ShinyHunters say they stole data on all FBI employees through an HR system

22.09.2026 10 min 26

A hacking group says it is holding the personnel file of everyone who works for the FBI, used to work for it, or ever applied. ShinyHunters told 404 Media it got in through the bureau's recruitment system, pulled two to three terabytes out of a government cloud, and defaced the FBI jobs portal on Tuesday. It is not asking for money. It wants the FBI to delete a notice the agency published about the group, and it has given the bureau a week.

The FBI has confirmed nothing. What can be checked from outside is narrow but real: the jobs portal is offline, and the reporters who saw a sample of the data matched part of it against public records.

In short

  • ShinyHunters claims 2-3 TB taken from FBI recruitment and personnel systems, with an Oracle PeopleSoft server as the way in.
  • 404 Media reviewed a sample of 5,000 records: names, home addresses, phone numbers, dates of birth and spouse details. Some of the numbers trace back to Justice Department staff.
  • The demand is not a ransom. The group wants the FBI to take down its published warning about ShinyHunters, within one week.
  • apply.fbijobs.gov and the Special Agent Applicant Portal now return a maintenance page. The FBI, Oracle and AWS have not commented.

What the group says it took

"We hacked the FBI. We hold data on all FBI employees and applicants," a representative of the group told 404 Media on 22 September. The same representative described the route: a zero-day in Oracle PeopleSoft, the software the bureau runs its hiring on, then a move sideways into servers in AWS GovCloud, where the data was downloaded. Three internal services are named in the claim: Criminal Justice, Human Resources and Medlink.

The defacement left on the jobs site was written to imitate a law enforcement takedown banner: "this site has been seized by ShinyHunters", followed by a claim that all FBI data was compromised, including personal and health information on current and former staff and on every applicant, and the line "We have a lot more than we claim here."

Asked whether this was an extortion attempt, the representative gave an answer worth reading twice: "what we plan to do is not something I'd call extortion, maybe coercion." And then: "This is not financially motivated." What the group wants is for the FBI to withdraw the public notice it published about ShinyHunters, which the group says contains false claims. The deadline is one week, after which it threatens to publish.

5000records in the sample reporters saw
2-3 TBvolume the group claims
3internal services named
7 daysbefore the threatened leak

What holds up and what does not

An extortion crew is a poor primary source, and this one has an obvious interest in sounding larger than it is. So it is worth separating the claim from the part anyone can verify.

The claimWhat can be checked from outside
Data on all FBI employees and applicantsJournalists have seen a sample of 5,000 records. Nobody outside the group has seen the full set, and there is no file listing.
The sample is genuine404 Media ran phone numbers from it through OSINT Industries and got matching names, and a second tool tied some numbers to Justice Department personnel. TechCrunch separately matched part of the data against public records.
2 to 3 terabytes exfiltratedThe group's word only. No sizes, no directory structure, no proof of volume has been shown.
Entry through an unknown PeopleSoft flawA screenshot points at a /PSEMHUB/ path on apply.fbijobs.gov. Oracle has not confirmed a new flaw and no CVE exists for it.
The jobs portal was seizedTrue in effect. apply.fbijobs.gov serves a "Scheduled Maintenance Underway" page, and the Special Agent Applicant Portal is down with it.

The PeopleSoft hole behind it

PeopleSoft is Oracle's back-office suite for payroll, HR and student records. The component in question, the Environment Management Hub, is an internal service that was never meant to face the internet, and in June it turned into one of the year's ugliest holes. CVE-2026-35273 scores 9.8 out of 10: no login, no user interaction, just an HTTP request to take over the server.

  1. The FBI publishes a public notice on ShinyHunters, describing the group's extortion and harassment methods.
  2. Mandiant later dates the start of exploitation of the PeopleSoft flaw to this day.
  3. End of the exploitation window Mandiant reconstructed. The group is tracked as UNC6240.
  4. Oracle ships an out-of-band patch for CVE-2026-35273.
  5. CISA adds the flaw to its catalogue of vulnerabilities known to be exploited.
  6. ShinyHunters says it found a new PeopleSoft flaw that night and used it against the FBI within hours.
  7. The jobs portal is defaced, then taken down. The ultimatum appears on the group's leak site.

The June campaign was not small. Mandiant warned more than a hundred organisations that their systems were exposed, and about 68 percent of them were universities. One of them, the University of Nottingham, ended up with the records of 455,000 students published on a leak site.

That history is why the FBI case is ambiguous rather than obvious. The screenshot the group shared points at the same component Oracle patched in June. Either there is a second flaw in the same place, or the bureau's server never received the June update. The group insists the bug is new and undisclosed. Oracle has not said a word either way.

Still unknown: whether the FBI lost anything at all, how much of the claimed volume exists, whether the flaw is new, and whether the 5,000-record sample is representative of a larger set or is the whole of it. The FBI's own notice from May warns that groups like this routinely inflate what they hold to force a response.

Why a recruitment database is the worst thing to lose

A hiring system sounds like a filing cabinet of CVs. It is not. To process one applicant it has to store a home address, a date of birth, a personal phone number, next of kin, and for any job with a medical exam, health records. That is why the defacement mentions health information, and why one of the three named services is called Medlink. An HR database holds the things a passport application asks for, on people who never became employees.

For most employers that is a privacy problem. For a law enforcement agency it is an operational one. 404 Media points out that criminals from this same ecosystem have already used stolen phone records to track, intimidate and harass the FBI agents investigating them. TechCrunch frames the risk in counterintelligence terms: a list of agents, their home addresses and their spouses is exactly the material a foreign service uses to pressure someone into cooperating. This is also the second known intrusion into an FBI system this year, after unidentified hackers reached a system used to manage real-time wiretaps and foreign intelligence warrants.

Who else runs PeopleSoft

ShinyHunters told CyberInsider it intends to use the new flaw against a much broader set of targets. That matters well beyond Washington, because PeopleSoft runs the payroll and student records of universities, ministries and large employers across Europe, Latin America and Asia. The June wave showed the shape of it: a hundred organisations in a fortnight, mostly campuses, because campuses run these systems with a small team and an internet-facing admin interface.

There is nothing an applicant can do about any of this. If you sent a CV to a large institution at some point in the last decade, your file is probably sitting in a system of this kind, you were never told which one, and you cannot check whether it has been patched.

What to do if your file could be in something like this

The realistic risk for an ordinary reader is not that a foreign service is after them. It is the wave of well-informed phishing that follows any breach of this size, where the caller knows your former employer, your address and your date of birth, and uses that to sound official. We have written before about how quickly stolen registry data turns into fake official demands, and the pattern does not change.

  • Treat any message about this breach as bait, including one that appears to come from the agency itself
  • Search your email addresses on Have I Been Pwned and turn on alerts for new leaks
  • Replace SMS codes with an authenticator app or a hardware key on mail and banking
  • Ask former employers and universities to erase the application file they no longer need
  • Search your own phone number in a logged-out browser and see what comes back
  • Freeze your credit file if your country offers it
Has the FBI confirmed the breach?
No. As of 22 September 2026 the bureau has not commented, and neither have Oracle or Amazon. The only thing visible from outside is the maintenance page on the jobs portal and the applicant portal being down.
Would a VPN have prevented this?
No. Nothing was taken from anyone's connection. The data sat in an employer's HR system on the other side of the internet, and a VPN has no reach into that. It changes what your provider and the networks in between can see, not what a company stores about you.
I applied there years ago and was rejected. Am I in the file?
The group claims applicant records are included, and recruitment systems keep rejected applications for years. Nobody outside the group can check a specific name, and there is no notification process for people who never became employees.
Is this the June PeopleSoft vulnerability again?
Unclear. The screenshot points at the same component Oracle patched on 10 June, so it is either a second flaw in that component or a server that never got the update. The group says the bug is new and undisclosed, Oracle has said nothing.
What happens when the week runs out?
The group threatens to publish the data. It has followed through on threats before, but the FBI's own May notice warns that these groups also exaggerate what they hold in order to force a reaction.

usafbishinyhuntersoracle peoplesoftawsdata breachcybersecuritypersonal dataprivacyhackingextortionphishingvulnerabilitylaw enforcement

Read also