ShinyHunters says a PeopleSoft zero-day got it into FBI data. FBI is investigating
The extortion group says an unpatched flaw in Oracle's HR and recruiting software let it reach FBI-managed AWS GovCloud servers. The FBI confirms only that it is investigating activity affecting FBIjobs.gov.
The claimed entry point is Oracle PeopleSoft. As of September 24, Oracle had published no alert for a new flaw.
ShinyHunters, an extortion group, says it broke into FBI systems through a previously unknown flaw in Oracle PeopleSoft, the HR and recruiting software. The claim went public on September 22, 2026. The FBI has confirmed something narrower. It told Nextgov it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
The group says it holds between two and three terabytes on current and former FBI employees and job applicants. 404 Media reviewed a sample of about 5,000 records and says it contains names, home addresses, phone numbers and spouse details. NBC News says a former FBI agent confirmed one sample document was authentic. NBC could not verify the extent of the claims. The group also claims to hold medical records from an FBI health database, The Hacker News reported. Nobody outside the group has confirmed that part.
The claimed path: PeopleSoft, then GovCloud
Every detail of the method comes from the attackers. ShinyHunters told BleepingComputer the flaw is in PeopleSoft, that it gave remote code execution, and that it is still unpatched. It says it moved from there into FBI-managed servers in AWS GovCloud. It also says it is now using the same flaw against large companies.
The FBI has not said where the break happened. "The point of breach is still undetermined," the bureau told Cybersecurity Dive, and it could be a third party or the FBI's own enterprise. The bureau says it works with the third-party providers that support FBIjobs.gov. Oracle and AWS did not comment to Nextgov. As of September 24, Oracle had published no security alert for a new PeopleSoft flaw tied to this incident, Netizen noted. We found no public CVE for it either.
PeopleSoft was hit in June too
This would not be the first PeopleSoft zero-day tied to the group. On June 10, 2026, Oracle shipped an out-of-band fix for CVE-2026-35273, a flaw in PeopleSoft PeopleTools 8.61 and 8.62 that is exploitable without authentication and rated CVSS 9.8. Rapid7 says attackers used it from May 27 to June 9, before the fix existed. Mandiant attributed that campaign to ShinyHunters, and by Mandiant's count 68 percent of the more than 100 notified organizations were universities and colleges.
ShinyHunters says the FBI flaw is a different one. Cybersecurity Dive says it is unclear whether the bug used here is new or the June one.
The group's stated motive is a May 15 FBI public service announcement about its attack on a learning management system. It demanded a retraction within a week, or it would publish the data, NBC reported. That same announcement warns that threat actors "often use their real or exaggerated claims of access" to push victims into paying.
Why a build studio cares
An HR and recruiting system rarely gets the threat model a team gives its own code. It arrives from a vendor, the vendor patches it, and it quietly holds the home address of everyone who ever applied. If the claimed path is real, the chain is a bought application facing the internet, then the cloud account behind it, and neither layer shows up in the buyer's own code review. Vendor-built software is part of your attack surface, which is why we audit it. Until Oracle says more, the checkable questions for a PeopleSoft owner are small: is the June fix for CVE-2026-35273 applied, and which PeopleSoft endpoints can the public internet reach? Rapid7 says the June attacks went after two of them, /PSEMHUB/hub and /PSIGW/HttpListeningConnector.
Next step: if you run PeopleSoft, confirm the fix in Oracle's June security alert for CVE-2026-35273 is applied, and watch Oracle's security alerts for a new one. If you run vendor software you cannot see inside, write to us at hello@gattyworks.com.