ShinyHunters (UNC6240) renewed exploitation of CVE-2026-35273 in Oracle PeopleSoft, bypassing WAF rules through URL-encoding and targeting multiple sectors globally including education, healthcare, and government. The threat actor adapted to published defenses by modifying exploits to reach the vulnerable PSEMHUB endpoint on unpatched systems.
Hacking group ShinyHunters claimed to have breached FBI systems using a zero-day Oracle PeopleSoft exploit, stealing data on all FBI employees and applicants including names, addresses, and phone numbers. The group defaced the FBI's jobs website and demanded the FBI retract or remove a 2026 Q2 report about their tactics within one week, stating their motivation is coercion rather than financial extortion.
ShinyHunters allegedly compromised the FBI using an Oracle PeopleSoft exploit to steal employee data and deface the recruitment website, demanding removal of a FLASH report they claim contains false allegations. The attack may have exploited a known CVSS 9.8 vulnerability that the FBI failed to patch within CISA's required timeline, followed by lateral movement to AWS GovCloud.
Hackers claiming to be ShinyHunters exploited a zero-day vulnerability in Oracle's PeopleSoft to breach AWS GovCloud servers and exfiltrated 2-3 terabytes of data, including alleged records of FBI employees and their spouses with personal information.
Hacking group ShinyHunters claims to have breached the FBI and stolen personal data on all FBI employees and applicants, including names, addresses, phone numbers, and spouse information. The group defaced the FBI jobs website and says it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating 2-3 terabytes of data. The breach poses significant national security and counterintelligence risks, as the stolen data could be used by criminals or foreign intelligence agencies to track and target FBI agents.
According to 404Media, a zero-day exploit in Oracle PeopleSoft was used in an unspecified incident. The report was shared on X (formerly Twitter) on September 22, 2026.