ShinyHunters claims it exploited an alleged pre-authentication Oracle PeopleSoft zero-day for remote code execution against an FBI jobs webpage, defaced the site, and pivoted into FBI-managed AWS GovCloud infrastructure. The group says it exfiltrated roughly 2–3 TB of data involving current, former, and prospective FBI personnel, as well as agents’ spouses; reported sample records include names, home addresses, and phone numbers, some of which were reportedly verified against public records.
The group says the intrusion was not financially motivated and demands that the FBI retract or correct allegations in a May 15 bulletin linking ShinyHunters to harassment, threatening communications, and swatting. The claims, including the alleged PeopleSoft vulnerability, lateral movement, and data theft, remain unverified: the FBI, Oracle, and AWS had not publicly confirmed the incident. If authentic, the exposure could enable targeted harassment, coercion, extortion, or counterintelligence targeting of FBI personnel and their families.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
The FBI said it was aware of claims of unauthorized activity affecting FBIjobs.gov and was investigating. It did not confirm ShinyHunters' alleged PeopleSoft exploit, GovCloud access, or data theft.
ShinyHunters said the alleged FBI intrusion was not financially motivated and demanded that the FBI correct or retract statements accusing the group of harassment, threats, swatting, and false claims of compromising material. The FBI, Oracle, and AWS had not confirmed the alleged breach, vulnerability, lateral movement, or data theft.
ShinyHunters published an unverified claim that it breached the FBI via an alleged pre-authentication Oracle PeopleSoft remote-code-execution zero-day, defaced the FBI jobs site, pivoted into FBI-managed AWS GovCloud systems, and exfiltrated roughly 2–3 TB of data. The group said the alleged data included information on current, former, and prospective FBI personnel, including agents, applicants, and spouses; samples reportedly contained names, addresses, and phone numbers.
In its May 15 bulletin, the FBI said ShinyHunters used harassment tactics including threatening calls and text messages to victims and their families, and in some cases swatting. The bulletin also warned that extortionists may falsely claim to possess sensitive or compromising material.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcemalware.news
Open sourcenextgov.com
Open sourcemalware.news
Open sourcetechcrunch.com
Open sourcetheregister.com
Open source404media.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.