Security & AI news

FBI breach claims · By FireAI Security & Research Team · Published

ShinyHunters claims a PeopleSoft zero-day let it breach FBI job-applicant and staff data

ShinyHunters claims a PeopleSoft zero-day let it breach FBI staff and job-applicant systems. The FBI says it is investigating. What applicants should check.

A document with an alert badge, illustrating ShinyHunters’ claimed theft of FBI staff and job-applicant data through a PeopleSoft flaw.

The extortion group ShinyHunters says it broke into FBI systems, including the bureau's public jobs site, and took data on serving staff and job applicants, BleepingComputer reported on 22 September, citing the group's own statements. The FBI has confirmed only that it is investigating. As of 28 September, Help Net Security reported, the FBI's job-application portals remained offline.

Background

ShinyHunters is a data-extortion group that has previously claimed breaches of large organisations and used the claims themselves, alongside stolen data, as leverage. PeopleSoft is Oracle enterprise software widely used by large institutions, including government agencies, for human-resources and administrative systems, so a flaw in it can potentially reach far beyond a single organisation. The Hacker News notes the group weaponised a different, already-disclosed PeopleSoft flaw, tracked as CVE-2026-35273, against other organisations in June 2026, so further claims against other PeopleSoft users would fit its pattern [2].

Findings

According to The Hacker News, a ShinyHunters spokesperson said the group used a previously unknown Oracle PeopleSoft flaw to gain remote code execution on FBI servers. The group claims to have taken roughly 2 to 3 terabytes of data from the FBI's Criminal Justice, HR, Medlink, BEAST, BICS, PEGA, FBIJobs and PHIRE systems, and to have moved into FBI-managed cloud infrastructure at Amazon Web Services, per BleepingComputer. It says the haul covers records on "almost all" FBI agents and everyone who has ever applied for a job with the bureau, including medical information from current and former staff. The group also defaced the FBI jobs site, apply.fbijobs.gov, with a banner reading "This site has been seized by ShinyHunters."

We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.

ShinyHunters, quoted by The Hacker News — a claim, not an independently confirmed fact

None of this is independently verified. BleepingComputer says it has not confirmed the claims itself, and the technical details of the flaw have not been made public. The FBI's statement, given to The Hacker News, stopped short of confirming a breach of its own systems: "While the point of breach is still undetermined—whether a third-party or the FBI's enterprise – we are actively and aggressively investigating this matter." ShinyHunters told BleepingComputer the attack was retaliation for a May 2026 FBI advisory about the group, and demanded it be corrected within a week [1].

Implications for job applicants and FBI staff

The exposure is direct mainly for anyone who has applied for a job with the FBI, currently works there, or shares personal or financial accounts with someone who has. For anyone else, there is no direct exposure from this specific claim. The pattern that follows a breach like this, whether the claim proves accurate or exaggerated, is the one that follows most large breach claims: a wave of phishing emails and texts impersonating the breached organisation.

Recommendations

  1. Anyone who has applied to the FBI, or works there, should treat any email or text about this breach with suspicion, and reach fbijobs.gov by typing the address directly rather than clicking a link.
  2. Never enter a Social Security number, home address or medical detail into a page reached from a link in an unsolicited message.
  3. Turn on two-factor authentication on important accounts, and change any password that has been reused elsewhere.
  4. Treat a message that asks to "verify your identity" by installing something or pasting a command into Terminal as a red flag; no genuine breach notification asks for that.
  5. Anyone whose Social Security number could plausibly be exposed by a breach like this should consider a credit freeze with the major bureaus, the one step that stops someone opening new credit in their name.

Relevance to FireAI

This is a claimed breach of someone else’s servers, using a flaw in software the FBI runs, not anything on a Mac. FireAI cannot detect that a breach happened, cannot scan the internet for exposed data, and cannot freeze anyone’s credit. If information is genuinely exposed, that process runs through the FBI’s own notification, a bank, and the credit bureaus, not through a firewall.

What FireAI can help with is what typically follows: the phishing. Clipboard Armor flags it when an app makes its first-ever connection moments after something changed on the clipboard, the timing pattern behind a "paste this to verify your identity" scam. If a link in an unexpected message leads to installing something new, FireAI asks the first time that app tries to connect and shows where it sends data on the world map, instead of letting it connect silently.

Limitations

None of the three sources independently confirm ShinyHunters’ claims. The technical details of the alleged PeopleSoft flaw have not been published, the FBI has not said which, if any, of its systems were breached, and the 2 to 3 terabyte figure and the "almost all" scope both come solely from the group’s own statement, not from a forensic disclosure.

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. BleepingComputer (Lawrence Abrams), 22 September 2026: ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
  2. The Hacker News (Ravie Lakshmanan), 23 September 2026: ShinyHunters claims FBI breach, says it stole data on agents and job applicants
  3. Help Net Security (Zeljka Zorz), 28 September 2026: FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day