ShinyHunters Claims FBI Breach via PeopleSoft Zero-Day
ShinyHunters claims it breached FBI systems via an unpatched Oracle PeopleSoft zero-day, exfiltrating employee data. FBI and Oracle have not confirmed.

Status: Unconfirmed. Claim originates with the threat actor. FBI and Oracle have not responded as of publication.
ShinyHunters says it breached FBI systems through a zero-day flaw in Oracle PeopleSoft, per BleepingComputer. The group claims access to FBI internal services and exfiltrated sensitive data on employees. No CVE has been assigned to the alleged flaw. Oracle has not issued an advisory or patch.
Oracle PeopleSoft is deployed across federal agencies, universities, and large enterprises for HR, payroll, and records management. An exploitable flaw in an internet-facing instance exposes personnel data at scale. No remediation path exists until Oracle publishes an advisory.
ShinyHunters has run active campaigns across sectors throughout 2026: Cl0p onion infrastructure breach, Cl0p victim extortion, McKesson patient records, M365 adversary-in-the-middle phishing.
Confidence: LOW on breach scope and method. Confirmation requires FBI statement or Oracle advisory. Developing.
Found this useful? Share it.


