Update: Added the FBI's statement below.

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.

The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.

The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion.

ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies.

BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

The FBI confirmed to BleepingComputer that it is investigating the claims but did not confirm whether its systems were breached or data was stolen.

"The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," the FBI told BleepingComputer.

The group also claims it tried to erase evidence of its activity from compromised servers to make the zero-day harder to identify.

ShinyHunters also told BleepingComputer that it is now using the same alleged PeopleSoft vulnerability to target corporations and the Fortune 500 after targeting the education sector.

ShinyHunters claims the stolen FBI data came from systems accessed following the initial PeopleSoft compromise.

These systems allegedly include the FBI's AWS GovCloud environment, which was used to store employee and applicant information.

BleepingComputer has contacted Oracle and Google Cloud's Mandiant threat intelligence team to determine whether they are aware of a new PeopleSoft vulnerability or related exploitation activity. . ."