$ techbeacon▋
Ransomware

Extortion Group ShinyHunters Alleges FBI Compromise via Unpatched PeopleSoft Flaw

Extortion Group ShinyHunters Alleges FBI Compromise via Unpatched PeopleSoft Flaw

An online extortion collective calling itself ShinyHunters says it infiltrated Federal Bureau of Investigation networks by exploiting a previously unknown vulnerability in Oracle's PeopleSoft enterprise software. The group claims the attack gave it access to internal portals and allowed the theft of personal information belonging to FBI staff and job applicants.

According to the gang's statement, the zero‑day exploit targets a core component of PeopleSoft that handles authentication and data exchange. By leveraging the flaw, ShinyHunters says it bypassed standard security controls, moved laterally across the agency’s internal environment, and exfiltrated files containing names, contact details, and employment histories.

PeopleSoft, a suite of applications for human resources, finance, and campus management, is widely deployed across U.S. government agencies. While Oracle routinely patches known weaknesses, a zero‑day—an undisclosed vulnerability—poses a particular challenge because defenders have no prior signature or mitigation. Security researchers have warned that legacy ERP systems are attractive targets for threat actors seeking high‑value data.

The FBI has not publicly confirmed the breach, but the agency’s cyber‑defense unit routinely monitors for indicators of compromise linked to known extortion groups. ShinyHunters has previously demanded payment from universities and private companies after exposing stolen data, a pattern that suggests the group may be seeking a ransom from the bureau as well.

Cybersecurity analysts note that the alleged breach underscores the difficulty of protecting large, complex networks that rely on third‑party software. Even agencies with robust security programs can be exposed when a vendor product contains an undisclosed flaw. The incident may prompt a broader review of PeopleSoft deployments and accelerate the push for rapid patching cycles.

Federal officials are expected to coordinate with Oracle and other partners to assess the scope of the intrusion, contain any further leakage, and determine whether additional data—beyond employee records—has been compromised. The case also raises the prospect of new guidance on zero‑day response and potential legislative attention to improve the resilience of critical government systems.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related