ZH version is available. Content is displayed in original English for accuracy.
Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
50% Positive
Analyzed from 2220 words in the discussion.
Trending Topics
#data#oracle#fbi#government#where#security#got#peoplesoft#major#thing

Discussion (90 Comments)Read Original on HackerNews
China hacked 22.1 million records of US government employees:
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
I guess your parking history around town could be valuable if someone is targeting you.
The card number?
In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.
Perhaps firing expertise and hiring incompetents wasn't a good idea.
AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.
It's okay. Larry got another island.
If anything Oracle will "contribute" a lot to congress people's midterm reelection and in a few months all will be forgotten and Oracle will get more Gov. contracts.
If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.
Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.
Hopefully there was some foresight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.
That's lot of data for a list of employees.
Wondering about pets..
Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.
The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".
Almost like its run by a bunch of 80 year olds...
There are many people that run open weight LLMs. And unsurprisingly, they don't all have a copy of the FBI employee database.
If you mean "using" an open weight LLM in combination with other tools or even potentially frontier models, then that's a lot more likely.
Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.
In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.
Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.
All you need to know about Clop is that they got fucked by SH as well just a few days ago.
ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.
Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far.
In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?
If you guessed Oracle PeopleSoft, you were right.
Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.
But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.
https://mesoclever.com/2026/06/11/oracle-wins-396m-hr-contra...
They even mentioned in the above June article:
> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.
So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.
Fookin Big Idiots.
Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.
Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.
They say glowie because they see Jews are n*s who are white. They “glow” (they’re not dark.)
It’s crazy hearing main stream mention this slur slang without awareness of its root or meaning.
https://www.tomshardware.com/tech-industry/artificial-intell...
Just goes to show that the wall of IT bureaucracy does nothing. I'm sure they had an ATO, a several-hundred-page SBOM, compliance audits, etc.
If they did have it set up, then somebody wasn't doing their job. If they didn't have it set up, they didn't comply (which is also not doing their job). I see this all the time. The security analysts send tickets to people when they see major issues and nobody is held accountable for inaction. Management asleep at the wheel (which is also their cover, can't be blamed for what you made sure you never knew about).
There was a time, 25-ish years ago, where exploits were thrown about like candy at a parade. The procedures you mention, along with other things, have made zero-days like these more valuable than gold.
Still skeptical, but the FBI's vendors are just as vulnerable to 0-days as Hertz's vendors.