Hacker News front pageJoseph Cox3 min readintro
'We hacked the FBI:' Hackers say they have data on all FBI employees
Summary
ShinyHunters alleges it breached FBI employee and applicant records by exploiting a zero‑day in Oracle PeopleSoft, stealing 2–3 TB of personal data and defacing the FBI jobs site. The claim is partially corroborated by OSINT checks, and the FBI says it is investigating the incident.
- ShinyHunters claims to have exfiltrated 2–3 TB of FBI employee PII via a zero‑day in Oracle PeopleSoft, accessing AWS GovCloud servers.
- Sample data of ~5 k employees was partially validated using OSINT tools, confirming names, addresses, and phone numbers.
- The group defaced the FBI jobs portal and threatened to release more data, framing it as coercion rather than extortion.
- FBI acknowledges the incident and is investigating; no evidence of ransom payment.
Security teams and incident responders should track this breach as it exposes high‑value PII of law‑enforcement personnel and demonstrates the impact of supply‑chain exploits in enterprise software.
5/10



