ShinyHunters claims FBI breach exposed up to three terabytes of data
The criminal group ShinyHunters claims to have breached the FBI's systems and stolen between 2 and 3 terabytes of employee data, but states the hack is not financially motivated. Instead, the group says it carried out the operation to force the FBI to retract previous statements characterising ShinyHunters as a harassment-focused extortion group that uses threatening messages, phone calls, and swatting tactics. The group disputes these allegations and wants the record corrected.
According to ShinyHunters, the breach exploited a zero-day vulnerability in Oracle PeopleSoft on the FBI's jobs portal, which allowed remote code execution and access to FBI servers hosted on Amazon's GovCloud platform. The stolen data reportedly includes information on current, former, and prospective FBI employees across human resources, MedLink, and Criminal Justice Information Services. The group defaced the FBI jobs webpage with a seizure banner before the site went down for maintenance. Neither Oracle, Amazon, nor the FBI has yet publicly responded to confirm the claims.
- ShinyHunters claims FBI hack to force retraction of harassment allegations, not for ransom
- Group says it stole 2–3 TB of employee data via Oracle PeopleSoft zero-day exploit
- FBI and vendors have not confirmed the breach or verified ShinyHunters' claims
Read the full article at the source →
Originally published by The Register as “ShinyHunters claims FBI hack: ‘This is NOT financially motivated’”.