ThreatPaper
Unverified

The FBI was breached via a new Oracle PeopleSoft zero-day

Assessment

ShinyHunters told media it gained remote code execution by exploiting a new Oracle PeopleSoft zero-day on an HR/recruitment server, then pivoted to an Amazon-hosted government cloud holding agent and applicant data. This is the group's own account of its method; no vendor advisory, CVE, agency, or outlet has confirmed a PeopleSoft zero-day or the cloud pivot. Critically, the FBI states the point of breach is undetermined and could be a third party rather than its own enterprise, which directly undercuts a confident 'the FBI was breached via PeopleSoft' framing. The claim is specific and plausible given 2026's broader targeting of Oracle enterprise applications, but on the current record it is an unverified attacker assertion, not an established root cause.

Where this claim appeared

ShinyHunters (via The Hacker News) · 2026-09-22

https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

ShinyHunters claims an FBI breach and defaces FBIjobs.gov — what's confirmed and what's only claimed

Think this assessment is wrong? Report an error.