ShinyHunters claims it breached FBI systems through a new Oracle PeopleSoft zero-day with remote code execution. BleepingComputer reports the group says it gained access Monday night, then moved laterally into FBI-managed AWS GovCloud. The claimed haul is 2 to 3 TB, including current and former employees and applicants, plus Criminal Justice, HR, and Medlink data. That is what the group says. It is not what independent reporters have verified end to end.

BleepingComputer has not independently verified the zero-day, the lateral movement, or the stolen volume. The FBI said it is aware of claims about unauthorized activity affecting FBIjobs.gov and is investigating. It did not confirm a breach or data theft. The group shared a screenshot of a defaced apply.fbijobs.gov page with an Umbreon logo. The site later showed a maintenance page. Treat the defacement screenshot as evidence something happened on that surface, not as proof of every claimed terabyte.

404 Media first reported the story after a sample of about 5,000 purported employee records, and verified that some of the information was accurate. ShinyHunters claims the same alleged zero-day is now used against Fortune 500 targets, frames the campaign as retaliation for a May 2026 FBI FLASH report, gave the FBI one week to correct or remove that report, and declined to say whether data would be released. None of that confirms the FBI lost 2 to 3 TB via PeopleSoft. It confirms a loud claim with some partial corroboration on records and a jobs portal incident under investigation.

For developers and IT teams, the useful takeaway is boring and important. PeopleSoft and similar HR or applicant portals are high-value targets because they sit next to identity data and sometimes cloud admin paths. Patch and monitor Oracle PeopleSoft aggressively when zero-day claims hit the news, even before every detail is proven. Watch FBIjobs.gov-style applicant flows for defacement and odd maintenance windows. Do not invent a confirmed FBI breach from a group claim and a portal screenshot.

I care about claims versus verified facts because security news moves faster than evidence. ShinyHunters made a serious allegation. 404 Media checked some records. The FBI is investigating FBIjobs.gov claims and has not confirmed theft. Until more is verified, plan as if PeopleSoft is under active attack interest, and keep your language precise.