ShinyHunters claims it used an Oracle PeopleSoft zero-day to hack FBI-related services and steal employee and applicant data; it also defaced the FBI jobs site
A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.
404 MediaJoseph Cox
Context & Ripple Effects
ShinyHunters had already built a public profile around alleged mass-data theft: researchers described the group in 2020 as offering what it said were roughly 200 million records, while a 2024 claim involving EPAM Systems was denied. The FBI also seized BreachForums domains tied to ShinyHunters’ alleged leak-extortion activity in 2025.
The group’s new allegations combine an alleged enterprise-software zero-day, personnel data, and a public-facing site defacement. That raises the stakes beyond a disputed database claim: the reported sample, examined by 404 Media, contains information that could expose DOJ personnel and their families to targeted abuse.
First-order effects
The FBI must establish whether its PeopleSoft-connected services were accessed and whether employee and applicant records require notification or protective measures; the intrusion and data-theft claims remain unconfirmed.
Oracle faces pressure to assess the alleged PeopleSoft zero-day and provide affected customers with guidance if the claimed exploit is validated.
Second-order effects
Organizations using PeopleSoft, particularly those holding workforce or applicant records, will have to review internet-facing instances, access logs, and identity data exposure rather than treat the allegation as an FBI-only incident.
The alleged disclosure of home addresses, phone numbers, and spouse details makes personnel-data repositories a more consequential target: victims face phishing, impersonation, and physical-security risks alongside conventional fraud.
Third-order effects
If the zero-day claim is substantiated, the episode would reinforce that legacy enterprise applications are a shared-risk layer across public-sector and large-employer identity systems, concentrating remediation demands on vendors and their customers.
The pairing of an alleged leak with a visible defacement points toward intrusion campaigns that use public proof to amplify pressure, rather than relying only on private extortion channels such as those previously associated with ShinyHunters.
The trend: Alleged data-theft campaigns are increasingly using public demonstrations and sensitive workforce data to turn a software-security failure into immediate institutional pressure.
‼️ ShinyHunters has shared a message on their pay or leak portal to Director Brett Leatherman of the FBI Cyber Division and Director Kash Patel of the FBI:
I have dug into some of the sample with open source info and previously compromised data. It shows people in this FBI breach are U.S DOJ personnel https://www.404media.co/...
New: hackers say they have data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk https://www.404media.co/...
If I were the FBI, I would not use a static page with animals on it the week after the whole “beastiality is not disqualifying anymore” debate got such attention. — I fear for those poor doggos... [embedded post]
“We're sniffing out site updates for you!” is definitely one way to say “we were hacked and thousands of FBI agents and applicants had their information stolen.” — Those federal puppers are fucking adorable though. https://www.404media.co/... [image]