mrkeyoor.com_
Wed 23 Sept 09:36 UTC
Tech6 min read

A 569-Point FBI Breach Claim Still Lacks Public Proof

ShinyHunters says it stole 2TB to 3TB from FBI systems. A defaced jobs site and a small data sample support concern, but not the gang's full claim.

By the September 23 snapshot, the FBI breach story had reached 569 Hacker News points and 394 comments. The evidence available to readers still stopped at a defaced recruiting site, a 5,000-record sample reviewed by one newsroom, and the attackers' account. The thread surged before the FBI had confirmed any data theft. Repeating "all FBI employees" as an established breach would turn an extortion group's widest claim into the headline fact.

ShinyHunters says it used a new Oracle PeopleSoft zero-day, moved into FBI-managed AWS GovCloud systems, and stole between 2TB and 3TB of data. The bureau's public position is much narrower. It told BleepingComputer that it was investigating claims of unauthorized activity affecting FBIjobs.gov. It did not confirm that the wider FBI network was breached, that GovCloud was reached, or that any data was taken.

What the public record supports

A ShinyHunters representative told 404 Media that the group held data on all FBI employees and applicants. The outlet saw a sample of about 5,000 alleged employee records containing names, addresses, phone numbers, and spouse details. That is direct reporting on material supplied by the claimant. It is stronger than a post on a leak forum, but the sample does not establish where every row came from or whether it represents the bureau's full workforce.

There is separate evidence that the recruiting site was altered. BleepingComputer received a screenshot showing apply.fbijobs.gov with ShinyHunters branding and a message claiming employee and applicant information had been compromised. The publication also received two alleged personnel records, one tied by the attackers to an agent and one to FBI Director Kash Patel, but said it could not verify their authenticity or source. A website defacement demonstrates unauthorized control over that web property. It does not map the attacker's access beyond it.

The 5,000-row sample adds weight, with an important limit. BleepingComputer reported that 404 Media checked some phone numbers and found matches for people with the same names, including numbers associated with US Department of Justice personnel. That can show that some entries describe real people. It cannot, by itself, show that the records were freshly taken from an FBI system rather than assembled or enriched from another source. 404 Media's published introduction calls them alleged agents for that reason.

The unverified portion is much larger: a new unpatched PeopleSoft flaw, lateral movement into GovCloud, access to criminal justice and medical services, 2TB to 3TB of exfiltration, and coverage of every employee and applicant. BleepingComputer explicitly said it had not independently verified the zero-day, lateral movement, or volume. Its report also said Oracle and Google's Mandiant team had been asked about the alleged new vulnerability, with no response included at publication.

The PeopleSoft history raises the stakes

The attack path is plausible because ShinyHunters has recently exploited PeopleSoft, but that history does not confirm the latest claim. In June, Google Threat Intelligence Group and Mandiant documented a campaign exploiting CVE-2026-35273 against PeopleSoft infrastructure. The activity ran from May 27 to June 9, before Oracle issued its June 10 alert, so the flaw was used as a zero-day during that period.

CVE-2026-35273 was an unauthenticated remote-code-execution flaw in PeopleSoft's Environment Management component with a CVSS score of 9.8. Google notified more than 100 organizations whose internet addresses appeared tied to exposed endpoints; 68 percent were higher-education institutions. Some organizations blocked or remediated the activity, while others had stolen data published on the ShinyHunters leak site, according to Google's investigation.

The confirmed campaign also shows how a PeopleSoft foothold could become a wider incident. Google's researchers found customized MeshCentral agents, internal reconnaissance, and a script that tried common administrative credentials over SSH to spread through PeopleSoft hosts. Their recovered command history included compression of exfiltrated directories with zstd and a later connection to infrastructure hosting the group's public leak site. Those findings belong to the May and June campaign, not the FBI event.

Oracle's security alert for CVE-2026-35273 covers PeopleTools 8.61 and 8.62 and says the flaw can be exploited remotely without credentials. Oracle also warns that older unsupported releases may be affected even though they were not tested. ShinyHunters now claims it found another PeopleSoft zero-day. No Oracle advisory cited in the current reporting identifies that alleged second flaw, so the known June CVE and the claimed September entry point must stay separate.

A sample cannot prove a complete breach

Extortion claims mix checkable details with claims only the victim or attacker can verify. The jobs-site defacement is checkable. A subset of names and phone numbers can be checked. The source database, collection date, record count, fields, and path into other systems require logs or a victim-side investigation. The FBI's statement to BleepingComputer confirms that investigation, not its outcome.

The 2TB to 3TB figure has the same problem. It comes from ShinyHunters, and neither newsroom said it independently measured the archive. Volume alone would not reveal whether the material contains unique personnel files, duplicated backups, application data, or unrelated system content. Hacker News commenters debated whether an exfiltration that large should have triggered monitoring, but the thread is evidence of community attention, not network telemetry from the FBI.

Even a genuine 5,000-record sample cannot support the word "all" without a denominator and a documented sampling method. Investigators would need to determine how many unique people are represented, whether former staff and applicants are mixed with current employees, and whether the records came from one system or several. The original 404 Media report establishes what its reporter saw and what the source said. It does not publish a forensic account of the alleged intrusion.

This caution does not make the personal-safety risk smaller. Names paired with home addresses, phone numbers, and spouse information could support targeted harassment or impersonation if the records are authentic. In a May warning about ShinyHunters, the FBI's Internet Crime Complaint Center said the actors use both real and exaggerated access claims, sometimes contact victims and relatives, and have posted stolen data after applying pressure. The same notice advised potential victims to wait for formal scope guidance rather than treat an attacker's message as a breach notice.

What PeopleSoft teams can do today

PeopleSoft administrators do not need the FBI claim to be settled before checking exposure to the known flaw. Google's June guidance says teams should disable the Environment Management Hub service in multi-server setups or remove the PSEMHUB application in single-server setups. Where that is not possible, it recommends blocking external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector. Google says those administrative endpoints are not required for ordinary browser sessions.

Logs can answer a more useful question than the headline: did an untrusted address send a POST request to /PSEMHUB/hub or /PSIGW/HttpListeningConnector? Google's indicators also include unexpected JSP files under the deployed PSEMHUB.war application, unfamiliar transaction directories, and outbound SMB traffic on TCP port 445 from PeopleSoft hosts. Those checks target the documented CVE-2026-35273 campaign. They are not indicators for the alleged new zero-day unless Oracle or an incident-response team later connects the two.

Oracle urges customers on affected PeopleTools versions to apply its mitigations immediately and remain on supported releases. Its June alert says releases outside Premier or Extended Support may also contain the flaw, while patches and mitigations are provided only for supported versions. An inventory that ends at "we run PeopleSoft" is therefore incomplete; version, exposed endpoints, and support status decide what action is available.

For people who receive messages claiming to contain their data, the FBI's May guidance is plain: verify unusual requests through a separate known channel, do not pay, avoid unexpected links or attachments, and retain incident details for reporting. Those steps were written for an earlier ShinyHunters campaign, but they fit the present uncertainty because the notice explicitly accounts for both stolen data and fabricated claims.

The next evidence to watch

Three developments would materially change the status: an FBI incident notice defining affected systems and people, an Oracle advisory or CVE for the alleged new PeopleSoft flaw, or independently verified records whose provenance can be tied to an FBI system. BleepingComputer's report says the FBI investigation is active and that Oracle and Mandiant were contacted. Until one of those sources adds evidence, the 2TB to 3TB figure and GovCloud access remain claims.

The story's 569-point rise shows how quickly a specific number and a famous target can outrun the available proof. PeopleSoft operators already have a documented 9.8-severity flaw and concrete checks from Google's investigation. They should act on that record now. The alleged FBI-wide breach should stay labeled as unresolved until the investigation supplies the missing scope.

We reviewed this

  1. Files — our honest review
  2. requests — our honest review
  3. browser — our honest review

Sources

  1. 'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees
  2. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
  3. ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit
  4. Oracle Security Alert Advisory - CVE-2026-35273
  5. ShinyHunters: Cyber Criminal Group Attacks Learning Management System
  6. 'We hacked the FBI:' Hackers say they have data on all FBI employees