Update: Added the FBI's statement below.

"The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.

The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

ShinyHunters claims it stole between 2TB and 3TB of data from the agency, including information on current and former FBI employees, job applicants, and other internal records.

The group also claims it compromised FBI Criminal Justice, HR, Medlink, and additional services during the intrusion.

ShinyHunters further claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies.

BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data. . ."