ShinyHunters claims it breached FBI systems by exploiting an unpatched Oracle PeopleSoft zero-day, then moved into FBI-managed AWS GovCloud infrastructure and stole sensitive employee and applicant data. The group also says it defaced the FBI Jobs site, targeted additional organizations with the same flaw, and framed the intrusion as retaliation over an FBI FLASH report. #ShinyHunters #OraclePeopleSoft #FBI #AWSGovCloud #KashPatel
Keypoints
- ShinyHunters claims it used a new Oracle PeopleSoft zero-day to breach FBI systems.
- The group says it moved into FBI-managed AWS GovCloud infrastructure after the initial access.
- It claims to have stolen 2TB to 3TB of data, including employee and applicant records.
- The alleged intrusion affected FBI Criminal Justice, HR, Medlink, and other services.
- ShinyHunters says it is also exploiting the same flaw against other organizations, including Fortune 500 firms.