Home / News EN / Hacker Attack on FBI via Oracle PeopleSoft Vulnerability

Hacker Attack on FBI via Oracle PeopleSoft Vulnerability

FBI hacker attack. The extortion group ShinyHunters claims to have compromised FBI systems by exploiting an unresolved zero-day vulnerability in the Oracle PeopleSoft platform, which is used for personnel management.

FBI hacker attack

According to reports from BleepingComputer, initial access was gained late Monday night through the job application portal apply.fbijobs.gov, exploiting a flaw that allows for remote code execution. The FBI stated it is aware of claims regarding FBIjobs.gov and has initiated necessary investigations, but has not confirmed either an intrusion or data theft.

FBI hacker attack: why it matters

The attackers claim to have subsequently moved laterally within the agency-managed AWS GovCloud infrastructure, stealing between 2 and 3 TB of information related to current and former employees, candidates, and internal services such as Criminal Justice, HR, and Medlink. To support their claim, they released a screenshot of the altered hiring site featuring the Pokémon Umbreon logo and the text “THIS SITE HAS BEEN SEIZED”. The group states that the FBI reacted quickly by disconnecting the involved machines.

404 Media, which first broke the news, received a sample containing approximately 5,000 records and verified the accuracy of some phone numbers linked to Department of Justice personnel. Among the displayed data are reportedly details about a special agent involved in an investigation into BreachForums and Director Kash Patel, elements that have not been independently verified.

According to statements from the criminals themselves, the same vulnerability is now being exploited against companies included in the Fortune 500 following a targeted campaign aimed at the education sector. The motivation behind this attack would not be economic: ShinyHunters demands the removal or correction of a FLASH report published by the FBI in May 2026, which describes their operational tactics, and has given one week to comply.

The group denies being part of “The Com” and rejects accusations of harassment and swatting. This is not the first time ShinyHunters has clashed with Oracle: in 2025, an exploit for E-Business Suite attributed to the same criminal group was used in a campaign by the Clop ransomware gang, whose site was defaced last week precisely by ShinyHunters.

What changes and what are the effects

The closest precedent dates back to the sale of the InfraGard database in December 2022: over 80,000 contacts of critical infrastructure professionals were offered for $50,000 by a user who presented themselves with a false application on behalf of a CEO. A year earlier, an email server from the LEEP portal was used to send tens of thousands of false alerts, while the most severe case remains the 2015 theft targeting the Office of Personnel Management, involving the compromise of 21.5 million security badges.

The crucial point now is the PeopleSoft vulnerability: if confirmed, it could affect thousands of public entities and universities that use this management system, including those in Italy. Oracle has not yet published an advisory, and the deadline set by the extortionists is approaching.

Source and further reading on FBI hacker attack: original article.

* Content created with the assistance of artificial intelligence systems.