Skip to content
Security

FBI Investigates ShinyHunters Claim of a PeopleSoft Zero-Day

The bureau said on 22 September 2026 that it is looking into unauthorised activity affecting FBIjobs.gov. The extortion group says it took two to three terabytes and wants a May FBI bulletin withdrawn, not a ransom.

By
· Updated 3 min read
inLinkedIn𝕏Post
FBI Headquarters - J. Edgar Hoover Building
FBI Headquarters - J. Edgar Hoover Building · ajay_suresh · CC BY 2.0 · via Wikimedia Commons

The FBI said on 22 September 2026 that it is investigating claims of unauthorised activity affecting FBIjobs.gov, the bureau's recruitment portal, after the extortion group ShinyHunters said it had stolen data on current, former and prospective employees. "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," the bureau told BleepingComputer. It did not confirm that any system was breached or that any data was taken.

ShinyHunters told both BleepingComputer and The Register that it got in through a previously unknown remote code execution flaw in Oracle PeopleSoft, the human resources software behind the jobs site, and used it on the night of Monday 21 September. The group says it then moved laterally into FBI-managed infrastructure on Amazon Web Services GovCloud and downloaded between two and three terabytes, covering human resources records, the MedLink health system and Criminal Justice Information Services.

What has actually been verified

404 Media reported the claim first, after receiving a sample of roughly 5,000 records. The publication said it checked part of that sample and found phone numbers matching people of the same name, including numbers associated with US Department of Justice personnel. BleepingComputer said on 22 September that it had not independently verified the zero-day, the lateral movement or the volume of data, and that it was not publishing the two sample records the group supplied. Both outlets published screenshots provided by ShinyHunters showing apply.fbijobs.gov defaced with the line "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)". The portal now returns a maintenance message.

A demand for a retraction, not a payment

The group is not asking for money. It says the attack answers an FBI FLASH bulletin published in May 2026, shortly after ShinyHunters claimed a breach of the education platform Instructure Canvas, which said the group sends threatening messages to victims and their family members, carries out swatting, and sometimes falsely claims to hold compromising material. ShinyHunters denies all of it, rejects the FBI's description of it as part of the cybercrime community known as The Com, and has given the bureau one week to correct or remove the document.

We want the FBI to correct or retract their statements they made, which included substantial false allegations.

ShinyHunters spokesperson, Speaking to The Register, 22 September 2026

Asked by BleepingComputer whether the data would be published if the FBI did not act, the group answered: "No comment." Asked whether the attack would bring heavier pressure from the US government, its main representative said: "I don't care."

Oracle has published nothing

Oracle's security alerts page listed no PeopleSoft advisory as of 23 September 2026, and the company's next scheduled Critical Patch Update falls on 20 October 2026, which would leave any such flaw unpatched for four weeks. Oracle, Amazon Web Services and Google Cloud's Mandiant had not answered questions from BleepingComputer or The Register when those reports were published. ShinyHunters says it is already turning the same flaw on other organisations, including Fortune 500 companies, a claim no vendor or incident responder has corroborated.

The honest reading is that the defacement is the only element visibly confirmed, and a defaced recruitment page demonstrates access to a web server, not to GovCloud. The group's track record cuts both ways. Oracle confirmed in 2025 that a proof-of-concept exploit leaked by an allied crew matched the one used in the Clop campaign against Oracle E-Business Suite, and ShinyHunters later said that exploit had been its own. It also has an obvious motive to inflate the scale here, because the bigger the claim, the more pressure the FBI feels to answer it. What is not known is whether the bureau's investigation has found any movement beyond the recruitment portal.

It would be the second reported intrusion into an FBI system this year. TechCrunch reported on 22 September that unidentified hackers previously broke into a system used to manage real-time wiretaps and foreign intelligence warrants, and that FBI director Kash Patel's personal email account was hacked and leaked by Handala, a group TechCrunch describes as Iran-backed.

What happens next?

  • The FBI's investigation will determine whether the intrusion reached beyond FBIjobs.gov into AWS GovCloud, and whether any notification to affected employees and applicants follows.
  • Oracle either issues an out-of-cycle PeopleSoft alert or waits for its 20 October 2026 Critical Patch Update, which would confirm or undercut the zero-day claim.
  • ShinyHunters has set a one-week deadline for the FBI to retract its May 2026 FLASH bulletin, expiring around 29 September 2026.
  • CISA would be expected to add any confirmed PeopleSoft flaw to its Known Exploited Vulnerabilities catalogue with a federal patching deadline.

Sources & references

  1. 01ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachBleepingComputernews22 September 2026. Carries the FBI's on-record statement confirming it is investigating.
  2. 02ShinyHunters claims FBI hack: 'This is NOT financially motivated'The Registernews22 September 2026. Source of the quoted spokesperson statement and the FLASH bulletin demand.
  3. 03Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' dataTechCrunchnews22 September 2026. Summarises 404 Media's partial verification and prior FBI intrusions.
  4. 04Critical Patch Updates, Security Alerts and BulletinsOracleprimaryChecked 23 September 2026. No PeopleSoft security alert listed; next Critical Patch Update scheduled for 20 October 2026.
Published 23 September 2026 · Updated 23 September 2026 · Report a correction · How we use AI
inLinkedIn𝕏Post

More from Security

View all
Security

Spain Logs Its First Data Breach Carried Out by an AI Agent

On 14 September 2026 the Spanish Data Protection Agency (AEPD) disclosed the first breach notification it has received in which an AI agent allegedly carried out several stages of the attack. The agency has not named the model or the organisation and says the report is still under review.

3 min read
Security

A Pixel Modem Zero-Day and a Citrix Bypass Top This Week's Exploited Flaws

Google's September 2026 Pixel bulletin fixes CVE-2026-58704, a modem permission bypass Google says may be under limited, targeted exploitation, among 110 flaws. CISA added Citrix NetScaler CVE-2026-19490 to its Known Exploited Vulnerabilities catalogue on 9 September with a 12 September deadline, after exploitation attempts began around 3 September following a public proof of concept. Cisco Talos attributes active exploitation of two Secure Firewall Management Center flaws to Sandworm and Qilin ransomware operators.

3 min read
Security/ Explainer

What Actually Took Effect Under the EU AI Act

Regulation (EU) 2026/1744, in force from 27 July 2026, pushed the AI Act's Annex III high-risk obligations to 2 December 2027 and embedded-product rules to 2 August 2028. From 2 August 2026 the AI Office and national authorities enforce transparency duties with fines up to €15 million or 3% of turnover, and new bans on non-consensual intimate imagery apply from 2 December 2026.

6 min read
Security/ Explainer

OWASP Ranked AI Risks Against Real Incidents, and Agency Jumped

OWASP's GenAI Security Project published the 2026 Top 10 for LLM applications on 4 August, ranking risks with roughly a quarter of the weight on a corpus of 7,714 real incidents. Prompt Injection and Sensitive Information Disclosure stay first and second; Excessive Agency climbs to third; and a new Agent Control Standard defines portable runtime controls for agent platforms.

6 min read