ShinyHunters Claims FBI Breach via Oracle PeopleSoft Zero-Day
Share
The hacking group ShinyHunters has claimed to have breached the FBI, allegedly using a zero-day exploit in Oracle PeopleSoft to access sensitive employee information. The group claims to have stolen data pertaining to “all FBI employees and applicants.”
An FBI spokesperson stated that the attackers exploited the PeopleSoft vulnerability before pivoting to AWS GovCloud servers to download between 2TB and 3TB of data. According to reports involving a sample of the data, the exfiltrated information includes personally identifiable information (PII) for approximately 5,000 employees, such as addresses, phone numbers, dates of birth, and details regarding spouses.
ShinyHunters indicated the attack was a retaliatory measure following an FBI Public Service Announcement (PSA) issued on 15 May. The group alleged the PSA contained inaccuracies regarding their operations and claims of possessing compromising material. The group also defaced the FBI jobs website on 22 September.
ShinyHunters has previously claimed breaches aimed at forcing official retractions of government statements.
ERP Systems Targeted by Zero-Day Exploits
Industry experts suggest the incident follows a pattern of targeting Enterprise Resource Planning (ERP) platforms. Steve Povolny, VP of AI strategy and security research at Exabeam, noted that the group appears to be systematically mining platforms that hold HR, payroll, and health data.
Povolny suggested that the group’s previous exploitation of a PeopleSoft vulnerability in the education sector between May and June may have been an unsuccessful attempt to target the FBI, with universities serving as collateral damage.
Mitigation and Security Recommendations
Security researchers advise PeopleSoft customers to assume potential compromise and implement immediate defensive measures. Recommendations include ensuring all previous zero-day patches are applied and disabling the Environment Management Hub or removing the PSEMHUB application.
To detect ongoing or past intrusions, organisations are advised to:
- Monitor for suspicious POST activity in WebLogic access logs.
- Search for unauthorised files in PSEMHUB directories.
- Check for XMLDecoder-based persistence and outbound traffic on port 445.
- Audit PeopleSoft host service identities for unusual API calls or bulk data queries.
- Rotate all secrets reachable from the affected servers.
Experts also recommend shipping logs off-host to prevent attackers from wiping local evidence and ensuring that the incident response team has the authority to isolate systems rapidly.




Leave a Reply