The hacking group ShinyHunters says it breached the Federal Bureau of Investigation through a zero-day vulnerability and obtained information on all agency employees and job candidates, according to a report published by Infosecurity Magazine. The collective announced the intrusion on its data leak platform, stating the attack was payback for what it calls false statements in an FBI public warning issued May 15. The group's apparent aim isn't ransom but forcing the bureau to retract or revise the announcement.
ShinyHunters provided a data sample to 404 Media containing personally identifying details on 5,000 FBI personnel, including home addresses, telephone numbers, birth dates, and occasionally information about partners. An FBI representative confirmed to 404 Media that the attackers exploited a previously unknown flaw in Oracle PeopleSoft, then moved laterally to AWS GovCloud servers and extracted between 2 and 3 terabytes of information. The group also vandalized the FBI careers portal on September 22, and the site remained offline for repairs at publication time.
This marks the second time in recent months ShinyHunters has weaponized PeopleSoft weaknesses. Between May and June, the group leveraged a zero-day in the software's Environment Management component to compromise dozens of educational organizations. Steve Povolny, vice president of AI strategy and security research at Exabeam, noted that when ShinyHunters burned through that vulnerability hitting more than 100 entities—mostly universities—they later revealed their initial target had been an FBI PeopleSoft server, and that first attempt was unsuccessful. "Three months later they claim a new PeopleSoft zero-day," Povolny stated, adding that this indicates a collective deliberately probing enterprise resource planning systems storing human resources, compensation, applicant, and medical records.
The pattern suggests ShinyHunters views PeopleSoft as a persistent entry point into organizations holding sensitive personnel data. The group's May–June campaign struck education institutions as unintended casualties when its primary FBI objective failed, underscoring how attackers pivot to secondary targets when main operations stall. The reappearance of a fresh PeopleSoft zero-day three months later signals the hackers refined their techniques and returned with a more effective exploit. Because the vulnerability remained unknown to Oracle and security teams before exploitation, traditional defenses like signatures and patches couldn't block the intrusion.
Povolny advised PeopleSoft customers to presume their systems are compromised, verify the earlier zero-day fix is deployed, and either disable Environment Management Hub or remove the PSEMHUB application entirely. Organizations should pull PeopleSoft administrative and integration interfaces off public internet access, then hunt proactively rather than wait for detection signatures that don't yet exist, he recommended. Security teams should search for suspicious POST activity in WebLogic access logs, unauthorized files in PSEMHUB directories, XMLDecoder-based persistence, outbound traffic on port 445, and remote-management agents like the MeshCentral tooling used for command and control in June. Povolny also urged customers to examine the PeopleSoft host and its service identities for unusual API calls, bulk data queries, or authentication events, ship logs off the host since attackers claim they erase local evidence, ensure incident response teams know who owns PeopleSoft, prepare to rotate every credential accessible from those servers, and secure pre-approval to isolate systems quickly. Organizations running legacy enterprise software now face a hard choice between operational continuity and exposure to adversaries who've made these platforms specialty targets.

