ShinyHunters Claims FBI Hack Exploiting Oracle Flaw
The cybercrime group says it breached FBI systems using a critical Oracle software vulnerability. The FBI is investigating the claim.

Key points
- ShinyHunters claims it accessed FBI criminal justice and HR systems, stealing data, including personal details on thousands of agents.
- The group reportedly exploited CVE-2026-35273, a critical flaw in Oracle PeopleSoft Enterprise PeopleTools.
- CISA added this flaw to its active-exploitation watchlist on June 12, with a patch deadline for federal agencies set three days later.
- The FBI confirmed it is investigating but hasn't verified any of ShinyHunters' claims.
ShinyHunters defaced a subdomain of the FBI's jobs website, fbijobs.gov, posting the message "This site has been seized by ShinyHunters." Soon after, the page was taken down for maintenance. The group shared a sample with 404 Media, first reporting the leak, which allegedly includes names, phone numbers, and home addresses of about 5,000 FBI employees. Reporters reviewing the sample said some data appeared genuine, though the origin is unverified.
The FBI's statement was concise: it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
How did the hackers claim to get in?
ShinyHunters told 404 Media it exploited a zero-day, a software flaw not yet patched by the maker, inside Oracle PeopleSoft Enterprise PeopleTools, used widely for managing HR in large organisations.
That vulnerability is now public and catalogued as CVE-2026-35273. It is severe, requiring no password to exploit. A successful attack grants full control of the affected system.
| Detail | Value |
|---|---|
| CVE ID | CVE-2026-35273 |
| Severity score | 9 / 10 (Critical) |
| Affected versions | Not specified |
| Published | 2026-06-11 |
| Added to CISA watchlist | 2026-06-12 |
CISA added this flaw to its Known Exploited Vulnerabilities catalogue on June 12, giving federal agencies three days to patch. It's unclear if the FBI had patched before the breach occurred.
The cybersecurity community noted ShinyHunters using similar PeopleSoft flaws against other targets in June. Whether the FBI attack used the same vulnerability or a different one remains uncertain. Attribution from criminals alone isn't the same as technical confirmation.
Why is ShinyHunters doing this now?
ShinyHunters claims it's responding to an FBI FLASH report from May that they say contained false statements about their tactics. The group denied claims that they exaggerate access to pressure victims, use harassment like swatting, or threaten victims' families, demanding a retraction.
This framing should be viewed skeptically. ShinyHunters has a long record of large-scale data theft. We've reported on ShinyHunters hitting Oracle PeopleSoft vulnerabilities in our 26 September story. Their criminal claims, though unverified, suggest a group operating at scale.
If you work for a federal agency or a large organisation using Oracle PeopleSoft, confirm your IT team has applied the patch. If not, that's the conversation to have this week.



