# oracle exploit — X 热门讨论 (2026-09-23 21:00 UTC)

## @DropSiteNews (Drop Site) · 09-23 19:35 · ♥58 ↻18 💬2 💢 Hacking group ShinyHunters claimed on Tuesday to have breached multiple FBI-related services and stolen data “on all FBI employees and applicants,” including names, home addresses, phone numbers and spouse information, according to 404 Media.

➤ The group also defaced the FBI’s jobs website Tuesday with a message reading “this site has been seized by ShinyHunters.”

➤ A group representative provided a sample containing data on 5,000 FBI employees, some of which 404 Media verified through open-source tools, and said the group used a zero-day exploit in an Oracle PeopleSoft product to access AWS GovCloud servers and exfiltrate between two and three terabytes of data.

➤ An FBI spokesperson said the agency is “aware of claims” and investigating the incident.

➤ The group, which typically extorts victims after breaches, said its motivation here is not financial but rather “coercion” tied to a prior FBI report describing ShinyHunters’ tactics, which it demanded be corrected or removed within a week. > 引用 @DarkWebInformer: ‼️ ShinyHunters has shared a message on their pay or leak portal to Director Brett Leatherman of the FBI Cyber Division and Director Kash Patel of the FBI:

"Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI,

During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended.

We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to "disrupt" our operations, an effort that ultimately proved unsuccessful.

For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that.

Our PSA today works to address these allegations and correct them.

We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.

We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations:

- "Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. " - "To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting" - " Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist." We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that. We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats. We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS.

Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of "The Com". We have NEVER been apart of "The Com". "The Com" is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense.

As a big believer and supporter of the U.S. Constitution - we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated.

We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to "disrupt" our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation. As any human being would do.

We welcome any and all journalists to inquire us at shinygroup@onionmail.com to hear our side of the story.

Make the right decision, don't be the next headline.

Thank you for your attention to this matter. -SH" https://x.com/DropSiteNews/status/2102844197514481979