ShinyHunters Claims FBI Breach via Oracle PeopleSoft Zero-Day
Extortion group alleges compromise of FBI systems through unpatched PeopleSoft vulnerability; claims unverified

Key Takeaways
- ShinyHunters claims an Oracle PeopleSoft zero-day was used to breach FBI systems.
- Sensitive employee and applicant data is alleged to have been exfiltrated.
- No independent confirmation of the zero-day CVE or active exploitation has been provided.
- FBI and Oracle have not issued statements confirming the incident.
- Organizations using PeopleSoft should ensure timely patching and monitor official advisories.
Quick answers
- What happened?
- The ShinyHunters ransomware operation claims it breached FBI systems using a previously unknown Oracle PeopleSoft vulnerability, exfiltrating sensitive employee and applicant data. As of now, neither the FBI nor Oracle has confirmed the breach or the existence of a zero-day CVE.
- Which products are affected?
- Oracle PeopleSoft
- What should defenders do?
- Organizations running Oracle PeopleSoft should apply the latest security patches and release bundles issued by Oracle. Enable network segmentation to limit lateral movement, monitor for unusual administrative activity, and subscribe to Oracle's Critical Patch Update advisories. Until a CVE is published, treat the claim as unverified but prioritize patching known PeopleSoft vulnerabilities.
According to a report by BleepingComputer published on September 22, 2026, the ShinyHunters extortion gang asserted that it compromised FBI information technology systems through a new, as-yet-unpatched Oracle PeopleSoft vulnerability. The group claimed the exploit allowed access to internal services and the theft of sensitive data belonging to FBI employees and job applicants. The report states that ShinyHunters is leveraging the alleged zero-day to demand payment or data deletion assurances. Both the FBI and Oracle have issued no official confirmation regarding the breach or the purported vulnerability. Security researchers and industry observers note that zero-day claims attributed to extortion groups often lack independent verification and should be treated with caution until corroborated by vendor advisories or credible threat intelligence.
Security Details
The claim centers on a purported Oracle PeopleSoft zero-day vulnerability. No CVE identifier has been assigned, and Oracle has not released a security advisory addressing this specific issue. The FBI has not confirmed any compromise of its systems. As is typical with extortion group assertions, the technical details and scope of the alleged exploit remain unverified.
Affected products
Oracle PeopleSoft
Mitigation
Organizations running Oracle PeopleSoft should apply the latest security patches and release bundles issued by Oracle. Enable network segmentation to limit lateral movement, monitor for unusual administrative activity, and subscribe to Oracle's Critical Patch Update advisories. Until a CVE is published, treat the claim as unverified but prioritize patching known PeopleSoft vulnerabilities.
Sources
BleepingComputer
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
Sep 22, 2026 · 19:13
Original link
Related Security News

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.




