ShinyHunters Defaces FBI Jobs Site, Claims 2TB of Employee Data Stolen in PeopleSoft Attack
ShinyHunters defaced the FBI's jobs site and says it stole over 2TB of personnel data using an Oracle PeopleSoft zero-day. The group says it wants no ransom, only a retraction of the FBI's May bulletin; the bureau has not commented.
The defaced page carried the group's ASCII logo and a message reading "This site has been seized by ShinyHunters. Rooting your systems since '19 :)". The FBI's jobs site has since been reclaimed, and an investigation into the breach claims is ongoing.
ShinyHunters told The Register that it found a zero-day vulnerability in Oracle's PeopleSoft human resource management system that allowed it to remotely execute arbitrary code on the underlying server. The group said it used that access to obtain names, addresses, phone numbers and information on spouses of current, former and prospective FBI employees, and that it had compromised human resources systems, MedLink and the Criminal Justice Information Services. A spokesperson told The Register the group holds data on "all FBI employees and applicants."
The FBI has not commented on the claims. Oracle and Amazon Web Services, which hosts the bureau's site, have also remained silent.
What sets the incident apart from ShinyHunters' previous campaigns is the stated motive. The group has historically broken into corporate networks, stolen files and pressed victims to pay for deletion of the data. This time, it says the objective is to force the FBI to change its account of how the group operates.
"This is NOT financially motivated," the group told The Register. "We want the FBI to correct or retract their statements they made, which included substantial false allegations." ShinyHunters added: "I have been doing my very best to combat these allegations. And this is the best way to do it."
Those statements were made in a public service announcement the FBI published on May 15, shortly after the attack on Canvas. In early May, Instructure, the education technology company behind the learning platform, confirmed it had suffered a cyberattack and lost sensitive customer data. Harvard, Oxford and MIT were later identified among the victims, and Instructure's chief executive was called to testify before the US House Committee on Homeland Security weeks later.
The FBI's bulletin said ShinyHunters "commonly use harassment strategies" to pressure victims, including "sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting." It added that the group may falsely claim to hold compromising material such as embarrassing photographs or videos, and that it has sometimes posted exfiltrated data to iterations of its leak site on the Tor network.
Not everyone accepts the group's denial of financial intent. Denis Calderone, chief technology officer of Suzu Labs, said in a statement to TechRadar Pro that the claims should be treated with scepticism. "I have a hard time believing terabytes of FBI personnel data just sit on a shelf," he said. "Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data." He added that agents and their spouses could have their home addresses posted publicly within a week if the threat is carried out.
Calderone said the more consequential issue is the vulnerability itself. "If you run PeopleSoft, don't wait for a patch. Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren't reachable from outside," he said. He also advised administrators to hunt for June indicators and for SSH attempts against psoft and oracle accounts, and to assess what their applicant portals can reach.