FBI Probes ShinyHunters Claim After Recruitment Portal Defacement
FBI investigates ShinyHunters claim of FBIjobs.gov breach, portal defacement and alleged theft of agent data. Scope remains unverified.
Illustrative image generated with AI
The FBI is investigating unauthorized activity involving FBIjobs.gov after the ShinyHunters cybercriminal group claimed it breached the recruitment platform, altered its content and stole sensitive records concerning agents and job applicants.
The claim appeared on September 22, 2026. ShinyHunters replaced FBI imagery with a Pokémon image associated with the group and issued demands through its data-leak site. The recruitment portal was subsequently disrupted, with visitors seeing maintenance messaging or a notice that special-agent applications were unavailable.
That visible compromise establishes that the public-facing service was affected. It does not prove ShinyHunters penetrated the FBI’s internal network, reached human-resources systems or obtained the full dataset it claims to hold.
A Defaced Website and a Much Broader Data-Theft Claim
The FBI has acknowledged the unauthorized activity and opened an investigation. It has not confirmed the origin of the allegedly stolen information, the systems accessed by the attackers or the extent of any data exfiltration.
ShinyHunters claims it extracted between 2 TB and 3 TB of information. The group also alleges that it accessed multiple FBI-related services, including human-resources infrastructure and a system it identified as “Medlink.”
Those assertions remain unverified. No publicly available technical evidence currently demonstrates access to those services or movement from FBIjobs.gov into a wider FBI environment.
The special-agent application portal remained unavailable as of Wednesday morning. The Bureau has not disclosed its containment measures, whether systems were taken offline voluntarily, or whether the interruption was a direct effect of the intrusion.
For now, the incident is best described as an alleged breach of recruitment infrastructure. Calling it a confirmed compromise of the FBI’s internal systems would go beyond the available evidence.
Sample Records Appear Real, but Their Source Is Unresolved
To support its claims, ShinyHunters provided journalists with a sample containing approximately 5,000 records. Some news organizations reportedly confirmed that records in the sample corresponded to genuine FBI personnel.
Reuters also compared portions of the data with credit-bureau information and previously compromised datasets maintained by dark-web intelligence company District 4 Labs. It found apparently corresponding details in at least 10 cases, including information associated with FBI Director Kash Patel. Some listed job descriptions also appeared consistent with the named individuals.
That validation has limits. Matching a name, address or employment detail establishes that a record may describe a real person, but it does not establish where the record was obtained. Information assembled from earlier breaches, commercial databases or other external sources could produce similar matches.
The alleged dataset may contain names, home addresses, telephone numbers, Social Security numbers, assignments and, in some cases, information about family members. These categories come from ShinyHunters’ statements and have not been confirmed by the FBI.
Determining provenance will therefore be central to the investigation. Investigators will need to compare the sample’s structure, metadata and field combinations with records held by recruitment and personnel systems, while checking whether the same information already circulated elsewhere.
PeopleSoft Zero-Day Theory Lacks Technical Confirmation
ShinyHunters reportedly attributed the operation to an unknown vulnerability in Oracle PeopleSoft. According to the group, the flaw allowed remote code execution through infrastructure connected to FBI recruitment services.
There is no public CVE identifier for this alleged zero-day. Oracle has not confirmed its existence, affected PeopleSoft products or versions, exploitation prerequisites, indicators of compromise, or any available patch. The FBI has also not confirmed PeopleSoft as the entry point.
The claim is technically plausible because ShinyHunters has previously been associated with exploitation of PeopleSoft systems. It should not, however, be treated as a verified reconstruction of this incident.
In June, Oracle addressed CVE-2026-35273, a critical unauthenticated remote-code-execution vulnerability in PeopleSoft PeopleTools. It carries a CVSS score of 9.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Google and Mandiant subsequently linked exploitation to ShinyHunters activity, particularly against educational organizations.
CVE-2026-35273 entered the CISA Known Exploited Vulnerabilities catalog on June 12, 2026. Federal agencies received a remediation deadline of June 15, 2026, and the vulnerability is recorded as having been used in ransomware campaigns.
CISA requires affected organizations to apply vendor mitigations while following BOD 26-04 risk-based update guidance and its forensic triage requirements. For cloud services, agencies must follow the applicable BOD 26-04 measures or discontinue use when mitigations are unavailable. Asset owners must also evaluate internet exposure and comply with the directive’s patching rules.
The exact affected versions of PeopleSoft PeopleTools were not disclosed in the available reporting. More importantly, ShinyHunters says the FBI operation used a different, previously unknown vulnerability. Nothing public currently connects CVE-2026-35273 to FBIjobs.gov.
Oracle has had three other vulnerabilities added to the KEV catalog within the last 90 days: CVE-2015-5287 on August 26, 2026; CVE-2026-21962 on August 24, 2026; and CVE-2026-46817 on July 15, 2026. Their presence adds operational context for Oracle customers but does not link them to this incident.
Retaliation, Not Ransom, Is the Stated Motive
ShinyHunters presented the operation as retaliation for FBI public-service announcement PSA260515, issued earlier in 2026 after the group’s attack on Instructure, the company behind the Canvas education platform. That incident disrupted services across thousands of US universities and K-12 schools, and Instructure ultimately paid a ransom to restore operations.
The FBI warning reportedly accused ShinyHunters of overstating theft claims and using coercive tactics against employees connected to victim organizations. The group demanded that the Bureau withdraw or revise the notice, threatening to release information about agents and applicants if it remains available.
ShinyHunters denied swatting corporate personnel, threatening family members by text, claiming possession of embarrassing images or videos, engaging in sextortion, and belonging to The Com.
These denials and demands explain the group’s declared motive; they do not authenticate its breach claims. It is also unknown whether the operation involved ShinyHunters’ core membership, affiliates, individual members or another actor adopting the name.
The episode follows increasingly confrontational activity by the group, including its recent compromise and defacement of Clop’s Tor leak site. The FBI has reportedly focused on ShinyHunters for nearly one year after incidents involving Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line and 7-Eleven.
Personnel and Applicants Face Risks Even Before Attribution Is Settled
If the data originated from FBI systems, the potential harm extends beyond conventional identity fraud. Home addresses, assignments and family details could support harassment, physical targeting, impersonation or carefully tailored social-engineering campaigns.
Information about work roles could also help adversaries identify personnel connected to sensitive investigations. Combined with telephone numbers or family relationships, those details could make fraudulent messages more convincing and increase pressure on targeted individuals.
Publication is not the only risk. Andrew Brandt, an incident responder at Huntress, assessed that a sale to criminal or nation-state buyers could be more dangerous than a public leak. A private buyer could preserve the intelligence value of the records and use them selectively for fraud, surveillance, coercion or follow-on attacks.
These remain risk scenarios, not established consequences. Their likelihood depends on whether the sample came from FBI-controlled systems, how current it is and whether ShinyHunters possesses substantially more data.
Defensive Priorities While the Investigation Continues
Organizations operating PeopleSoft PeopleTools should not wait for confirmation of the FBI’s alleged intrusion before reviewing exposed deployments. They should inventory internet-facing components, inspect authentication and administrative activity, search for unexplained code execution, and examine connected services for lateral movement or persistence.
Systems affected by CVE-2026-35273 require the prescribed Oracle and CISA mitigations. The purported second PeopleSoft flaw must remain classified as unconfirmed until Oracle or another authoritative technical body publishes validation and remediation guidance.
For the FBI, the immediate priorities include establishing the origin of the 5,000-record sample, identifying any exfiltration path, assessing connected recruitment infrastructure and determining whether attackers reached personnel data or other services.
Potentially affected agents, former employees and applicants should be prepared for targeted phishing, impersonation, identity fraud and harassment. Messages referencing real applications, job titles, relatives or addresses should not be considered trustworthy merely because they contain accurate personal details.
Monitoring criminal marketplaces and leak sites will also be necessary. Any release or attempted sale could clarify the dataset’s scope, but it could simultaneously increase the danger to the people named in it.
The investigation has confirmed unauthorized activity against FBIjobs.gov. Everything beyond that—including the alleged zero-day, terabytes of stolen information and access to broader FBI systems—still requires proof.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-21962Critical10.0Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0
- CVE-2026-46817Critical9.8Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful a
- CVE-2026-35273Critical9.8Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleS
- CVE-2015-5287High7.8The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
