CVE Tools

ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

SecurityWeekBy Eduard Kovacs

Reported exploitedPeopleSoftShinyHunters

Our summary

ShinyHunters claims it breached FBI systems, defaced a subdomain of fbijobs.gov, and obtained personal data allegedly belonging to thousands of FBI employees. The group says it used a zero-day flaw in Oracle PeopleSoft to access FBI systems and steal 2-3 TB of information, though the FBI is still investigating and the data's source has not been confirmed. ShinyHunters has previously been linked to in-the-wild exploitation of the Oracle PeopleSoft vulnerability tracked as CVE-2026-35273, but it is unclear whether that flaw was used in the alleged FBI incident.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store