ShinyHunters say they stole data on all FBI employees through an HR system
A hacking group says it is holding the personnel file of everyone who works for the FBI, used to work for it, or ever applied. ShinyHunters told 404 Media it got in through the bureau's recruitment system, pulled two to three terabytes out of a government cloud, and defaced the FBI jobs portal on Tuesday. It is not asking for money. It wants the FBI to delete a notice the agency published about the group, and it has given the bureau a week.
The FBI has confirmed nothing. What can be checked from outside is narrow but real: the jobs portal is offline, and the reporters who saw a sample of the data matched part of it against public records.
In short
- ShinyHunters claims 2-3 TB taken from FBI recruitment and personnel systems, with an Oracle PeopleSoft server as the way in.
- 404 Media reviewed a sample of 5,000 records: names, home addresses, phone numbers, dates of birth and spouse details. Some of the numbers trace back to Justice Department staff.
- The demand is not a ransom. The group wants the FBI to take down its published warning about ShinyHunters, within one week.
- apply.fbijobs.gov and the Special Agent Applicant Portal now return a maintenance page. The FBI, Oracle and AWS have not commented.
What the group says it took
"We hacked the FBI. We hold data on all FBI employees and applicants," a representative of the group told 404 Media on 22 September. The same representative described the route: a zero-day in Oracle PeopleSoft, the software the bureau runs its hiring on, then a move sideways into servers in AWS GovCloud, where the data was downloaded. Three internal services are named in the claim: Criminal Justice, Human Resources and Medlink.
The defacement left on the jobs site was written to imitate a law enforcement takedown banner: "this site has been seized by ShinyHunters", followed by a claim that all FBI data was compromised, including personal and health information on current and former staff and on every applicant, and the line "We have a lot more than we claim here."
Asked whether this was an extortion attempt, the representative gave an answer worth reading twice: "what we plan to do is not something I'd call extortion, maybe coercion." And then: "This is not financially motivated." What the group wants is for the FBI to withdraw the public notice it published about ShinyHunters, which the group says contains false claims. The deadline is one week, after which it threatens to publish.
What holds up and what does not
An extortion crew is a poor primary source, and this one has an obvious interest in sounding larger than it is. So it is worth separating the claim from the part anyone can verify.
| The claim | What can be checked from outside |
|---|---|
| Data on all FBI employees and applicants | Journalists have seen a sample of 5,000 records. Nobody outside the group has seen the full set, and there is no file listing. |
| The sample is genuine | 404 Media ran phone numbers from it through OSINT Industries and got matching names, and a second tool tied some numbers to Justice Department personnel. TechCrunch separately matched part of the data against public records. |
| 2 to 3 terabytes exfiltrated | The group's word only. No sizes, no directory structure, no proof of volume has been shown. |
| Entry through an unknown PeopleSoft flaw | A screenshot points at a /PSEMHUB/ path on apply.fbijobs.gov. Oracle has not confirmed a new flaw and no CVE exists for it. |
| The jobs portal was seized | True in effect. apply.fbijobs.gov serves a "Scheduled Maintenance Underway" page, and the Special Agent Applicant Portal is down with it. |
The PeopleSoft hole behind it
PeopleSoft is Oracle's back-office suite for payroll, HR and student records. The component in question, the Environment Management Hub, is an internal service that was never meant to face the internet, and in June it turned into one of the year's ugliest holes. CVE-2026-35273 scores 9.8 out of 10: no login, no user interaction, just an HTTP request to take over the server.
- The FBI publishes a public notice on ShinyHunters, describing the group's extortion and harassment methods.
- Mandiant later dates the start of exploitation of the PeopleSoft flaw to this day.
- End of the exploitation window Mandiant reconstructed. The group is tracked as UNC6240.
- Oracle ships an out-of-band patch for CVE-2026-35273.
- CISA adds the flaw to its catalogue of vulnerabilities known to be exploited.
- ShinyHunters says it found a new PeopleSoft flaw that night and used it against the FBI within hours.
- The jobs portal is defaced, then taken down. The ultimatum appears on the group's leak site.
The June campaign was not small. Mandiant warned more than a hundred organisations that their systems were exposed, and about 68 percent of them were universities. One of them, the University of Nottingham, ended up with the records of 455,000 students published on a leak site.
That history is why the FBI case is ambiguous rather than obvious. The screenshot the group shared points at the same component Oracle patched in June. Either there is a second flaw in the same place, or the bureau's server never received the June update. The group insists the bug is new and undisclosed. Oracle has not said a word either way.
Why a recruitment database is the worst thing to lose
A hiring system sounds like a filing cabinet of CVs. It is not. To process one applicant it has to store a home address, a date of birth, a personal phone number, next of kin, and for any job with a medical exam, health records. That is why the defacement mentions health information, and why one of the three named services is called Medlink. An HR database holds the things a passport application asks for, on people who never became employees.
For most employers that is a privacy problem. For a law enforcement agency it is an operational one. 404 Media points out that criminals from this same ecosystem have already used stolen phone records to track, intimidate and harass the FBI agents investigating them. TechCrunch frames the risk in counterintelligence terms: a list of agents, their home addresses and their spouses is exactly the material a foreign service uses to pressure someone into cooperating. This is also the second known intrusion into an FBI system this year, after unidentified hackers reached a system used to manage real-time wiretaps and foreign intelligence warrants.
Who else runs PeopleSoft
ShinyHunters told CyberInsider it intends to use the new flaw against a much broader set of targets. That matters well beyond Washington, because PeopleSoft runs the payroll and student records of universities, ministries and large employers across Europe, Latin America and Asia. The June wave showed the shape of it: a hundred organisations in a fortnight, mostly campuses, because campuses run these systems with a small team and an internet-facing admin interface.
There is nothing an applicant can do about any of this. If you sent a CV to a large institution at some point in the last decade, your file is probably sitting in a system of this kind, you were never told which one, and you cannot check whether it has been patched.
What to do if your file could be in something like this
The realistic risk for an ordinary reader is not that a foreign service is after them. It is the wave of well-informed phishing that follows any breach of this size, where the caller knows your former employer, your address and your date of birth, and uses that to sound official. We have written before about how quickly stolen registry data turns into fake official demands, and the pattern does not change.
- Treat any message about this breach as bait, including one that appears to come from the agency itself
- Search your email addresses on Have I Been Pwned and turn on alerts for new leaks
- Replace SMS codes with an authenticator app or a hardware key on mail and banking
- Ask former employers and universities to erase the application file they no longer need
- Search your own phone number in a logged-out browser and see what comes back
- Freeze your credit file if your country offers it
Has the FBI confirmed the breach?
Would a VPN have prevented this?
I applied there years ago and was rejected. Am I in the file?
Is this the June PeopleSoft vulnerability again?
What happens when the week runs out?
• 'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees - 404 Media
• Hacking group ShinyHunters claims it breached the FBI - TechCrunch
• ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day - CyberInsider
• ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit - Google Threat Intelligence
• Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273) - Rapid7
• ShinyHunters Exploits Oracle PeopleSoft Zero-Day to Breach Universities - The Hacker News
• ShinyHunters: Cyber Criminal Group Attacks Learning Management System - FBI IC3
• Scheduled Maintenance Underway - apply.fbijobs.gov