CTIPilot
← Back to the live brief
HIGHNATOB3incident

ShinyHunters claims a breach of the FBI's own recruitment infrastructure via an unconfirmed Oracle PeopleSoft zero-day; the FBI confirms only that it is investigating

A serial extortion actor claims it rooted the FBI through an undisclosed Oracle PeopleSoft flaw and pivoted into an AWS-hosted government data store

Defender actions

  • Watch Oracle's own security-alert channel for an emergency PeopleSoft advisory in the coming days; any organization running an internet-facing PeopleSoft component, especially a recruitment or HR/jobs-portal instance matching the FBI's own claimed entry point, should treat unexplained PeopleSoft process activity or unusual outbound connections as a priority hunt lead until Oracle confirms or denies the claim.

Analysis

The extortion group ShinyHunters claims it breached the FBI's own recruitment infrastructure using a new, undisclosed remote-code-execution zero-day in Oracle PeopleSoft, often used by human resources and recruiters to store job applicants' personal information (TechCrunch, 2026-09-22). "The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure" (BleepingComputer, 2026-09-22). ShinyHunters claims it stole 2-3TB of data, names, agent statuses, emails, phone numbers, home addresses and in some cases spouses' information including Social Security numbers (Axios, 2026-09-22), spanning current and former FBI employees and job applicants, and that it compromised additional internal services including Criminal Justice, HR and Medlink systems along the way (BleepingComputer, 2026-09-22). The group defaced the FBI's careers site, apply.fbijobs.gov, with its Umbreon Pokémon logo and a message claiming the theft; the FBI took the site offline, and it now shows a maintenance page. The FBI's confirmed response is limited to a single statement: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," (FBI, quoted by BleepingComputer, 2026-09-22); the bureau has not confirmed a breach occurred, its scope, or the claimed PeopleSoft zero-day, and "BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data" (BleepingComputer, 2026-09-22).

404 Media first reported the claim after receiving a sample of roughly 5,000 alleged FBI personnel records; "the publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel" (BleepingComputer, relaying 404 Media, 2026-09-22), which supports that some genuine personnel data changed hands without confirming the exploitation mechanism or the full claimed volume. ShinyHunters' own account of the vulnerability is unusually specific but still entirely self-reported: "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI," (ShinyHunters, quoted by BleepingComputer, 2026-09-22) and the group says it is now exploiting the same alleged flaw against other organizations, including Fortune 500 companies, after previously targeting the education sector with a PeopleSoft campaign (BleepingComputer, 2026-09-22). ShinyHunters frames the FBI intrusion as retaliation for a May 2026 FBI/IC3 flash report naming the group, demanding a correction within one week rather than a ransom and claiming the demand is not financially motivated (BleepingComputer, 2026-09-22). The same week, ShinyHunters separately defaced the ransomware group Clop's own Tor leak site over an unrelated dispute, using it to extort Clop directly (BleepingComputer, 2026-09-19); a parallel campaign against a different victim that this entry does not otherwise cover.

Cited evidence

The threat actors told BleepingComputer the vulnerability allows remote code execution and that they used it Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure.

BleepingComputer 2026-09-22

The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,

FBI, quoted by BleepingComputer

BleepingComputer has not independently verified the alleged zero-day, lateral movement, or amount of stolen data.

BleepingComputer 2026-09-22

The publication said it verified that some information in the sample was accurate, including phone numbers corresponding to people with the same names and numbers associated with US Department of Justice personnel.

BleepingComputer, relaying 404 Media's own verification

ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.

Axios 2026-09-22

Sources7

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.