ShinyHunters Claims Major Breach of FBI Systems, Says Motive Is Not Money
The cybercrime group ShinyHunters says it has breached FBI systems and stolen more than 2 terabytes of data belonging to current, former, and prospective employees. According to the group, the attack began with exploitation of an alleged zero-day vulnerability in Oracle PeopleSoft software on the FBI's jobs website, which allegedly allowed remote code execution. The group says it then defaced the site and moved laterally into FBI-managed servers hosted on AWS GovCloud, claiming access to systems tied to human resources, MedLink, and Criminal Justice Information Services.
Unusually for the group, ShinyHunters says this incident is not about financial gain. Instead, the group wants the FBI to retract statements from a May bulletin that described ShinyHunters as using harassment tactics such as threatening calls, swatting, and false claims of possessing compromising material against victims. Neither the FBI, Oracle, nor AWS had responded to requests for comment at the time of reporting, so key details of the claimed breach remain unverified.
This case highlights how software supply chain flaws, such as vulnerabilities in enterprise platforms like PeopleSoft, can expose even highly secure organisations to serious data theft risks. Businesses using similar enterprise resource platforms should watch for vendor security advisories and patch promptly once details emerge.