ShinyHunters says a PeopleSoft zero-day opened an FBI server
Key takeaways
- ShinyHunters claims it found a zero-day in Oracle PeopleSoft, achieved remote code execution on an FBI server, and took 2 to 3 terabytes covering employees, former employees and applicants.
- The FBI has not verified the intrusion, has not confirmed records were stolen, and has not confirmed the PeopleSoft vulnerability was involved. It has confirmed it is investigating.
- The group told The Register the attack was retaliation for a May FBI advisory describing its tactics rather than financially motivated.
- Recruitment portals are structurally exposed: public by necessity, full of identity documents, and patched on enterprise timescales.
The ShinyHunters extortion group says it took between 2 and 3 terabytes of data from an FBI server, and says it was not after money.
None of that is confirmed. The FBI has not verified the intrusion, has not confirmed any records were taken, and has not confirmed that the vulnerability described was involved. What is confirmed is that the bureau is investigating.
What the group claims
ShinyHunters told The Register it found a zero-day in Oracle PeopleSoft and used it to get remote code execution on an FBI server. The data it describes covers employees, former employees and job applicants. The entry point it points to is a page on apply.fbijobs.gov under a /PSEMHUB/ path, supported by a screenshot showing Linux system information.
The group framed the attack as retaliation for an FBI advisory in May that described its tactics, rather than as an extortion attempt. Attacker statements about motive are a form of marketing and are worth treating that way.
Why a jobs portal is the interesting part
Set aside whether this particular claim survives scrutiny. Recruitment and HR systems are a real soft spot in otherwise well defended organisations, for reasons that are structural rather than careless.
A jobs portal has to sit on the public internet, because applicants need to reach it. It collects identity documents, addresses and sometimes health information, because hiring requires them. It runs on enterprise software patched to an enterprise schedule, measured in weeks rather than hours. Those properties pull against each other and the tension does not resolve.
That is the pattern rather than the exception. A single trusted account was enough in the unauthorized access reported across three companies through Gemini, and September's Patch Tuesday alone carried 972 fixes, which tells you roughly how much enterprise patching backlog exists at any given moment.
What to watch
Whether Oracle confirms a PeopleSoft vulnerability. That is the load-bearing claim here, and it is the one that can be checked without the FBI saying anything at all. A PeopleSoft zero-day would matter well beyond this incident, because the same software runs HR and student records at a large number of universities and government agencies. If it turns up in the CISA KEV catalogue, the claim stops being a claim.