Threats & Adversaries · Web App Attack

ShinyHunters Claims FBI Portal Led to GovCloud Data Theft

ShinyHunters claims it used an Oracle PeopleSoft zero-day on the FBI jobs site to get remote code execution, deface the page, and steal 2 TB to 3 TB of employee and applicant data. The group told The Register the campaign is not financially motivated and said it wanted the FBI to retract earlier statements about it.

The claimed path matters more than the banner image: the attackers say one public HR page became a foothold on the server, then a bridge into FBI-managed systems on AWS GovCloud. If that chain is real, a web portal incident can spill into HR, identity, and other connected government data stores instead of stopping at the website itself.

For agencies that run public recruiting or personnel portals tied to internal services, the exposure sits in the connections around the portal as much as in the page itself. The reporting does not confirm the exploit or the theft independently, but it does show how a single web-facing app can become a path into broader federal systems.

3 sources · 2h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-22

Every edition of this story: ShinyHunters Claims FBI Portal Led to GovCloud Data Theft

More from today