Skip to main content
Federal Data BreachSecurity Incident· 3 min read· in Technology

Hackers Claim 3TB Breach of FBI Employee Data via HR Software Flaw

The cybercriminal group ShinyHunters alleges it stole three terabytes of sensitive FBI personnel data using a zero-day vulnerability in Oracle's PeopleSoft, though federal officials have not confirmed the breach.

By Tariq Nasser

Cybersecurity Analysts 40%Enterprise Security Vendors 30%Federal Law Enforcement 30%
Cybersecurity Analysts
Focus on verifying the authenticity of the leaked sample and identifying the specific software vulnerability.
Enterprise Security Vendors
Emphasize the systemic risks posed by legacy HR software and the need for stricter access controls.
Federal Law Enforcement
Maintain operational security by refusing to confirm unverified breaches during active investigations.

Perspectives this story doesn't cover

  • Oracle Corporation
  • Federal Employee Unions

The cybercriminal syndicate ShinyHunters claims to have exfiltrated three terabytes of highly sensitive personnel data from the Federal Bureau of Investigation, boasting of a catastrophic breach of federal security. Yet the evidence the group has actually produced amounts to a sample of just 5,000 records, and neither the FBI nor the software vendor involved has confirmed that any intrusion took place.[1][3]

The threat actors assert they bypassed federal defenses using an unpatched zero-day vulnerability in Oracle's PeopleSoft, the human resources platform used by numerous government agencies. According to the group's posts on a dark web forum, the stolen database contains the personal information, medical records, and clearance details of thousands of current and former federal employees.[1][5]

While the scale of the claimed 3-terabyte theft remains unverified, the 5,000-record sample shared by the hackers on September 22, 2026, appears to contain structured HR data. Cybersecurity researchers analyzing the dump noted that the fields match the architecture of a standard PeopleSoft deployment, though it is not yet clear if the data is fresh or aggregated from previous, unrelated breaches.[3]

"If this data is authentic and recent, it represents a significant counterintelligence risk," noted analysts at eSecurity Planet, highlighting that medical and financial records are frequently leveraged for extortion or recruitment by foreign intelligence services. The 5,000-record sample would represent roughly 14 percent of the FBI's estimated 35,000-person workforce if the data proves unique to active personnel.[3]

Cybersecurity researchers are analyzing a 5,000-record sample released by the hackers to determine its authenticity.
The 5,000-record sample would represent roughly 14 percent of the FBI's estimated 35,000-person workforce if the data proves unique to active personnel.

The FBI has maintained a strict silence regarding the incident. When pressed for comment by Security Magazine on September 23, the bureau declined to confirm or deny the breach, adhering to its standard protocol for ongoing cyber investigations. Oracle has similarly not issued any security advisories regarding a new zero-day flaw in its PeopleSoft architecture.[2]

ShinyHunters has a documented history of exaggerating the scope of its compromises to drive up the price of stolen data, but the group also possesses a track record of genuine, high-profile intrusions. In previous campaigns, the syndicate successfully breached major telecommunications and ticketing companies, often exploiting third-party software integrations rather than attacking primary network perimeters directly.[1][5]

The focus on an HR platform underscores a structural vulnerability in enterprise security. Human resources systems require extensive access to sensitive employee data and must frequently interface with external payroll and benefits providers, creating a broad attack surface. "HR systems are a prime target because they aggregate the most sensitive data an organization holds into a single, often legacy, application," researchers at DoControl explained in a September 25 technical brief.[4]

Human resources platforms have increasingly become primary targets for data extortion syndicates.

Legacy software like PeopleSoft, which has been a staple of enterprise and government HR departments for over 20 years, often relies on complex, highly customized deployments. These customizations can make applying security patches difficult and slow, leaving windows of opportunity for threat actors who discover novel exploitation methods before an agency can secure the architecture.[4]

The cybersecurity community is currently monitoring dark web marketplaces to see if the full database is put up for sale or if the initial sample was the entirety of the exfiltrated data. Until the FBI or the Cybersecurity and Infrastructure Security Agency releases a formal incident report, the true extent of the compromise—and the validity of the zero-day claim—remains an open question.[2][3]

Key points

  1. ShinyHunters claims to have stolen three terabytes of FBI personnel and medical data.
  2. The hackers allege they exploited an unpatched zero-day flaw in Oracle's PeopleSoft HR software.
  3. A sample of 5,000 records has been released, but the full scale of the breach remains unverified.
  4. Neither the FBI nor Oracle has officially confirmed the intrusion or the software vulnerability.

Viewpoints in depth

The Threat Intelligence View

Security researchers are treating the breach claims with caution until the data is verified.

Cybersecurity analysts emphasize that ransomware and extortion groups frequently recycle old data or inflate the size of their hauls to generate media panic. While the 5,000-record sample shows structural similarities to genuine PeopleSoft databases, researchers are currently cross-referencing the leaked names and credentials against previous federal breaches. If the data is entirely novel, it would confirm a severe perimeter failure; if it contains heavy overlap with older leaks, the 3-terabyte claim may be a fabrication designed to extort a ransom without a corresponding zero-day exploit.

The Enterprise Risk View

Vendor analysts point to human resources software as a structural weak point in government networks.

Security vendors highlight that legacy HR platforms like PeopleSoft require deep integrations across multiple internal networks to manage payroll, benefits, and clearances. This makes them highly lucrative targets. Because these systems are often heavily customized by government agencies, applying routine security patches can break critical workflows, leading to delayed update cycles. This operational lag creates a window where sophisticated actors can exploit known or zero-day vulnerabilities before the agency can secure the architecture.

Why this matters

If verified, the exposure of federal law enforcement medical records and personnel files represents a severe operational security failure that could expose agents to extortion. It also highlights the systemic risk posed by legacy human resources software managing highly sensitive government data.

Sources

Source coverage

5 outlets

3 viewpoints surfaced

Cybersecurity Analysts 40%Enterprise Security Vendors 30%Federal Law Enforcement 30%
  1. [1]BleepingComputerCybersecurity Analysts

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Read on BleepingComputer →
  2. [2]Security MagazineFederal Law Enforcement

    FBI Hacked, Employee Data Reportedly Exposed

    Read on Security Magazine →
  3. [3]eSecurity PlanetCybersecurity Analysts

    ShinyHunters Claims FBI Breach: 5,000 Records Shared as Evidence

    Read on eSecurity Planet →
  4. [4]DoControlEnterprise Security Vendors

    ShinyHunters FBI Breach: Why HR Systems Are a Security Risk

    Read on DoControl →
  5. [5]Computing UKCybersecurity Analysts

    ShinyHunters claims FBI breach and data theft

    Read on Computing UK →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.