ShinyHunters claims it breached the Federal Bureau of Investigation and stole more than 2 terabytes of employee data, saying its goal is to force the FBI to retract what it calls false allegations made in a May 15 bulletin rather than extract a ransom payment.

The group said it exploited an Oracle PeopleSoft zero-day vulnerability on the FBI's jobs webpage to achieve remote code execution on the servers and gain initial access. It then defaced the jobs site with a banner reading "This site has been seized by ShinyHunters" before moving laterally to FBI managed servers hosted on AWS GovCloud to download the data.

ShinyHunters claims the stolen data includes information on current, former and prospective FBI employees from human resources, MedLink and Criminal Justice Information Services systems.

"This is NOT financially motivated," a group spokesperson said, adding that it seeks for the FBI to "correct or retract their statements they made, which included substantial false allegations."

The May 15 bulletin ShinyHunters references was issued shortly after the group's alleged breach of ed-tech platform Instructure's Canvas. In that alert, the FBI characterized ShinyHunters as using "harassment strategies," including threatening text messages, phone calls and swatting. The warning also noted that extortionists "may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist."

ShinyHunters denies those characterizations. A spokesperson said, "I have been doing my very best to combat these allegations. And this is the best way to do it."

The FBI did not immediately respond to requests for comment. Neither Oracle nor AWS provided immediate responses to inquiries about the claimed zero-day or alleged data theft.