ShinyHunters claims it used an Oracle PeopleSoft zero-day to hack FBI-related services and steal employee and applicant data; it also defaced the FBI jobs site
First reported by 404 Media ·
Personal data for FBI employees and applicants is now accessible by a hacking group, posing potential national security and personal safety risks.
The hacking group ShinyHunters claims to have breached multiple FBI-related services, including the FBI jobs website, which they defaced. A representative stated they obtained data on "all FBI employees and applicants," including names, home addresses, phone numbers, and details about employees' spouses. ShinyHunters provided a sample of 5,000 records to 404 Media, which corroborated some details with open-source intelligence tools and identified some numbers as belonging to U.S. Department of Justice personnel. The group claims the breach occurred Monday night and used a zero-day exploit in Oracle's PeopleSoft, leading to the exfiltration of two to three terabytes of data from AWS GovCloud servers. The defaced FBI jobs site read, "this site has been seized by ShinyHunters." While ShinyHunters typically extorts victims, the group's representative suggested this action was "not financially motivated" and described their plan as "coercion" rather than extortion, indicating a low likelihood of ransom payment from the FBI.
This incident highlights the persistent vulnerability of government systems, even those handling sensitive data like employee PII and applicant information. The successful exploitation of an Oracle PeopleSoft zero-day and subsequent exfiltration of terabytes of data from AWS GovCloud underscores the need for continuous security patching and robust data protection measures within federal agencies. The potential implications for national security and counterintelligence are significant, as foreign intelligence agencies could leverage this information to better understand U.S. law enforcement operations, and individuals could face threats to their safety. The hack also brings to light the evolving tactics of hacking groups, with ShinyHunters indicating a shift from purely financial motives to potentially coercive or disruptive actions.
The implications extend beyond the FBI, raising concerns about the security posture of other government entities that rely on similar Oracle PeopleSoft infrastructure and cloud services. The defacement of the FBI jobs site and the group's commentary suggest a deliberate attempt to sow distrust and expose perceived weaknesses in federal cybersecurity. As a result, agencies may face increased scrutiny and pressure to reassess their security protocols, potentially leading to significant investments in cybersecurity upgrades and employee training. The incident also serves as a stark reminder of the cascading effects of data breaches, where compromised information can be used for various malicious purposes, including espionage, harassment, and destabilization.
AI-written summary. May contain errors.