Security14 publishers3 min readPublished
ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE
The extortion crew defaced apply.fbijobs.gov on September 22 and told reporters it got remote code execution from a new Oracle PeopleSoft flaw, the same one it says it is now using against Fortune 500 targets. No technical details are public.
The Watch · Security desk

What happened
- Hackread saw apply.fbijobs.gov defaced on September 22, 2026 with a page reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS", the group's branding and a link to its dark web leak site.
- ShinyHunters told BleepingComputer the initial access was remote code execution against Oracle PeopleSoft, followed by lateral movement into FBI-managed AWS GovCloud infrastructure.
- The group claims it took between 2TB and 3TB covering current and former FBI employees, job applicants and other internal records.
- 404 Media broke the story after receiving a sample of about 5,000 purported FBI employee records, and said some contents checked out, including numbers associated with Justice Department personnel.
- The FBI told Reuters it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is investigating.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The group worked the education sector first and has named its next target set as corporations including the Fortune 500. Every internet-reachable PeopleSoft instance sits inside that stated scope.
- constraint BleepingComputer could not verify the zero-day, the lateral movement or the data volume. Any operator pulling PeopleSoft off the internet this week is acting on an extortion crew's description of the bug.
- decision The defaced site is the FBI's own Oracle applicant portal. Organisations running PeopleSoft self-service for external job applicants have to decide whether that endpoint stays public with no patch available.
- precedent One earlier PeopleSoft flaw carried this crew into more than 100 organisations, mostly universities. That is the reach to expect from a single working PeopleSoft bug in their hands.
The crew has been in PeopleSoft before. ShinyHunters weaponized CVE-2026-35273 in June 2026 to break into enterprise networks and extort the victims [15]. The flaw it describes now is a different one. It says the bug remains a zero-day and has released no technical details [17], and no public description of a PeopleSoft pre-authenticated RCE zero-day exists [14]. About three months separate the June exploitation from this one [2].
"The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," the group told BleepingComputer [5]. BleepingComputer asked Oracle and Google Cloud's Mandiant whether either was aware of a new PeopleSoft vulnerability or related exploitation activity [11]. ShinyHunters also says it tried to erase evidence of its activity from the servers it touched, to make the zero-day harder to identify [10].
Take that last claim at face value and a clean PeopleSoft log review means less than it looks. For now the work is exposure and behaviour: whether the application server is reachable from the internet, and which cloud credentials it can use from where it sits.
The group's stated motive is retaliation. The FBI's IC3 public service announcement titled "ShinyHunters: Cyber Criminal Group Attacks Learning Management System" was published on May 15, 2026, and the group cites it as the reason for the attack [18]. ShinyHunters says it found the bug on a Monday night and used it immediately, which dates the intrusion to September 21 [1]. That is 130 days after the advisory [3]. The statement was addressed to FBI Cyber Division Assistant Director Brett Leatherman and Director Kash Patel [23].
Etay Maor, VP of threat intelligence at Cato Networks, said in remarks published by The Hacker News that "Its recent playbook has emphasized abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter" [19]. The intrusion described here is perimeter exploitation. Maor also described the group as a resilient criminal brand that has outlasted takedowns, arrests and forum seizures by evolving its methods and attracting new operators, and as more than a fixed set of people or infrastructure [25]. He flagged the September 23 timestamp on the group's post against September 22 coverage in the US as a pointer toward activity in Asia, and said it is not a definitive attribution [20].
ShinyHunters names Criminal Justice, HR and Medlink among the FBI services it says were compromised [7]. The jobs portal now returns "Scheduled Maintenance Underway. We're Sniffing Out Site Updates for You!" [22], and the group's account of the shutdown is that the FBI "literally pulled the plug on everything" [21].
What to watch
- An Oracle advisory, a CVE, or a Mandiant write-up with indicators would give PeopleSoft operators something to scan and patch. For now there is only exposure to reduce.
- A named corporate victim from the claimed Fortune 500 wave would move the reuse claim off the actor's word.
- Whether the FBI investigation confirms PeopleSoft as the initial access vector or places the jobs portal defacement separately.