
ShinyHunters Claims Data Breach at FBI Through PeopleSoft Zero-Day
.webp)
The ShinyHunters extortion group claims it carried out a data breach at the FBI using an unknown flaw in Oracle PeopleSoft. The group says it stole 2TB to 3TB of data covering current and former employees, job applicants, and other internal records. The FBI has confirmed it is investigating reported unauthorized activity on its FBIjobs.gov recruitmentportal. However, the bureau has not confirmed that attackers reached its systems or took any information.
ShinyHunters says it exploited the alleged zero-day on Monday night, September 21, to gain remote code execution on an FBI server. From there, the group claims it moved laterally into FBI-managed AWS GovCloud infrastructure holding employee and applicant files. No one has independently verified these technical claims so far.
What ShinyHunters Claims It Took
ShinyHunters says the data breach at the FBI exposed current and former staff, plus every person who applied through the portal. The group also claims it reached the bureau's Criminal Justice, HR, and Medlink services, along with other internal systems. Its statements describe the haul as including both personally identifiable information and protected health information.
The group shared sample records it says belong to FBI personnel. One allegedly relates to Director Kash Patel, and another to a special agent who worked on a past BreachForums investigation. Journalists who received a separate sample of about 5,000 purported employee records confirmed that parts of it matched public records. That sample included names, home addresses, and phone numbers of agents and their spouses.
ShinyHunters also says it briefly defaced the FBI Jobs site with its Umbreon Pokémon logo. A banner on the page claimed the group had seized the site. According to ShinyHunters, the bureau spotted the intrusion quickly, took affected systems offline, and cut its access across several networks at once.
What the FBI Has Confirmed About the Data Breach
The bureau's public position remains narrow. It has acknowledged claims of unauthorized activity affecting FBIjobs.gov and says itis investigating. FBI officials have said nothing about the scope of any data breach or the alleged zero-day.
That gap is worth noting. The FBI's own May 2026 FLASH report warned that actors using the ShinyHunters name may exaggerate their access to pressure victims. The partially verified sample points to some genuine data. Still, it does not prove where that data came from or how the group obtained it.
The FBI Jobs portal remained offline for maintenance a day after the defacement claim surfaced. The bureau has not said when it will return. It has also not said if FBI job applicants should take any steps in response to the claimed data breach.
An Alleged Second PeopleSoft Zero-Day
If investigators confirm the breach at the FBI, the data theft would involve the group's second PeopleSoft zero-day this year. In June, Oracle issued an emergency alert for CVE-2026-35273, a critical flaw in PeopleSoft PeopleTools. The bug allowed unauthenticated remote code execution. Mandiant and Google later confirmed that ShinyHunters exploited it between May 27 and June 9, mainly against universities.
That campaign reached well beyond education. Nissan later disclosed an employee data breach tied to the same flaw. ShinyHunters also claimed access to around 300 PeopleSoft instances across 100 organizations. Oracle released emergency mitigations for the affected PeopleTools versions 8.61 and 8.62.
An Open Question for PeopleSoft Customers
ShinyHunters now says it found a new PeopleSoft vulnerability and used it against the FBI almost immediately. The group claims it is also targeting Fortune 500 companies with the same flaw. It says it tried to scrub traces of the exploit from compromised servers. Neither Oracle nor Mandiant has confirmed a new bug, and no public CVE exists.
A screenshot the group shared shows a page on the FBI Jobs domain under a PSEMHUB path. PSEMHUB is the same Environment Management component that CVE-2026-35273 affected. So the entry point could be a fresh bug in that component. It could also be the older flaw on a system that never received the June mitigations.
Retaliation Rather Than Ransom
The motive sets this incident apart from the group's usual extortion playbook. On its leak site, ShinyHunters framed the attack as retaliation for the FBI's May FLASH report. The bureau issued that report after the group's attack on Instructure's Canvas platform. It warned that actors using the ShinyHunters name have harassed victims and their relatives, sometimes through swatting.
ShinyHunters rejected those allegations. It also denied any link to The Com, a loose cybercrime network that law enforcement ties to data breaches and cryptocurrency theft. The group gave the FBI one week to corrector withdraw the report and insisted the demand carried no financial motive. It declined to say if it would leak data from the alleged breach should the FBI refuse.
The claim also caps a rapid run of provocations. In early September, ShinyHunters claimed a data breach at Florida's DAVID driver database, partly via an alleged FBI agent's account. On September 19, it defaced the leak site of the Clop ransomware gang and threatened to extort its rival.
The Risk to Agents and Applicants
If the FBI confirms the breach and the data proves genuine, the consequences reach well past identity theft. Home addresses and family details of federal agents create a physical safety risk, especially from a group accused of swatting. Applicants face exposure too, because FBI job applications can contain extensive personal histories.
The records also offer fertile ground for social engineering. Attackers could use real names, addresses, and job details to craft convincing phishing messages. Agents, their relatives, and other government staff would all make likely targets. Anyone who has applied for a role at the bureau should treat unexpected contact referencing their application with caution.
What Comes Next
For organizations running PeopleSoft, the practical steps are clear even before Oracle responds. Security teams should confirm the June mitigations for CVE-2026-35273 are in place. They should also restrict internet exposure of PSEMHUB and other administrative endpoints, then review logs for unusual activity on any web-facing HR or recruitment instance.
The FBI investigation will decide how much of the group's account holds up. Until the FBI confirms a data breach, the incident remains a claim backed by partial evidence. But the one-week deadline and the prospect of a second PeopleSoft zero-day make this one of the group's most consequential claims this year.
Subscribe to receive the latest blog posts to your inbox every week.