The group provided samples to researchers containing personal details of 5,000 individuals, including home addresses, phone numbers, and information regarding spouses. Verification efforts by independent outlets confirmed that some of these phone numbers align with Department of Justice personnel. ShinyHunters alleges they bypassed security via a zero-day vulnerability in Oracle PeopleSoft software, eventually accessing FBI-managed servers on AWS GovCloud. They claim to have siphoned between two and three terabytes of data from systems including human resources and the Criminal Justice Information Services.
The FBI confirmed it is investigating unauthorized activity affecting the FBIjobs.gov portal but has not verified the scope of the exposure. Cybersecurity firm CyPro noted that the hackers failed to provide specific technical evidence to substantiate the PeopleSoft exploit, leaving the full extent of the compromise unconfirmed. The group demands the FBI retract its May 15 advisory, which described ShinyHunters as using harassment and swatting to extort victims. This incident follows a pattern of aggressive activity from the collective, which recently hijacked the leak site of the Cl0p ransomware gang. For those potentially affected, the fallout extends beyond the bureau’s internal feud, as the exposure of home addresses and family details creates significant risks for identity theft and physical targeting.



Comments (0)
No comments yet. Be the first!