Field Notes / Breach Analysis
A Crew Claims It Took Terabytes From the FBI Through PeopleSoft. There Is No CVE to Scan For.
ShinyHunters says it used an unpatched Oracle PeopleSoft flaw to reach FBI systems, deface the bureau’s jobs portal and take 2 to 3 terabytes. The FBI says it is investigating and has confirmed nothing. Whatever the truth of the claim, one detail should move your week: no CVE has been published, so your vulnerability scanner will mark every PeopleSoft server you run as clean tomorrow morning.
What is claimed, and what is confirmed
On Monday night, by its own account, the extortion crew ShinyHunters got into an internet-facing Oracle PeopleSoft instance. From there it says it reached FBI Criminal Justice services, HR, Medlink and others, then into AWS GovCloud. It put its logo on apply.fbijobs.gov above the line THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS, and it says the same flaw is now being turned on Fortune 500 companies BleepingComputer .
The FBI's statement runs to one sentence. It is aware of claims regarding unauthorised activity affecting FBIjobs.gov, and it is investigating. No confirmation of a breach. No confirmation of theft.
Two reporters have touched the data. BleepingComputer received two sample records and did not verify them. 404 Media received around 5,000 purported employee records and found that some of the phone numbers matched real Department of Justice personnel. That is a long way from 3 terabytes, and it is a long way from nothing.
Hold both thoughts. The theft may be smaller than advertised. The technique is real enough that a jobs portal belonging to the FBI carried a Pokémon logo for an afternoon, and three days earlier the same crew defaced the Clop ransomware gang's own leak site BleepingComputer, 19 Sep 2026 . People who can do that to Clop can do it to a university payroll server.
Why your scanner says you are fine
Cyber Essentials has the same boundary, and it is worth being precise about it because certified organisations will be asked. The standard requires vendor-supported software to be patched within 14 days of a fix for a high or critical issue Cyber Essentials v3.3 . That clock cannot start before Oracle ships a patch. An organisation can hold a valid certificate, pass its annual scan, and be compromised on the same afternoon through a flaw with no fix. The certificate is not wrong. It certifies what it says it certifies.
The applicant database is the crown jewel nobody guards
Note which system carried the defacement. Not a case management platform. The recruitment portal.
Every organisation that hires holds a database of people who wanted to work there. National insurance numbers. Home addresses. Dates of birth. Right-to-work documents, often scanned passports. Referees, which means the names and contact details of people at other organisations entirely. Salary history. For a public body, security clearance status.
Most of those people never became employees. They applied once, four years ago, and have no relationship with the organisation now. They are not in the business continuity plan, and the system holding them is rarely in the scope document when a penetration test gets commissioned, because it does not process payments and it does not touch the product. Under UK GDPR the ICO makes no such distinction ICO breach guidance .
The chain matters more than the flaw
Strip the claim back to its shape and it is the pattern behind most serious intrusions we see. An internet-facing enterprise application. A flaw in it. Then the interesting part: the application holds credentials, trusts an identity provider, and assumes a cloud role. The flaw gets you the server. The trust relationships get you everything the server is allowed to touch. ShinyHunters says that second step took it from a PeopleSoft box into GovCloud.
Mandiant's incident responders keep describing the same arc from over 500,000 hours of response work M-Trends 2026 . The initial flaw is rarely what makes an incident expensive. What makes it expensive is what the compromised system was permitted to reach, and how little anyone had thought about that before the alert fired.
A scan grades each host on its own. It has no view of what the host can reach next, which is the only thing that determines whether a single bad afternoon becomes a reportable incident.
What to check this week
If you run PeopleSoft, or you manage it for clients, four things are worth doing before Oracle publishes anything.
Find every instance, including the ones nobody owns. Test and pre-production servers stood up for a migration, never decommissioned, still listening. In our engagements the forgotten instance is reachable more often than the production one, because production went behind the VPN in 2023 and the copy did not.
Take it off the internet if it does not need to be there. A self-service HR portal used by staff can sit behind your access proxy. An applicant-facing careers page usually cannot, which tells you where to spend the attention.
Read 30 days of authentication logs. Successful logins from addresses you do not recognise. Administrative accounts created outside your change process. Bulk record exports at hours when nobody was working.
Map the blast radius. Write down what that server trusts and what trusts it: the directory, the cloud role, the databases it queries, the integrations pushing data in and out. If you cannot write it on one page, an attacker who lands there will discover it faster than you can reconstruct it.
The question a scan cannot answer
By the time Oracle publishes an advisory, the organisations that were going to be hit through this flaw will already have been hit. That is what a zero-day is. The window is not the time between the patch and your patching. It is the time before anybody knows there is something to patch.
What closes that window is not a faster scan. It is knowing, before the news breaks, which of your systems face the internet, which hold regulated personal data, and what each one is permitted to reach if somebody lands on it. We answer that question by attacking the estate the way a crew like this one does, and by handing you the path, the evidence and the fix. Every finding is re-tested for twelve months, so the proof you give your board or your client does not go stale the week after it is written.
Start with the free audit: what an attacker can see of your estate from the outside, including the instance you forgot you had.
References
Sources
- BleepingComputer. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach. 22 September 2026. bleepingcomputer.com
- BleepingComputer. ShinyHunters hacks Clop leak site, threatens to extort ransomware gang. 19 September 2026. bleepingcomputer.com
- NCSC. Vulnerability management guidance: how to assess and prioritise. ncsc.gov.uk
- NCSC / IASME. Cyber Essentials: Requirements for IT Infrastructure v3.3, April 2026. ncsc.gov.uk
- Information Commissioner’s Office. Personal data breaches: a guide. ico.org.uk
- Mandiant. M-Trends 2026, drawn from over 500,000 hours of incident response in 2025. cloud.google.com