zero-day in June that led to a run of extortion attempts long after Oracle said it had patched the bugs.
Compiled by The ScientistSomething wrong?How this is made
Why it matters
- exposure If the group is telling the truth, Harris said every PeopleSoft customer is exposed to an unpatchable, undisclosed flaw with no vendor guidance to act on.
- decision PeopleSoft shops have to decide now whether to pull the Environment Management Hub and Integration Broker off the internet. Dickson says this does not break normal user sessions, so acting on an unconfirmed claim costs little.
- constraint Filtering gives weak protection against an unpatched hole: attackers got past the firewall rules some shops chose over patching last time by changing one character in the URL.
- precedent A second critical preauth RCE in the same window as CVE-2026-35273 would, in Harris's words, show "a pattern of recurring critical exposure rather than one isolated bug."
The case for a new PeopleSoft flaw has one source. ShinyHunters made the claim to The Register before either arrest [14]. "ShinyHunters says it used a second, previously undocumented PeopleSoft preauth RCE zero-day, distinct from the CVE-2026-35273 flaw exploited in the earlier campaign," said Philip Harris, a research director at IDC [15]. He added: "Every outlet covering this is explicit that the zero-day claim comes only from the threat actor, not from independent forensic confirmation or from Oracle. That distinction matters." [12]
The supporting evidence is circumstantial. The FBI shut down its PeopleSoft-based jobs portal after the theft [1]. That fits the group's account. But an operator takes a breached system offline whatever the entry point, so the shutdown cannot separate a new zero-day from the known CVE-2026-35273. The group also claims, as Harris relayed it, that it is already using the flaw against other, unnamed Fortune 500 targets [16]. That claim has the same single source.
I think the claim deserves to be taken seriously, but it has not been established. A group that runs extortion campaigns has reason to advertise new capability, and this one has a record of finding real PeopleSoft holes [6]. Neither the FBI nor Oracle has given official word on PeopleSoft's role [2].
The arrests have not changed that. Analysts and consultants quoted by CIO sharply played down what the arrests mean while playing up the risk from the possible new flaw [13]. In a video about the Dutch arrest, an FBI official warned gang members: "You know how to find us, and we know how to find you." [4]
Frank Dickson, principal analyst at Dickson Research, gave a list a shop can work through without settling the question. "For PeopleSoft shops, the to-do list is short," he said. "Apply Oracle's patch. Disable or remove the Environment Management Hub if you do not use it. Search your logs for encoded variants of the PSEMHUB path, not just the literal string. If you find a web shell, treat the server as compromised and rotate every credential it could read." [9] He also pointed customers to Mandiant's report from late last month, especially "hunting for the web shells and outbound traffic Mandiant describes." [8]
The thing this guidance doesn't tell you is whether a clean result means a clean system. The web-shell and outbound-traffic hunt [8] looks for what an intruder leaves behind after getting in, whichever route was used. The PSEMHUB log search checks one known route [9]. The only account of the route used by the claimed second flaw is the group's own [15].
What to watch
- Whether Oracle issues an advisory or patch, or a CVE is assigned, for a second PeopleSoft preauth flaw.
- Whether CISA adds a new PeopleSoft entry to its Known Exploited Vulnerabilities catalog.
- Whether the FBI or prosecutors, with the Jordan suspect cooperating, disclose the attack vector used against the jobs portal.