IC Technology & Cyber — 2026-10-07

FBI Confirms ShinyHunters Data Breach as Arrests in Jordan and Netherlands Follow Theft of Employee Personnel Files via PeopleSoft Zero-Day

BLUFOracle is likely to publish a security advisory for the PeopleSoft flaw by November 30, but until then every PeopleSoft customer faces an unpatched vulnerability the arrests did nothing to neutralize.

The FBI confirmed the breach of its FBIJobs.gov portal in an internal notice to employees, which acknowledged that some employees' personal information was stolen, according to a New York Times report relayed by CBS News ShinyHunters FBI hack" data-source="CBS News" data-url="https://cbsnews.com/news/dutch-arrest-shinyhunters-fbi-hack" data-rt="secondary" data-mbfc="high" data-otype="broadcaster">1. ShinyHunters claimed it took two to three terabytes of data using a new Oracle PeopleSoft vulnerability, though Oracle has not commented and no CVE has been assigned 12. Dutch police arrested a 24-year-old Amsterdam man on September 15, and a Rotterdam court ordered him held 90 days 3. CBS sources identified him as Pepijn van der Stap, and he is also suspected of soliciting two murders 1. Reuters reported, per CSO Online, that a suspected member was later arrested in Jordan and is cooperating with investigators 2.

Analysis
Oracle is likely to publish a security advisory or CVE for the claimed PeopleSoft flaw by November 30. We have high confidence in this judgment because the FBI has confirmed the breach and enterprise analysts are pressing for disclosure, though the zero-day claim rests solely on ShinyHunters. Independent sourcing is thin, since most items trace to CBS, AP, or a single CSO relay of Reuters, but the accounts agree on the arrests and the confirmation. The Jordanian suspect's cooperation moves the case past the Dutch arrest and could give investigators the vulnerability details Oracle needs. The arrests do not remove exposure, because the exploit and stolen data remain with the group. Oracle may issue no separate advisory if the group reused the June flaw, CVE-2026-35273, in modified form. If Oracle publishes, administrators patch and hunt for web shells against a defined flaw. If not, they must keep Environment Management Hub and Integration Broker off the public internet and treat exposure as unresolved.
4 sources
  1. Dutch arrest ShinyHunters FBI hack - CBS News
  2. Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks - CSO Online
  3. Dutch police arrest a suspected ShinyHunters member; court orders 90-day detention - ABC News (AP)
  4. Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE