Overnight on 21-22 September 2026, the FBI's recruitment portal at apply.fbijobs.gov was defaced with a banner reading "This site has been seized by ShinyHunters." Within hours the group was telling reporters it had used a new Oracle PeopleSoft zero-day to get in, moved from there into FBI servers on AWS GovCloud, and walked out with 2-3 TB of data on "almost ALL FBI Agents" and everyone who has applied for a job there.
That is a very large claim, and most of it currently rests on the word of the people making it. The FBI has confirmed it is investigating "unauthorized activity affecting FBIjobs.gov". It has not confirmed a breach of its internal systems, and neither Oracle nor AWS has commented.
Below: what ShinyHunters is claiming, which parts have actually been verified, why the group says it did this, how seriously to take it, and what anyone running PeopleSoft should do now rather than after the facts settle.
What ShinyHunters claims#
Speaking to BleepingComputer, The Register and 404 Media, the group described the attack in four steps:
- Initial access through an unpatched Oracle PeopleSoft vulnerability on the FBI jobs portal, giving remote code execution.
- Lateral movement from that server into FBI infrastructure hosted on AWS GovCloud.
- Data theft of 2-3 TB, allegedly covering Criminal Justice, HR and "Medlink" services, including names, home addresses and phone numbers of agents and their spouses.
- Defacement of the jobs site as proof of access.
It also set a one-week deadline before it says it will release data, and, unusually for this group, said it wants no money at all.
What has actually been verified#
| Claim | Status | Basis |
|---|---|---|
| The FBI is investigating an incident | Confirmed | FBI statement to multiple outlets |
| The jobs portal went offline | Confirmed | apply.fbijobs.gov and the Special Agent application portal showed maintenance pages |
| The site was defaced | Plausible, not confirmed | Only the group's own screenshot |
| Some of the leaked records are real | Partly confirmed | 404 Media matched phone numbers in a ~5,000-record sample to named people, some of them DOJ staff |
| Entry via a new PeopleSoft zero-day | Unverified | No CVE, exploit detail or advisory published |
| Lateral movement into AWS GovCloud | Unverified | No evidence shown |
| 2-3 TB covering "almost all" agents | Unverified | Only the sample has been checked |
Two things are easy to lose in the coverage.
A real sample does not prove the scope. 404 Media's checks show the records it received relate to real people. They do not show those records came from FBI systems rather than an earlier breach or a data broker, and they say nothing about the other 99% of the claimed haul.
The FBI's wording is careful. Its later statement said it is "actively and aggressively investigating" and working "closely with those third-party providers", which points at the portal's hosting and software supply chain rather than the bureau's core network. That may change as the investigation continues, but for now there is no official confirmation that anything beyond the recruitment portal was touched.
Why they say they did it#
This part is well documented. On 15 May 2026 the FBI's Internet Crime Complaint Center published PSA260515, a public warning issued after ShinyHunters' attack on Instructure's Canvas learning platform disrupted schools and universities across the US. The bulletin described the group as specialising in large-scale data theft and extortion, and said it uses harassment and threats to pressure victims into paying.
ShinyHunters' demand is that the FBI retract that bulletin. The group posted a counter-"PSA" on its leak site addressed to FBI leadership, disputing the harassment allegations and denying any link to "The Com", the loose criminal network the bureau has tied it to. Its line to The Register: "This is NOT financially motivated."
Retaliation against the agency that named you is a strange strategy for a group whose business depends on staying out of handcuffs. Cynthia Kaiser of Halcyon, quoted by CyberScoop, called it the kind of "lack of discipline that historically has led to takedowns." Flashpoint's analysts made the opposite point: whatever happens next, the stunt bolsters the group's reputation as a credible threat to every future extortion victim.
How seriously to take ShinyHunters#
Seriously, but not literally.
The group has a long record of real, large breaches: Tokopedia and Microsoft's private GitHub repositories in 2020, the AT&T data in 2021, Ticketmaster and Santander through stolen Snowflake credentials in 2024, the Salesforce voice-phishing campaign in 2025, and the Canvas breach this May. Several members have been arrested and convicted, and the brand has kept operating anyway.
It also has a record of inflated numbers, and the name is now worn by more than one crew. In 2025 and again in 2026 the group's own leadership disowned breaches that others had claimed in its name. "ShinyHunters says" is evidence that something happened, not a measurement of how much.
The detail that makes this claim more credible than most is the method. In June, Google's threat intelligence team tied ShinyHunters to mass exploitation of CVE-2026-35273, a critical (CVSS 9.8) unauthenticated remote code execution flaw in PeopleSoft's Environment Management Hub. It was exploited as a zero-day between 27 May and 9 June, before Oracle's out-of-band alert on 10 June, and more than 100 organisations were notified, roughly two-thirds of them universities. After getting in, the attackers mapped the environment, sprayed SSH credentials at internal hosts and exfiltrated data.
So the group has broken into PeopleSoft at scale before, using exactly the kind of foothold it describes here. Whether the FBI incident used a genuinely new flaw or an unpatched instance of the June one is not known yet. For defenders, that distinction matters less than it sounds.
What PeopleSoft admins should do now#
Do not wait for Oracle to confirm or deny a new zero-day. If the June campaign is any guide, the exposed surface is the same.
1) Confirm you are patched for CVE-2026-35273#
PeopleTools 8.61 and 8.62 were named as affected, with older unsupported versions likely vulnerable too. Apply Oracle's June security alert fix and verify it, rather than assuming it went out with the last patch cycle.
2) Take the management endpoints off the internet#
Block external access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the perimeter. Disable the Environment Management Hub service in multi-server setups, or remove the PSEMHUB application on single-server installs. Almost nobody needs these reachable from the public internet, and a candidate-facing jobs portal certainly does not.
3) Hunt, do not just patch#
Look for unexpected .jsp files under the PSEMHUB.war directory, recently modified XML under envmetadata, external POST requests to the endpoints above in your WebLogic logs, and outbound SMB (TCP 445) to unknown addresses. A patched server that was compromised in June is still compromised.
4) Assume the web tier is a door, not a wall#
The claimed pivot from a jobs portal into cloud infrastructure is the pattern that turns an embarrassing defacement into a real breach. Internet-facing HR and recruitment systems should sit in their own segment, with their own credentials and no standing trust into the rest of the estate. Shared service accounts and reused SSH passwords are what the June attackers sprayed for. It is the same lesson we keep returning to in what actually breaks company security: the breach is rarely the first server, it is everything that server was allowed to reach.
If you work at the FBI or ever applied to it#
Nothing has been published yet, and it may never be. But the data claimed (names, home addresses, phone numbers, applicant records) is exactly what powers targeted scams, so the sensible response is cheap and worth doing now.
- Treat any message that mentions your application as suspect. Follow-up "background check", "application status" or "security clearance" contacts are the obvious lure. Verify through a number you look up yourself, never one in the message. Our anatomy of a scam text covers the patterns.
- Set a carrier PIN and a port-out freeze. A leaked phone number plus a home address is enough to attempt a SIM swap, which is how SMS codes get stolen.
- Freeze your credit with Equifax, Experian and TransUnion. It is free in the US and blocks new accounts being opened in your name.
- Move important accounts to passkeys where offered. A phishing site cannot capture a passkey the way it captures a password and a one-time code; our password guide walks through the switch.
What to watch next#
The claim will be settled by one of three things: an Oracle security alert or new CVE for PeopleSoft, a fuller FBI statement on what was accessed, or ShinyHunters publishing data when its deadline passes. Any of them will tell us far more than the current round of screenshots. We will update this post when one arrives.
Summary#
- Confirmed: the FBI is investigating an incident on its jobs portal, the portal went offline, and some records in a leaked sample belong to real people.
- Unverified: the new zero-day, the move into AWS GovCloud, and the 2-3 TB "almost all agents" scope.
- Motive: retaliation for the FBI's May 2026 bulletin about the Canvas attack; the group says it wants a retraction, not money.
- Credibility: ShinyHunters has a real record of large breaches and a real record of inflated claims. Its June PeopleSoft campaign makes the method plausible.
- PeopleSoft admins: patch CVE-2026-35273, block
/PSEMHUB/*and/PSIGW/HttpListeningConnectorexternally, and hunt for signs of earlier compromise. - Anyone exposed: expect targeted phishing, set a carrier PIN, freeze your credit, and prefer passkeys.
Running PeopleSoft or another internet-facing HR system and not sure what an attacker could reach from it? Get in touch - the bluwarden team can review your exposure, segmentation and incident response before you need them. See what our services cover.
This post reflects public reporting as of 24 September 2026. The investigation is ongoing and details may change.
