Skip to content

Leadership3 publishers3 min readPublished

ShinyHunters claims 2 to 3 terabytes of FBI personnel data from an Oracle PeopleSoft flaw

The bureau has not confirmed a breach and says it cannot yet tell whether its own systems or a third-party provider were the way in, while Reuters and 404 Media report that sample records match real personnel.

The Board Room · Leadership desk

Photograph accompanying ShinyHunters claims 2 to 3 terabytes of FBI personnel data from an Oracle PeopleSoft flaw
Photo: abcnews.com

What happened

  • ShinyHunters said in dark web posts and exchanges with media outlets that it took 2 to 3 terabytes of data on FBI and Justice Department workers, covering both employees and job applicants.
  • The group said it got in through a new vulnerability in Oracle PeopleSoft, a human resources application, and listed criminal justice, human resources and Medlink among the affected services.
  • The FBI has not confirmed a breach, saying on Tuesday that it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is investigating.
  • Reuters said it partially verified a sample it was shown against social security numbers, credit bureau records and previously breached data, including information on FBI director Kash Patel.
  • The FBI jobs site was defaced with a message claiming ShinyHunters had seized it, in the style of an FBI seizure notice, and now tells visitors it is down for maintenance.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure Addresses, dates of birth and spouse details on people whose employer is a federal law enforcement agency are useful for targeting, and that usefulness survives a password reset.
  • constraint With the entry point undetermined between the bureau's own enterprise and a third-party provider, anyone running the same suite is still guessing whether to patch an install or interrogate a vendor.
  • precedent Two PeopleSoft flaws tied to one group inside a year puts HR platforms in the same review tier as finance and customer systems for organisations that run the suite.
  • decision The FBI tells victims not to pay or engage, and the demand here is a correction to an FBI report, so the victim is working from guidance aimed at payment demands.

PC Gamer reported that the sample ShinyHunters gave 404 Media appears to contain the personal data of 5,000 FBI employees [11], and that 404 found it includes addresses, phone numbers, dates of birth and "in some cases details on their spouse" [12]. An applicant file is the most complete record an organisation holds on a person before they are hired. CBS News reported that neither Reuters nor 404 Media has established that the records came from FBI systems [8].

ShinyHunters says the vulnerability it used is new [3]. That is the weakest-supported part of the claim, and the part that matters to other PeopleSoft customers. FBI documents confirm that the bureau's recruiting arm uses PeopleSoft and AWS GovCloud [10]. CBS News called a new software flaw, a breach of FBI systems and large-scale data theft plausible, while saying it has not verified the group's claims [9].

An Internet Crime Complaint Center advisory in May 2026 cautioned that actors using the ShinyHunters name may make real or exaggerated claims of access, threaten victims and their relatives and engage in swatting [19]. Earlier the same month, a May 8 FLASH bulletin warned about stolen credentials and the abuse of trusted vendor and cloud relationships [18]. On Wednesday the bureau said "the point of breach is still undetermined" and that it is "working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk" [7].

PeopleSoft has come up twice in a year of this group's activity. Google documented ShinyHunters exploiting a different PeopleSoft zero-day from May 25 through June 9, a stretch of 16 days [23][27]. Add the flaw claimed this week and two separate PeopleSoft vulnerabilities are tied to the group in 2026, one documented by an outside researcher and one asserted by the attacker [28].

What ShinyHunters wants is a correction to an FBI report. A post addressed to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman said "We have compromised the FBI." [5] The group gave the bureau one week to "correct or remove" portions of the FLASH report it disputes [21]. Its representative told 404 Media that what it planned was "not something I'd call extortion, maybe coercion" [24], while CBS News reported that the group's post rejected descriptions of its actions as ransom, coercion or extortion [22]. In both May warnings the FBI advised organisations not to pay or engage with the demands [20].

FBIjobs.gov has been the primary place to apply for agent and support positions since 2017 [16], so the exposed population, if the claim holds, reaches well beyond current staff. Sources told ABC News that the FBI is still assessing the extent of the breach and what information may have been compromised, and that it is unclear how many people might be impacted [17].

What to watch

  • Whether Oracle confirms or patches a new PeopleSoft vulnerability; CBS News said it has asked the company for comment.
  • Whether the FBI's investigation places the entry point in its own enterprise or with a third-party provider supporting FBIJobs.gov.
  • What the group does when its one-week deadline for the FBI to correct the FLASH report runs out.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories