ShinyHunters Says It Breached FBI Recruitment Systems and Took 2-3 Terabytes of Personnel Data; FBI Says It Is Investigating FBIjobs.gov
The cybercrime group says it used an undisclosed Oracle PeopleSoft flaw to reach FBI personnel records and shared a sample Reuters partly matched against other data; the FBI has confirmed only that it is looking into unauthorized activity on its jobs site.
A Fake Seizure Notice, a Data Sample, and a One-Sentence Denial
Late Monday night, someone changed the look of a single web page. Visitors to apply.fbijobs.gov, the FBI's online job portal, found a banner reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS," stamped with the group's cartoon fox logo[5][7]. By Tuesday, the story had grown far past a defaced webpage. The cybercrime group ShinyHunters told several news outlets it hadn't just vandalized a page — it said it had slipped through an unknown flaw in Oracle's PeopleSoft software, moved into FBI-run servers on Amazon's cloud, and walked away with 2 to 3 terabytes of personnel records[1][2][5][6].
The FBI's response to all of this fits in one sentence: it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating"[4][5]. It has not confirmed that any data was stolen. It has not confirmed that hackers reached internal systems. It has not confirmed the PeopleSoft flaw exists at all[1][5]. What's verified and what's merely claimed sit on two very different levels, and that gap is the real story here.
What a Sample File Can and Can't Prove
ShinyHunters handed reporters a sample it says covers 5,000 FBI employees — names, home addresses, phone numbers, and spouse information[1][2]. Reuters did something none of the other outlets could: it checked. Reporters ran names, addresses, and Social Security numbers from the sample against credit-bureau records and against older breached data held by a dark-web intelligence firm called District 4 Labs[2][3].
In at least nine cases, the details lined up with real people, including — Reuters found — information matching FBI Director Kash Patel[2][3]. That is a genuine result. It tells you the sample isn't made up out of thin air; those are real addresses tied to real names.
What it does not tell you is where the data came from. Reuters was explicit on this point: it could not establish whether the information was pulled from FBI systems, or whether it originated somewhere else entirely, like one of the many older data leaks already circulating online[2][3]. Matching a real address proves the address is real. It doesn't prove which database it was copied from.
The Software at the Center, and Why It's a Soft Target
The claimed break-in point is Oracle PeopleSoft, human-resources software that runs hiring, payroll, and employee records for large organizations, including many federal agencies and universities[1][5]. By its nature, a job-application system has to be reachable from the open internet — otherwise applicants couldn't use it. That also means it's a soft target: it holds sensitive data like Social Security numbers, but it doesn't always get patched as fast as an agency's more central computer systems[13][14].
This isn't ShinyHunters' first run at PeopleSoft. In June 2026, the group exploited a real, confirmed flaw in the software — CVE-2026-35273, a security hole rated 9.8 out of 10 for severity that let attackers break in without even logging in[12][13]. Oracle rushed out a fix on June 10, and the U.S. government's cybersecurity agency, CISA, added the flaw to its official list of exploited vulnerabilities on June 12[12][14]. Google's security division, Mandiant, tied that campaign to more than 100 organizations, about 68% of them colleges and universities[13][14].
That earlier flaw is now patched. It's not the one in question here. ShinyHunters says the FBI intrusion used a second, still-undisclosed PeopleSoft flaw — a distinct claim that Oracle and Amazon have not confirmed[5]. Conflating the two would be a mistake: one is a documented fact, the other is an open question.
Why Everyone Involved Has a Reason to Shape the Story This Way
Four parties are effectively narrating this event, and only one of them — ShinyHunters — is actually talking in detail. That imbalance matters. Federal incident response runs on forensic timelines measured in weeks; attackers can publish their version within hours. That mismatch means the accused party's account dominates the first news cycle almost by default, regardless of how accurate it turns out to be[4][5][6].
ShinyHunters says the attack is "NOT financially motivated" and wants the FBI to retract a bulletin it issued in May 2026 describing the group's tactics and urging victims not to pay ransoms[6][8]. That's a real, stated grievance. It's also true that publicity itself has value for an extortion-adjacent group even without a ransom demand — a credible claim against the FBI raises the group's standing and could pressure future victims to pay faster[6][8]. Both things can be true at once: a stated grievance and a reputational payoff.
The FBI's caution serves a different, also legitimate purpose. Confirming details before forensics are finished risks spreading information that turns out to be wrong, and it also hands the attacker a map of what investigators do and don't know[4][5]. Taking the recruitment portals offline — which the bureau has done — is the kind of containment step agencies take first and explain later[5]. Oracle and Amazon, for their part, have industry-standard reasons to stay quiet on an unconfirmed zero-day: announcing a flaw with no fix ready would just be a target list for other attackers[5][12].
Whose Safety Is Actually on the Line
The people with the most at stake in this story aren't in the negotiation at all. If ShinyHunters' claims hold up, the people exposed are FBI employees, applicants, and their families — whose home addresses and spouse information the group says it holds[1][2]. For agents who work undercover or on organized-crime and terrorism cases, a leaked home address isn't an inconvenience. It's a safety risk[1][2].
Applicants are a separate group worth naming. Someone who applied for an FBI job years ago and was never hired may have submitted extensive background paperwork without any current relationship to the bureau that would prompt a notification if something went wrong. Reuters' partial matches mean that, at minimum, some real people's information is circulating somewhere — even though where it came from is still unresolved[2][3].
How the Coverage Split Along the Way
Outlets covered this event through very different lenses. Reuters, which did the only independent verification in the whole story, kept the claim inside careful "say they" language and put the FBI's silence in its own headline[3]. Axios followed a similar path, keeping the theft framed as a claim under investigation rather than a settled fact[4].
Others leaned harder into the group's own framing. The Washington Times used the word "massive" — the hackers' own scale estimate — as the headline's defining word[9]. 404 Media led with the quote "We Hacked the FBI" and the phrase "All FBI Employees," the maximal version of a claim nobody has confirmed[9]. RedState went further, describing the sample file as something that helped "back up" the breach claim, treating evidence supplied by the accused party as if it settled the matter[9].
International outlets like CBC and Australia's ABC ran the story straighter off the wire, framing the U.S. government as the target of a global criminal network rather than folding it into domestic political arguments[10][11]. What's still missing from the record, more than a day after the defacement, is any confirmation — from the FBI, from Oracle, or from Amazon — of what actually happened beneath the surface of that one altered web page.
Summary
On Monday night, September 21, 2026, someone defaced apply.fbijobs.gov, the FBI's online job-application portal. The page carried a fake seizure notice reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS" and the group's Umbreon Pokémon logo[5][7]. The cybercrime group ShinyHunters then told reporters it had used an undisclosed flaw in Oracle PeopleSoft software to get in, moved from there into FBI-managed servers on Amazon's AWS GovCloud, and downloaded between 2 and 3 terabytes of records on current, former and prospective FBI employees[1][5]. The FBI's full public response is one sentence: it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov" and is investigating[4][5]. It has not confirmed that any data was stolen, that internal systems were reached, or that a PeopleSoft flaw was used[1][5].
The gap between claim and confirmation is the whole story. ShinyHunters gave reporters a sample it said held personal data on 5,000 FBI employees — names, home addresses, phone numbers and spouse information[1][2]. Reuters ran some of those names, addresses and Social Security numbers against credit-bureau records and against older breached data held by the dark-web intelligence firm District 4 Labs. In at least nine cases the details matched, including, Reuters reported, records for FBI Director Kash Patel[2][3]. But Reuters said plainly that it could not establish where the data came from, or whether it was taken from FBI systems at all[2][3]. Matching a real person's real address does not prove which database it came out of.
The group says this is not a shakedown. ShinyHunters told The Register the attack is "NOT financially motivated" and says it wants the FBI to retract a bulletin the bureau issued in May 2026 describing the group's tactics and urging victims not to pay[6][8]. Security researchers note the group has a track record: in June 2026 ShinyHunters exploited a real PeopleSoft hole, CVE-2026-35273, against more than 100 organizations before Oracle patched it[12][13]. The group says the FBI intrusion used a different, still-unpatched flaw. Oracle and Amazon have not confirmed that[5].
The genuine dispute is about scope, not about whether something happened. Something clearly happened to a public-facing FBI website. Whether that reached actual FBI personnel systems — the difference between an embarrassing web defacement and a serious counterintelligence problem — is unresolved and rests, so far, on the word of the people who say they did it.
The Event
Late on Monday, September 21, 2026, the FBI's job-application site at apply.fbijobs.gov displayed a counterfeit seizure notice attributed to the cybercrime group ShinyHunters, along with the group's Umbreon logo[5][7]. On Tuesday, September 22, ShinyHunters posted a statement on its dark-web leak site and spoke with Reuters, BleepingComputer, TechCrunch and The Register, claiming it had exploited an undisclosed Oracle PeopleSoft vulnerability, moved into FBI-managed AWS GovCloud infrastructure, and taken 2 to 3 terabytes of data on employees and applicants[1][2][5][6]. The group supplied a sample it described as covering 5,000 FBI employees[1][2]. The FBI said it is aware of claims of unauthorized activity affecting FBIjobs.gov and is investigating; its recruitment portals were taken offline[4][5].
Undisputed Facts
- A page at apply.fbijobs.gov was defaced on the night of Monday, September 21, 2026, with a fake seizure banner naming ShinyHunters[5][7].
- The FBI's on-the-record statement is that it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating"[4][5].
- FBI recruitment portals were taken offline after the defacement[5].
- ShinyHunters claims it took between 2 and 3 terabytes of data covering current, former and prospective employees, and says it reached FBI Criminal Justice, HR and Medlink services plus AWS GovCloud[1][5].
- ShinyHunters gave reporters a sample it said contained personal data on 5,000 FBI employees, including names, home addresses, phone numbers and spouse information[1][2].
- Reuters matched details from that sample — names, postal addresses and Social Security numbers — against credit-bureau records and previously breached data held by District 4 Labs, and found matches in at least nine cases, but said it could not establish where the data came from or whether it was taken from FBI systems[2][3].
- ShinyHunters says it is not seeking an extortion payment and wants the FBI to retract a May 2026 bulletin describing its tactics[6][8].
- A separate Oracle PeopleSoft flaw, CVE-2026-35273, rated 9.8 and allowing remote code execution without a login, was exploited by ShinyHunters between May 27 and June 9, 2026, patched by Oracle on June 10 and added to CISA's Known Exploited Vulnerabilities catalog on June 12[12][13][14].
- Oracle, Amazon Web Services and the FBI have not confirmed ShinyHunters' technical account of the FBI intrusion[1][5].
The Pressure
Strip away the moralizing and blame. What structural realities persist regardless of which narrative wins?
- Agencies confirm late, attackers publish early
- Federal incident response runs on forensics timelines measured in weeks. Attackers publish in hours. That asymmetry guarantees that the attacker's version dominates the first news cycle regardless of how accurate it turns out to be — here, the FBI's entire public record is one sentence against thousands of words of hacker interviews[4][5][6].
- Publicity is the product, even without a ransom
- Declining to demand money does not make an extortion group non-commercial. Reputation is what sets future victims' willingness to pay. A claimed FBI breach is the most valuable advertising such a group can buy, which is itself a reason to expect the claim to be stated at its maximum[6][8].
- HR software is soft, internet-facing infrastructure
- PeopleSoft is the back-office HR and applicant system for large governments and universities. It must be reachable from the open internet so applicants can use it, it holds Social Security numbers and home addresses, and it is often patched on a slower cycle than mission-critical systems. That combination is why the same group hit more than 100 organizations, about 68% of them colleges, in a single June campaign[13][14].
- Vendors cannot confirm a zero-day before they can fix it
- A 'zero-day' is a flaw with no patch available. Publicly confirming one hands a working target to every other attacker in the window before a fix ships. So vendor silence in the first days is the expected behavior, not evidence either way about whether the flaw is real[5][12].
Material realityOne thing is documented: a public-facing FBI web page was defaced, and the bureau's recruitment portals went offline[5][7]. Everything beyond that surface — lateral movement into AWS GovCloud, 2 to 3 terabytes taken, records on Criminal Justice, HR and Medlink systems — rests on the attacker's account and has been confirmed by no government agency or vendor[1][5]. Reuters' checking cuts both ways: matching names, addresses and Social Security numbers in at least nine records against credit-bureau and prior-breach data shows the sample is not fabricated, but the same check cannot show the data came from the FBI rather than from older breaches already in circulation[2][3]. The underlying software risk is real and independently established: CVE-2026-35273 was a genuine unauthenticated remote-code-execution flaw in PeopleSoft, exploited as a zero-day from May 27 to June 9, 2026, patched June 10 and listed by CISA on June 12[12][14]. Whether a second, unpatched PeopleSoft flaw exists is the open technical question, and it matters far beyond the FBI: the same software runs payroll and hiring for hundreds of government bodies and schools.
Narrative as a weaponThree parties are shaping what you read, and only one of them is talking. ShinyHunters wants you to believe it penetrated the deepest FBI personnel systems, that it did so for principle rather than money, and that the bureau's advisories about it are worthless — all three claims serve its standing in criminal markets. The FBI wants the story to stay sized to a jobs website until forensics are done, which is both sound incident practice and convenient. Oracle and Amazon want the zero-day claim treated as unproven, which is standard vendor procedure and also their commercial interest. Downstream, U.S. partisan outlets are borrowing the story for an argument about federal competence that predates it, while the technical press is putting an unverified exploit in headlines because the exploit is the interesting part. The sentence that should anchor any reader's judgment is Reuters' own: it matched some records, and it could not establish where they came from.
How Each Side Sees It
Each major actor’s view — how it frames things, its underlying incentive, and how it’s materially affected. Tap a side to read it.
Frames it asThe bureau's position is procedural and deliberately narrow: it will say what it can verify and nothing more[4]. Confirming a hacker's claim before forensics are done rewards the attacker and can spread false information — the group has an obvious interest in making the breach sound worse than it is. There is also an operational argument: publicly mapping exactly which systems were touched tells the intruder what the bureau knows and what it missed. Taking the recruitment portals offline is the containment step you take first and explain later[5].
WhyContain the incident, avoid confirming anything that turns out to be wrong, and protect personnel whose home addresses and family details may be exposed[1][2]. Politically, the bureau under Director Kash Patel is under sustained scrutiny, and a confirmed breach of agent records is the kind of story that outlives the news cycle[3].
Impact on themIf the personnel claims hold, the cost is not money but safety: agents who work undercover or on organized-crime and terrorism cases would have home addresses and spouse details in criminal hands[1][2]. Reuters reported that Patel's own records appeared among the matched entries[3]. Recruitment is also disrupted while the portals stay down[5].
Frames it asThe group's stated case is that this is retaliation, not robbery. It says it is "NOT financially motivated" and demands the FBI withdraw a May 2026 bulletin that described its methods and told victims not to pay[6][8]. Its implicit argument to the security world is a competence claim: the same agency that publishes advisories telling others how to defend themselves was running an unpatched, internet-facing PeopleSoft instance. The group also points to a track record it says makes it credible — it demonstrably did exploit a PeopleSoft zero-day against more than 100 organizations in June 2026 before Oracle had a fix[12][13].
WhyReputation and leverage. Publicity is the currency of extortion groups even when no ransom is named; a credible FBI scalp raises the price every future victim expects to pay, and pressures the bureau to soften how it describes the group in advisories[6][8]. Members of the collective have faced arrests and a BreachForums seizure in late 2025, giving the group reason to project that it is undiminished[15].
Impact on themCriminal exposure rises sharply — attacking a federal law-enforcement agency invites a level of investigative effort that a university breach does not[13]. Against that, the group gains standing in criminal markets. Note that everything in this entry is the group's own account, unverified by any government or vendor[1][5].
Frames it asBoth companies' position is that an attacker's description of a vulnerability is not a vulnerability report. Oracle patched CVE-2026-35273 out of band on June 10, 2026, within about two weeks of the first known exploitation — a fast turnaround for enterprise software[12][14]. The vendors' broader argument is that a hosted-software flaw only becomes a breach when a customer leaves a system exposed and unpatched, and that responsibility for configuration and patch timing sits with the operator. Neither has validated ShinyHunters' account of a new, unpatched flaw[5].
WhyAvoid confirming an unpatched zero-day before they have one to fix — saying "yes, there is a new hole" without a patch hands every other attacker a target list. Commercially, PeopleSoft is core HR software for governments and universities, and a second zero-day in four months is a serious sales problem[13].
Impact on themDirect: if a new flaw is confirmed, Oracle faces an emergency patch cycle across thousands of government and education customers[13][14]. AWS GovCloud is the U.S. government's compliance-hardened cloud region, so any claim that an attacker moved into it laterally is significant for federal cloud policy even if it is ultimately disproven[1][5].
Frames it asThe affected people are not a party to the dispute but bear the risk. Their argument is that the burden of proof runs the other way: when addresses and Social Security numbers are already circulating, waiting for confirmation before issuing warnings costs them time they cannot get back. Applicants are a distinct group — people who applied for FBI jobs and were never hired may have submitted extensive background information without any ongoing relationship to the agency that would prompt a notification.
WhyPrompt, specific notice of what was exposed, and credit and identity protection — the standard remedy after a federal data loss.
Impact on themReuters' partial matches mean at least some real people's details are in circulation somewhere, even though the source of that data is unestablished[2][3]. For agents in covert or high-risk assignments, exposure of a home address is a physical-safety issue rather than a financial one[1].
Like this article?
The Bias Ledger average rating 3.9
The same story, as framed by outlets across the spectrum, ordered least to most biased. The bias score (1 = straight, 10 = heavily spun) is an AI assessment of that framing — click an outlet to see its track record. The tell is the word choice or omission that reveals the angle.
| Outlet | Vantage | Bias | How they frame it | The tell |
|---|---|---|---|---|
| Reuters | U.S./U.K. wire service, center | 1 | "ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate comment from FBI" — the claim is kept inside a "say they" verb, and the absence of FBI comment is in the headline. | Reuters did the only independent verification work in the story and then published its own limits: it could not establish where the data came from. That caveat is the least-spun sentence in the whole news cycle, and most aggregators dropped it. |
| Axios | U.S. center-left | 2 | "FBI investigating claims that a major cybercrime group stole sensitive personnel data" — the FBI's investigation is the subject; the theft stays a claim. | Structurally the most cautious U.S. framing, and closest to what the record supports. The trade-off is that it passes over the group's stated demand — retraction of the May bulletin — which is the one detail that explains why this target was chosen. |
| BleepingComputer | U.S. technical trade press | 3 | "ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach" — states the exploit route in the headline while hedging with "claims." | Deepest technical sourcing, but it puts the unverified zero-day in the headline as though it were established. The distinction between this alleged new flaw and the confirmed, already-patched CVE-2026-35273 sits well below the fold. |
| The Register | U.K. technical trade press | 4 | "ShinyHunters claims FBI hack: 'This is NOT financially motivated'" — foregrounds the group's self-description. | Putting the hackers' motive claim in quotation marks in the headline gives an extortion crew free space to define its own story. The claim is newsworthy; leading with it lets the group's framing set the terms of the coverage. |
| The Washington Times | U.S. right | 5 | "Hacker group ShinyHunters claims massive breach of FBI employee data" — "massive" carries the weight. | "Massive" is the hackers' own scale estimate promoted into the headline as description. The FBI's much narrower statement — that it is investigating activity on a jobs website — appears lower down, so the headline sizes the event by the attacker's account. |
| 404 Media | U.S. left-leaning independent tech | 5 | "'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees" — leads with the hackers' quote and the word "All." | Quoting the boast in the headline technically attributes it, but the quote does the framing work, and "All FBI Employees" is the maximal version of an unconfirmed claim. The subhead hedging does not travel to social shares. |
| RedState (Opinion) | U.S. right, opinion | 7 | "'We Hacked the FBI': ShinyHunters Hands Over 5,000 Employee Records to Back Up Stunning Breach Claim" — "to Back Up" presents the sample as corroboration. | A sample supplied by the accused party is treated as evidence that settles the question. Reuters' finding was nine partial matches of unknown origin, not confirmation of 5,000 stolen FBI records — the headline collapses that distance. |
References
- Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data — TechCrunch · U.S. technology trade press, center-left; owned by Regent LP
- ShinyHunters hackers say they breached FBI, stole data on bureau employees — CNBC · U.S. business news, center; carrying Reuters reporting
- ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate comment from FBI — Reuters · International wire service, center; owned by Thomson Reuters
- FBI investigating claims that a major cybercrime group stole sensitive personnel data — Axios · U.S. center-left digital news; owned by Cox Enterprises
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach — BleepingComputer · U.S. independent security trade publication; ad- and subscription-funded
- ShinyHunters claims FBI hack: 'This is NOT financially motivated' — The Register · U.K. technology trade press, skeptical house style; ad-funded
- ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day — CyberInsider · Independent security news site; commercially funded
- ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report — SecurityWeek · U.S. security industry trade press; vendor-advertising funded
- 'We Hacked the FBI': ShinyHunters Hands Over 5,000 Employee Records to Back Up Stunning Breach Claim — RedState · U.S. conservative opinion site; owned by Salem Media Group
- ShinyHunters hackers say they breached FBI, stole employee data — CBC News · Canadian public broadcaster, publicly funded
- Hacking group purports to have stolen FBI employee data in cyber attack — ABC News (Australia) · Australian public broadcaster, publicly funded
- Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273) — Rapid7 · Commercial cybersecurity vendor; sells vulnerability-management products
- Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters — SecurityWeek · U.S. security trade press; reporting Google/Mandiant findings, a commercial incident-response vendor
- Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks — SecurityWeek · U.S. security trade press; vendor-advertising funded
- Scattered Lapsus$ Hunters — Wikipedia · Volunteer-edited encyclopedia; used here only for arrest and forum-seizure chronology