FBI rushes to investigate if ShinyHunters hack of thousands of employees is real
ShinyHunters claims breach of FBI employee data via Oracle PeopleSoft zero-day; FBI investigating and warning staff.
ShinyHunters told FBI Director Kash Patel it would change an advisory only if demands were met within one week, claiming access to sensitive FBI employee data via a weaponized zero-day in Oracle PeopleSoft. The FBI has not confirmed the breach and says the point of compromise is undetermined; the FBI jobs site remains offline and personnel were emailed to protect themselves. The group denies financial motive and says it will keep using the PeopleSoft zero-day, with experts expecting a data leak if the deadline passes.
- ShinyHunters claims FBI employee data stolen via Oracle PeopleSoft zero-day
- FBI says breach point undetermined; jobs site offline, staff warned
- One-week deadline to comply with demands or risk data leak
- Group denies extortion, claims motive is to 'set the record straight'
Full article304 words · extracted from arstechnica.com · click to collapse
To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or presumably risk a breach of sensitive employee data.
FBI warns employees to be safe
Not many details have been released on how ShinyHunters got access to the data. ShinyHunters would only tell NYT that “it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.” So far, Oracle is silent on that bug, reports said, while ShinyHunters said it plans to continue using the zero-day for its “businesses’ normal operations.”
The FBI has not confirmed that the hack occurred, but it has begun probing the claims. On Wednesday, the FBI said in an X post that “the point of breach is still undetermined—whether a third-party or the FBI’s enterprise.” Until more information is known, the FBI said, “we are actively and aggressively investigating this matter and working closely” with third-party providers that support the jobs site “to mitigate any and all risk.”
As of Wednesday, the jobs site remained inaccessible, as sources inside the FBI told Bloomberg that all personnel received an email warning them to “take steps to protect themselves while the investigation continues.”
ShinyHunters has not said what will happen if the FBI misses the deadline, but cybersecurity experts told the NYT that most likely the data will be leaked online.
“We cannot comment on what we will do if the FBI does not comply with our request,” ShinyHunters said in an email to the NYT. “We reiterate we are not extorting the FBI and this is NOT financially motivated.”
“Our intention, goal, and motive is solely to set the record straight,” the group said.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/tech-policy/2026/09/fbi-rushes-to-investigate-if-shinyhunters-hack-of-thousands-of-employees-is-real/