2026-09-24 · view entry permalink →
ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI confirms only that it is investigating
The extortion group ShinyHunters claims it breached the FBI's own recruitment infrastructure using a new, undisclosed remote-code-execution zero-day in Oracle PeopleSoft, often used by human resources and recruiters to store job applicants' personal information (TechCrunch, 2026-09-22). "The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure" (BleepingComputer, 2026-09-22). ShinyHunters claims it stole 2-3TB of data, names, agent statuses, emails, phone numbers, home addresses and in some cases spouses' information including Social Security numbers (Axios, 2026-09-22), spanning current and former FBI employees and job applicants, and that it compromised additional internal services including Criminal Justice, HR and Medlink systems along the way (BleepingComputer, 2026-09-22). The group defaced the FBI's careers site, apply.fbijobs.gov, with its Umbreon Pokémon logo and a message claiming the theft; the FBI took the site offline, and it now shows a maintenance page. The FBI's confirmed response is limited to a single statement: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," (FBI, quoted by BleepingComputer, 2026-09-22); the bureau has not confirmed a breach occurred, its scope, or the claimed PeopleSoft zero-day, and "BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data" (BleepingComputer, 2026-09-22).
404 Media first reported the claim after receiving a sample of roughly 5,000 alleged FBI personnel records; "the publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel" (BleepingComputer, relaying 404 Media, 2026-09-22), which supports that some genuine personnel data changed hands without confirming the exploitation mechanism or the full claimed volume. ShinyHunters' own account of the vulnerability is unusually specific but still entirely self-reported: "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," (ShinyHunters, quoted by BleepingComputer, 2026-09-22) and the group says it is now exploiting the same alleged flaw against other organizations, including Fortune 500 companies, after previously targeting the education sector with a PeopleSoft campaign (BleepingComputer, 2026-09-22). ShinyHunters frames the FBI intrusion as retaliation for a May 2026 FBI/IC3 flash report naming the group, demanding a correction within one week rather than a ransom and claiming the demand is not financially motivated (BleepingComputer, 2026-09-22). The same week, ShinyHunters separately defaced the ransomware group Clop's own Tor leak site over an unrelated dispute, using it to extort Clop directly (BleepingComputer, 2026-09-19); a parallel campaign against a different victim that this entry does not otherwise cover.
The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.
The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,
BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.
The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.
ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.