ShinyHunters Claims FBI Breach Via PeopleSoft Zero-Day, Highlighting ERP Risk for All Businesses
The hacking group ShinyHunters says it breached the FBI, stealing personal data on employees and applicants, by exploiting a previously unknown vulnerability (a zero-day) in Oracle PeopleSoft software. The group claims the attack was retaliation for an FBI public statement it disagreed with, rather than an attempt to extort money. A sample of the data shared with journalists reportedly included personal details of around 5,000 FBI employees, and the FBI's jobs website was reportedly defaced and taken offline.
According to an FBI spokesperson, the attackers exploited the PeopleSoft flaw and then moved into AWS cloud servers, downloading a large volume of data. This is not the group's first run at PeopleSoft: between May and June, ShinyHunters exploited a related vulnerability in PeopleSoft's Environment Management component to hit dozens of universities, an attack researchers now believe was a byproduct of an earlier failed attempt to breach the FBI.
Security researchers say this pattern suggests ShinyHunters is deliberately targeting enterprise resource planning (ERP) systems like PeopleSoft because they hold valuable HR, payroll, applicant and health records. Organisations using PeopleSoft are advised to assume they may already be compromised, apply available patches, and disable or remove vulnerable components such as the Environment Management Hub.