ShinyHunters defaced the FBI job application portal on 22 September and says an unpatched Oracle PeopleSoft flaw was the way in. The Bureau has confirmed only that it is investigating claims of unauthorized activity affecting fbijobs.gov.
- What is established. The recruitment portal was defaced, the Bureau is investigating, and 404 Media verified part of a 5,000 record sample against public records.
- What is only claimed. The zero day, the two to three terabytes, records on almost every agent, and the move into an AWS GovCloud environment all come from the attackers.
- Why patching would not have helped. A zero day has no patch when it is used, and Oracle needed two weeks to answer the group’s June PeopleSoft flaw.
- What would have. Blocking the PSEMHUB and PSIGW endpoints at the perimeter, segmenting the web tier from HR and justice systems, watching egress, and monitoring for new binaries in the deployment directory.
- Who else is exposed. The same group hit over 100 organizations in June, 68 percent of them universities, and says it is moving on to larger enterprises.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
