One of the world's most notorious cybercrime crews says it has turned its tools on the very agency that hunts it. On Monday night, the hacking group ShinyHunters claims it broke into FBI systems through a previously unknown flaw in Oracle's PeopleSoft software and walked away with 2 to 3 terabytes of data on current and former agents, their families and people who applied for FBI jobs. The FBI has confirmed it is investigating. If the claims hold up, it would be one of the most sensitive government data breaches in years, and a warning to every organisation that still runs PeopleSoft.
What happened
ShinyHunters says it found a remote code execution vulnerability in Oracle PeopleSoft, a widely used human resources and enterprise platform, and "immediately exploited it" against the FBI. According to the group, it first compromised a PeopleSoft HR server, then moved into storage hosted on Amazon Web Services' GovCloud, where agent and applicant records were kept. The group also defaced FBIjobs.gov, the bureau's recruitment portal, which was taken offline.
In a statement, the FBI said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." Oracle had not publicly commented on whether a new PeopleSoft vulnerability exists at the time of reporting.
Key details
- Volume: ShinyHunters claims 2–3 TB of stolen data covering "almost all" FBI agents and job applicants.
- Data types: Names, home addresses, phone numbers, emails, birth dates, agent status and, in some records, spouse details including Social Security numbers. Some samples reportedly included health-related information.
- Proof offered: The group shared a sample file with journalists said to cover roughly 5,000 FBI employees. 404 Media reported verifying parts of the sample against public records, and security researchers told Axios the attack appears legitimate, though the full dataset has not been independently confirmed.
- Motive: Unusually, the hackers say they are not after money. They are demanding the FBI withdraw a May 2026 alert that described the group's use of harassment, threats against victims' families and swatting, and warned that it sometimes exaggerates its access.
Why it matters
Stolen credit card numbers can be cancelled. The home addresses of federal agents and their spouses cannot. Security experts warn that if this data leaks or is sold, it could be used by criminal groups or foreign intelligence services to target, pressure or blackmail agents and their families. That makes this less a privacy incident than a potential national security problem.
It is also another blow to the FBI's own security record this year. Earlier in 2026, intruders reached FBI systems connected to wiretap and surveillance work, and the personal email account of Director Kash Patel was compromised.
Finally, the method matters as much as the target. ShinyHunters says it is using the same alleged zero-day against Fortune 500 companies and other organisations. PeopleSoft runs payroll and HR at governments, universities and large enterprises around the world, and HR systems are exactly where the most sensitive personal data lives.
Why it matters for developers and Africa's tech scene
Many African governments, banks and universities rely on large enterprise suites such as PeopleSoft and similar ERP platforms, often on older versions that are slow to patch. Security teams should watch closely for an Oracle advisory, restrict internet exposure of PeopleSoft servers, review logs for unusual activity, and treat HR databases as crown-jewel assets. The broader lesson for developers is that a single unpatched internal system can open a path into cloud storage that was assumed to be safe.
What's next
The key questions now are whether Oracle confirms and patches the flaw, how much of the claimed data is real, and whether ShinyHunters follows through on its one-week deadline for the FBI to retract its warning. Expect emergency guidance for PeopleSoft customers if the vulnerability is confirmed, and possibly more victims coming forward.
Also in tech today
- Qualcomm unveiled two new smartphone chips built with a heavy focus on on-device AI.
- Researchers warn that stolen passwords are leaving many US water utilities open to hackers.
- Waymo is making teenagers a new target market for its robotaxi service.
Sources
- TechCrunch: ShinyHunters claims it breached the FBI, stole agents' and applicants' data
- BleepingComputer: ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
- Axios: FBI investigating claims that a major cybercrime group stole sensitive personnel data
- Nextgov/FCW: ShinyHunters claims FBI data theft, demands bureau retract cyber warning
- TechCrunch: Qualcomm launches two new smartphone chips
- TechCrunch: Stolen passwords are exposing America's water providers to hackers
- TechCrunch: Waymo's latest expansion strategy: teenagers
0 Comments