Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 24, 2026 · 6 min read

ShinyHunters Claims FBI Jobs Site Hack via PeopleSoft Bug

On September 22, the extortion crew defaced apply.fbijobs.gov with a Pokémon logo and said an unpatched Oracle PeopleSoft flaw gave it a path into FBI HR, Criminal Justice and Medlink records. The FBI says it is investigating.

Anyone who opened the FBI's special agent application portal on the night of September 22 saw a Pokémon instead of a recruitment page. "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)" read the banner on apply.fbijobs.gov, according to BleepingComputer. The group behind it says the defacement was the least of it. ShinyHunters claims it walked through an unpatched Oracle PeopleSoft zero day and left with 2TB to 3TB of data on current and former FBI employees and the people who applied to join them.

Key Takeaways

  • ShinyHunters defaced apply.fbijobs.gov on September 22, 2026, and claims it stole 2TB to 3TB of FBI employee and job applicant data.
  • The FBI confirmed only that it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
  • 404 Media and Reuters received a sample of about 5,000 purported FBI agent records, and 404 Media matched some phone numbers to real employee names.
  • The group says initial access came through a PeopleSoft remote code execution zero day, with no CVE assigned at the time of reporting.
  • FBI applicants are the exposed population most readers never think about, and their names, phone numbers and home addresses are prime material for targeted phishing.

What Did ShinyHunters Claim to Steal From the FBI?

ShinyHunters claims it took data from three FBI service areas: Criminal Justice, HR and Medlink, plus records on current staff, former staff and job applicants. On its leak site the group threatened to publish information on "every FBI agent and anyone who has applied for a job at the FBI," The Record reported.

Some of it appears to be real. The group handed roughly 5,000 purported agent records to 404 Media and Reuters. 404 Media found phone numbers that matched employee names and Justice Department personnel records. Malwarebytes describes the sample as containing names, home addresses, phone numbers and spouse details.

What is not verified matters just as much:

  • The FBI has not confirmed a breach or any data theft.
  • The 2TB to 3TB figure comes from ShinyHunters alone.
  • A 5,000 record sample says nothing reliable about whether the group holds data on "almost ALL" agents, as it boasts.

As of Wednesday morning, September 23, the special agent application portal was still offline.

How Did the Attackers Get In?

According to ShinyHunters, the entry point was a PeopleSoft vulnerability that allowed remote code execution, followed by lateral movement into FBI managed AWS GovCloud infrastructure. BleepingComputer reported that the group also tried to erase evidence to hide the flaw, and that no CVE had been assigned when it published.

That detail is the one defenders should sit with. PeopleSoft has been ShinyHunters' favorite door since the spring. On June 11, Oracle shipped emergency mitigations for CVE-2026-35273, a 9.8 severity unauthenticated flaw in PeopleTools 8.61 and 8.62. At the time, ShinyHunters said it had stolen data from "300 instances for over 100 organizations," and Mandiant noted 68% of notified organizations were in higher education. The same campaign later reached Nissan's employee records.

Nobody has publicly tied the FBI intrusion to CVE-2026-35273, and the "zero day" label suggests something newer. Only two readings fit the facts. A fresh, unpatched PeopleSoft bug is circulating, or a federal agency left a June fix unapplied for three months. Neither is comforting, and every PeopleSoft shop should treat both as live until Oracle says otherwise. The group itself claims it is now using the same flaw against Fortune 500 companies after working through the education sector.

Laptop showing a job application form glowing red on a dark government office desk beside stacks of personnel files, illustrating the alleged FBIjobs.gov breach

Why Did ShinyHunters Target the FBI?

ShinyHunters says the hack is retaliation for FBI warnings published in May 2026, and it demanded the bureau correct or remove them within a week. The key document is the IC3 public service announcement I-051526-PSA, issued May 15 after the group's attack on the Instructure learning platform disrupted thousands of US universities and K-12 schools.

That advisory accused the group of "sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting." ShinyHunters objects to exactly those lines. Its leak site post insists "WE ARE NOT SEXTORTIONISTS" and says it has "NEVER conducted swatting attacks against corporate victims."

Here is the contrarian read. Most coverage frames this as a brazen strike on law enforcement. In practice it looks like reputation management by an extortion business. Victims who believe a gang will harass their families are less likely to engage with it, and that hurts revenue. Threatening to dox thousands of FBI applicants in order to prove you are not the kind of group that threatens people is a strange way to make that case. It also fits a pattern we covered two days ago, when ShinyHunters hijacked Clop's leak site: this crew increasingly performs for an audience.

What This Means for Your Inbox

Applicants are the quiet victims here. Agents work inside an institution with security teams and counterintelligence support. The civilian who filled out an application years ago and never got a call back has none of that, yet their name, phone number and address may sit in the same dump. The Record quoted experts warning that the stolen data could be sold to criminal or nation state groups for financial fraud or targeted physical attacks.

For most people, the first sign of that resale will arrive by email. A message that references your real application, your real address or a real FBI recruiter name is far more convincing than generic spam. Expect lures posing as "background check updates," "application status" notices or HR requests for identity documents. ShinyHunters data has fed email scams before: after earlier dumps, leaked addresses powered a $2,000 sextortion campaign. A separate Pentagon DMDC breach exposed Social Security numbers of 3 million people, so expect personnel themed phishing from more than one dump.

The IC3 advisory's own guidance applies directly: "Verify urgent or unusual requests received through emails, texts, calls via another communication method," and "Do not click on suspicious links or download unexpected attachments."

What Should You Do Right Now?

If you have ever applied to the FBI, assume your application details are exposed and act accordingly. The steps below draw on the FBI's own May advisory and Malwarebytes' guidance.

For individuals

  • Treat any email or call about your FBI application as suspect. Verify it through fbijobs.gov directly, never through a link or number in the message.
  • Change the password on the email account you used to apply, and stop reusing it anywhere else.
  • Turn on two factor authentication, preferably a FIDO2 security key or passkey.
  • Consider a credit freeze if your application included a Social Security number or financial history.
  • If you receive threats or extortion demands, do not pay or reply. Report them to IC3.

For PeopleSoft administrators

  • Confirm the June CVE-2026-35273 mitigations and any later patches are applied, using Oracle's security alerts page.
  • Pull PeopleSoft web tier and application server logs for unusual process execution, and watch for outbound connections to cloud tenants you do not own.
  • Keep PeopleSoft login and application portals off the open internet where you can, or place them behind a VPN or zero trust proxy.
  • Tell HR and help desk staff to expect vishing and pretext calls that cite real employee details.

Looking Ahead

The one week deadline ShinyHunters set expires within days. Watch for three things: whether the FBI confirms the intrusion, whether Oracle issues a new PeopleSoft advisory or CVE, and whether applicant records start appearing on the group's leak site. If the flaw really is a new zero day, the same PeopleSoft attack path that hit universities in June is open again, and the FBI will not be its last target.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.