SHINYHUNTERS CLAIMS FBI BREACH THROUGH ORACLE PEOPLESOFT ZERO-DAY

The ShinyHunters cyber extortion group claims it breached FBI systems by exploiting a previously unknown vulnerability in Oracle PeopleSoft, potentially exposing sensitive information belonging to employees and job applicants. The FBI has acknowledged reports of unauthorized activity affecting FBIJobs.gov and says it is investigating, but it has not confirmed the broader breach claims or the reported volume of stolen data.

According to ShinyHunters, the alleged PeopleSoft zero-day provided initial access before the attackers moved laterally into additional FBI services, including infrastructure hosted in AWS GovCloud. The group claims it obtained between 2TB and 3TB of data, including records associated with current and former employees and applicants. Those figures and the claimed lateral movement have not been independently verified.

The incident gained additional attention after the FBI Jobs website was reportedly defaced with ShinyHunters branding and a message claiming employee and applicant information had been compromised.

Alleged Oracle PeopleSoft Zero-Day Raises Enterprise Concerns

ShinyHunters says the initial intrusion involved a new, unpatched Oracle PeopleSoft vulnerability capable of remote code execution. The group further claims it is using the same alleged flaw against other organizations, including large corporations. As of September 22, public reporting has not established a CVE or independently confirmed the technical details of the claimed zero-day.

For now, the key distinction is between confirmed and alleged information. The FBI has confirmed it is investigating unauthorized-activity claims involving FBIJobs.gov, while claims involving the PeopleSoft zero-day, AWS GovCloud access, internal FBI services, and terabytes of stolen data remain under investigation.

Leave a Comment

Your email address will not be published. Required fields are marked *