2026-09-24 · view entry permalink →
ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI now confirms the compromise itself while still investigating scope
The extortion group ShinyHunters claims it breached the FBI's own recruitment infrastructure using a new, undisclosed remote-code-execution zero-day in Oracle PeopleSoft, often used by human resources and recruiters to store job applicants' personal information (TechCrunch, 2026-09-22). "The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure" (BleepingComputer, 2026-09-22). ShinyHunters claims it stole 2-3TB of data, names, agent statuses, emails, phone numbers, home addresses and in some cases spouses' information including Social Security numbers (Axios, 2026-09-22), spanning current and former FBI employees and job applicants, and that it compromised additional internal services including Criminal Justice, HR and Medlink systems along the way (BleepingComputer, 2026-09-22). The group defaced the FBI's careers site, apply.fbijobs.gov, with its Umbreon Pokémon logo and a message claiming the theft; the FBI took the site offline, and it now shows a maintenance page. The FBI's confirmed response is limited to a single statement: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," (FBI, quoted by BleepingComputer, 2026-09-22); the bureau has not confirmed a breach occurred, its scope, or the claimed PeopleSoft zero-day, and "BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data" (BleepingComputer, 2026-09-22).
404 Media first reported the claim after receiving a sample of roughly 5,000 alleged FBI personnel records; "the publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel" (BleepingComputer, relaying 404 Media, 2026-09-22), which supports that some genuine personnel data changed hands without confirming the exploitation mechanism or the full claimed volume. ShinyHunters' own account of the vulnerability is unusually specific but still entirely self-reported: "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," (ShinyHunters, quoted by BleepingComputer, 2026-09-22) and the group says it is now exploiting the same alleged flaw against other organizations, including Fortune 500 companies, after previously targeting the education sector with a PeopleSoft campaign (BleepingComputer, 2026-09-22). ShinyHunters frames the FBI intrusion as retaliation for a May 2026 FBI/IC3 flash report naming the group, demanding a correction within one week rather than a ransom and claiming the demand is not financially motivated (BleepingComputer, 2026-09-22). The same week, ShinyHunters separately defaced the ransomware group Clop's own Tor leak site over an unrelated dispute, using it to extort Clop directly (BleepingComputer, 2026-09-19); a parallel campaign against a different victim that this entry does not otherwise cover.
The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.
The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,
BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.
The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.
ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.
ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited "NEW unknown vulnerability in the same PSEMHUB component."
The FBI hasn't confirmed the type or amount of data compromised or attributed the breach to ShinyHunters directly. The agency said it is "actively and aggressively investigating" the incident, the root cause and its alleged impact to FBI employees' personally identifiable data in a statement Wednesday.
Limited samples of the stolen data contain FBI agents' personal contact information, details on family members, office and duty assignments and, in some cases, information on agency personnel specialties, multiple sources said.
In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to
Reuters reported Friday that records circulated by the hackers included psychiatric and medical evaluations. The BBC also reported seeing blood and urine test results.
Part of this entry's central open question, whether ShinyHunters' claimed FBI-specific zero-day was real, is now partially resolved. Mandiant/GTIG's report on a separate, wider mass-exploitation wave against the already-known CVE-2026-35273 documents a URL-encoded WAF-bypass technique (requesting /%50SEMHUB/ in place of /PSEMHUB/), and BleepingComputer reports: "ShinyHunters has confirmed to BleepingComputer that they used this WAF bypass against FBI Jobs, but continue to claim that they also exploited "NEW unknown vulnerability in the same PSEMHUB component."" (BleepingComputer, 2026-09-26). At least part of the FBI Jobs intrusion therefore used a known technique against a known CVE rather than the wholly undisclosed zero-day this entry originally reported, though ShinyHunters still claims an additional, still-unconfirmed vulnerability was also involved; the FBI has not updated its own statement and no party has confirmed or denied either technical claim.
Defender takeaway (updated): any organization running Oracle PeopleSoft, not only recruitment or applicant-facing instances, should treat the WAF-bypass technique as active and in use against government targets specifically; a WAF rule blocking the literal /PSEMHUB/ path is not sufficient, since ShinyHunters is confirmed using the URL-encoded /%50SEMHUB/ variant, and Mandiant warns further encoded or mixed-case variants may follow. Patch to a supported PeopleTools release or remove PSEMHUB rather than relying on WAF string-matching alone.
The FBI has now issued its own press release confirming the fbijobs.gov compromise and "alleged impact" to employee personally identifiable information, superseding its prior "aware of claims ... investigating" holding statement: "The FBI hasn't confirmed the type or amount of data compromised or attributed the breach to ShinyHunters directly. The agency said it is 'actively and aggressively investigating' the incident, the root cause and its alleged impact to FBI employees' personally identifiable data in a statement Wednesday" (CyberScoop, 2026-09-28). Nextgov/FCW reports that Reuters found the circulated records included psychiatric and medical evaluations, and that the BBC separately reported seeing blood and urine test results: "Reuters reported Friday that records circulated by the hackers included psychiatric and medical evaluations. The BBC also reported seeing blood and urine test results" (Nextgov/FCW, 2026-09-28). The group separately provided Nextgov/FCW a roughly 5,000-entry sample of names, home addresses, phone numbers and relatives' information, and Nextgov/FCW's own earlier reporting found the exposed data identifies employees working intelligence matters involving Russia, China, Hezbollah and cartels, plus personnel in the Bureau's Remote Operations Unit, which develops tools to target computers and networks (Nextgov/FCW, 2026-09-24). CyberScoop separately reports: "Limited samples of the stolen data contain FBI agents' personal contact information, details on family members, office and duty assignments and, in some cases, information on agency personnel specialties, multiple sources said" (CyberScoop, 2026-09-28). Security researchers Jon DiMaggio (Arkem Cyber) and Cynthia Kaiser (a former FBI official, now at Halcyon) warn the exposure creates counterintelligence and physical-safety risk for agents on sensitive cases, and that data already shared with journalists as proof samples is irretrievably disseminated regardless of any later takedown. ShinyHunters told Nextgov/FCW it will not publish the stolen data: "Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to" (Nextgov/FCW, 2026-09-28), and states the intrusion's motive is coercive rather than financial: it is demanding the FBI retract or amend a May 2026 public advisory (PSA260515) describing the group's operations and tactics, disputes any affiliation with "The Com" cybercrime ecosystem, and denies using sextortion-style threats.
Dutch police separately confirmed, via a statement on X on 2026-09-28, the arrest of a 24-year-old suspect connected to the ShinyHunters investigation; three sources identify him to Krebs on Security as Pepijn van der Stap ("Umbreon"), a previously convicted cybercriminal who volunteered at the Dutch Institute for Vulnerability Disclosure and worked as a software engineer at a Dutch cybersecurity firm. Dutch police are separately asking the public to help identify a voice in a recorded February 2026 call in which a ShinyHunters member social-engineered access into Odido, the country's largest mobile carrier; Krebs states it remains unclear whether police have matched that voice to a confirmed identity, so this entry does not treat the Odido case as resolved or connected to the September arrest. Krebs reports: "In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p" (Krebs on Security, 2026-09-28). Multiple sources cited by Krebs describe a collective calling itself ScatteredLapsussHunters, led by a Jordan-based teenage cybercriminal known as "Rey," as having taken effective control of ShinyHunters' operations and driven its 2026 pivot toward high-risk, non-financially-motivated targets including the FBI and Cl0p; the FBI defacement reused van der Stap's old "Umbreon" artwork, which sources say may have been an attempt to pin the FBI intrusion on the arrested Dutch hacker rather than the group's current operators. CyberScoop separately quotes DiMaggio's independent assessment that "ShinyHunters" today operates as a criminal brand used by a fluid network rather than a single fixed group, corroborating the brand-fragmentation picture without itself confirming the ScatteredLapsussHunters/Rey narrative.
Defender takeaway (updated): treat "ShinyHunters" as a brand a fluid, currently fragmenting network of operators uses, not a fixed group with stable objectives; its current operators have demonstrated willingness to target law-enforcement and national-security-adjacent personnel data specifically, and to pursue coercive, non-financial demands rather than the financially motivated pattern this constituency may have hunted for previously. For a national or cantonal police service or defense IT estate, the transferable lesson is that staff-directory and personnel-system data (contact details, duty assignments, family information) carries a counterintelligence and physical-safety value to this actor class independent of any ransom potential, and should be protected and monitored accordingly.