Skip to content
theregister·

🚨ShinyHunters Claims FBI Hack, 2TB of Data Stolen

FBI jobs site hacked, 2TB of employee data stolen

TL;DR

ShinyHunters claims to have hacked the FBI, stealing over 2TB of employee data. The hack used an Oracle PeopleSoft zero-day vulnerability, compromising HR, MedLink, and CJIS services. No ransom demands, just a message correcting the FBI's record on ShinyHunters.

ShinyHunters claims to have hacked the FBI, stealing over 2TB of employee data. The hack used an Oracle PeopleSoft zero-day vulnerability, allowing remote code execution and lateral movement onto AWS GovCloud-managed servers. The compromised services include HR, MedLink, and CJIS. This hack isn't about money; ShinyHunters aims to correct the FBI's record on their group's actions. If you're dealing with sensitive data, this is a stark reminder of the risks. The hack highlights the importance of patching known vulnerabilities and securing cloud environments.

ShinyHunters Claims FBI Hack, 2TB of Data Stolen — theregister

Key Points

1

ShinyHunters claims to have stolen over 2TB of employee data from the FBI.

2

The hack used an Oracle PeopleSoft zero-day vulnerability for remote code execution.

3

Compromised services include HR, MedLink, and Criminal Justice Information Services.

4

The FBI's bulletin on ShinyHunters claims harassment and false information.

5

ShinyHunters denies the allegations and aims to correct the FBI's record.

Why It Matters

If you're dealing with sensitive data, this hack is a wake-up call. The FBI's compromised systems highlight the risks of unpatched vulnerabilities and cloud security. Security teams need to prioritize patching known issues and securing cloud environments to prevent similar breaches.

FBIShinyHuntersOracle PeopleSoftzero-dayAWS GovCloud

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,488 builders reading daily.