TTO-2026-0922-151 · September 22, 2026 Data BreachThreat Actor

ShinyHunters Claims FBI Network Breach via Oracle PeopleSoft Zero-Day and Threatens to Publish Stolen Data

oracle.comShinyHuntersFBI network breach claimOracle PeopleSoft zero-day allegedStolen data threatened for publicationFBI and DOJ have not confirmedClaim unverified by independent third party

Summary

ShinyHunters has publicly claimed to have breached FBI network infrastructure via a zero-day vulnerability in Oracle PeopleSoft, the human resources and enterprise management platform used by numerous U.S. federal agencies. The group alleges it obtained internal FBI data including personnel records, case management information, and network configuration details, and is threatening to publish the stolen data unless its demands are met. The FBI and Department of Justice have not confirmed the breach. Oracle has not confirmed a PeopleSoft zero-day vulnerability. The claim has not been independently verified by a security research organization as of this writing.

Timeline

DateEvent
Sep 21-22, 2026ShinyHunters publicly claims FBI network breach via Oracle PeopleSoft zero-day; threatens to publish stolen data; BleepingComputer reports
Sep 22, 2026FBI and DOJ have not confirmed breach; Oracle has not confirmed PeopleSoft zero-day; claim unverified by independent third party as of TTO publication

What Happened

ShinyHunters has posted a claim alleging it compromised FBI network infrastructure by exploiting a previously unknown vulnerability in Oracle PeopleSoft, the enterprise resource planning platform widely deployed across U.S. federal agencies for human resources, payroll, and workforce management. Oracle PeopleSoft is a high-value target in federal environments: it processes personnel records, benefits data, and organizational information for agencies that include law enforcement and intelligence community components.

The key facts that would establish the claim are not yet available: neither the FBI nor DOJ has confirmed a breach, Oracle has not confirmed the existence of a PeopleSoft zero-day CVE, and no independent security organization has verified the stolen data sample or the intrusion method. ShinyHunters’ prior campaigns — including the verified Ticketmaster breach, AT&T data theft, and the Clop leak site claim from September 19 — demonstrate a genuine capability to execute large intrusions. The verification gap between ShinyHunters’ announcements and confirmed facts has historically closed within days to weeks. TTO will update this bulletin when authoritative confirmation or refutation is available.

Domain Intelligence

oracle.com — 62.46

oracle.com scores in the low-trust range at 62.46. Oracle is the vendor of PeopleSoft, the platform alleged to contain the zero-day used in this claimed intrusion. Oracle has not confirmed a PeopleSoft zero-day vulnerability as of this publication.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026