Securityaffairs

ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack


ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

Pierluigi Paganini
September 23, 2026

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.

The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead carried out in response to an FBI warning published earlier this year.

The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel. The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.

Reuters was able to partially match some of the sample information with other records, including data associated with FBI Director Kash Patel. However, the news agency could not determine where the information originally came from or independently confirm that it had been stolen from FBI systems.

“Reuters was able to partially verify the authenticity of the information by running the details, including the Social Security numbers, ​against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs.” reads the report published by Reuters. “In at least 10 instances — including in the case ‌of FBI ⁠Director Kash Patel — Reuters found details that appeared to match. A person familiar with the matter said that the job descriptions in the data also matched in at least some cases.”

The FBI has acknowledged that it is aware of claims involving unauthorized activity affecting FBIjobs.gov and said it is investigating. The agency has not confirmed that its internal systems were compromised or that ShinyHunters obtained the data it claims to possess.

ShinyHunters has provided a possible technical explanation for the alleged intrusion. The group claims the exploitation of an Oracle PeopleSoft zero-day, reportedly using it to gain remote code execution through infrastructure connected to the FBI’s recruitment services.

The claim is notable because ShinyHunters has already been linked to attacks exploiting a real PeopleSoft zero-day earlier this year. In June, Oracle addressed CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in PeopleSoft PeopleTools. Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.

That history makes the latest claim technically plausible, but it does not prove that the same group used another PeopleSoft zero-day against the FBI. No public CVE or vendor confirmation currently exists for the alleged new vulnerability.

The attackers also reportedly claimed access to several FBI-related services, including human resources systems and a system they referred to as Medlink. They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.

Reuters and other media outlets confirmed the recruitment website did experience disruption around the time of the claim. A page that had reportedly been defaced by the attackers later displayed a scheduled-maintenance message. That disruption could be consistent with an intrusion, but it is not by itself proof that the wider FBI systems were breached.

There is also a clear motive behind the operation claimed by ShinyHunters. The group says it targeted the FBI after a May 2026 public advisory describing its tactics and warning victims against paying. ShinyHunters disputes the FBI’s characterization of its activities and is reportedly demanding that the Bureau retract or correct the warning.

This makes the alleged attack unusual. Instead of immediately demanding a conventional ransom, the group appears to be using the stolen data as leverage in a dispute with U.S. law enforcement.

The timing is also significant. ShinyHunters has recently claimed responsibility for several major breaches and has been involved in a public dispute with the Clop cybercrime operation. The group recently claimed to have compromised Clop’s data leak site, highlighting the increasingly aggressive behavior surrounding the group.

For now, however, the FBI investigation remains the missing piece. Until investigators confirm the intrusion, the extent of access and the origin of the leaked records, the ShinyHunters account should remain a claim rather than an established FBI breach.

What is already clear is that the incident would be serious if confirmed. Personal information belonging to law enforcement personnel could expose agents and their families to targeted harassment, social engineering and other forms of abuse. But the available evidence does not yet allow those consequences to be attributed to a confirmed compromise of FBI internal systems.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, FBI)







Source link