Skip to content
vulnerabilityVulnerability Research

ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day

2 min read
Share

ShinyHunters claims FBI breach via Oracle PeopleSoft zero-day

The ShinyHunters extortion group is claiming a breach of FBI systems through an unpatched Oracle PeopleSoft zero-day. The group states it has exfiltrated sensitive internal data. No CVE has been assigned to the claimed vulnerability. The FBI has not confirmed the breach. ShinyHunters has a documented history of high-profile breaches and has previously published sample data to substantiate similar claims.

The claimed breach

ShinyHunters posted on a criminal forum claiming access to FBI internal systems via a zero-day in Oracle PeopleSoft, a widely deployed enterprise HR and financials platform. The group claims to have exfiltrated data including personnel records. Oracle PeopleSoft has a history of critical vulnerabilities enabling pre-authentication remote code execution, and the platform is deployed by federal agencies, universities, and large enterprises globally. Oracle and the FBI have not issued public statements on the specific claim at time of writing.

Oracle PeopleSoft as an enterprise attack surface

PeopleSoft is one of the highest-value targets in federal and enterprise environments because it holds personnel data, payroll records, and in some cases security clearance processing records. A successful breach can yield data that enables identity theft, phishing, and social engineering at scale. PeopleSoft deployments that face the internet, or that can be reached through perimeter compromises, are persistent high-value targets. Oracle issues critical PeopleSoft patches in its quarterly Critical Patch Update; many organizations run PeopleSoft on long patch cycles due to customization complexity, creating exposure windows that can last months.

What organizations running PeopleSoft should do

Immediately review your PeopleSoft patch status against Oracle's most recent Critical Patch Update. PeopleSoft administrative interfaces should not be publicly accessible; if yours is, restrict access to internal networks or VPN today. Enable detailed audit logging on privileged PeopleSoft accounts and review recently granted access. Treat an unverified claim like this as a reason to increase monitoring rather than wait for official confirmation: ShinyHunters has historically followed breach claims with sample data releases. If you use PeopleSoft for HR or payroll, notify your security team to review access logs for anomalous activity in the past 30 days.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help assessing your PeopleSoft deployment's exposure or reviewing your Oracle patch status.