ShinyHunters Hackers Defaced FBI's Jobs Site, Claim Agents' Data Stolen

ShinyHunters, the extortion crew the FBI publicly called out in May, broke into the bureau's own jobs portal this week and left a message: seized. The group says it took 2 to 3 terabytes of data, including home addresses for agents, and is giving the FBI seven days to retract its warning.

FBIjobs.gov normally lists openings for special agents and analysts. On September 22, it displayed a banner reading "This site has been seized by ShinyHunters," alongside an image of the Pokémon the group has adopted as its mascot. The applicant portal went dark. The FBI confirmed it's investigating. It hasn't said whether its systems were actually compromised.

ShinyHunters claims the defacement was just the opening move. According to reporting from TechCrunch and CyberScoop, the group says it broke into an FBI server Monday night using a previously unknown flaw in Oracle's PeopleSoft platform, gained remote code execution, and then moved laterally into other agency systems, including infrastructure hosted in AWS GovCloud. From there, ShinyHunters claims it pulled between 2 and 3 terabytes of files out of the FBI's Criminal Justice, HR, and Medlink services. The group told The Record and Bleeping Computer the haul includes home addresses, phone numbers, and family details for what it called "almost ALL FBI Agents," plus job applicants.

None of that is verified. The FBI hasn't confirmed the scope, or even that the stolen files are real. But the bureau has a credibility problem here that most victims don't: it's the same agency that just spent months warning the public about exactly this group's tactics.

This is personal. On May 15, 2026, the FBI's Internet Crime Complaint Center published PSA 260515, warning that ShinyHunters harasses victims, threatens their families - and in some cases, swats them. ShinyHunters is now demanding the FBI pull that advisory, calling it false, and says it will leak the stolen files if the bureau doesn't comply within a week. Malwarebytes reported the group framed the entire breach as revenge for the PSA. It's an unusual position for the FBI to be in: the agency built to hunt hackers is now the one being told what to publish.

The hole ShinyHunters says it used isn't new. Oracle disclosed CVE-2026-35273, a remote code execution flaw in PeopleSoft's PeopleTools rated 9.8 out of 10 in severity, on June 10. Google's Mandiant traced exploitation back to May 27, meaning the bug was actively being used as a zero-day for roughly two weeks before anyone outside the attackers knew it existed. By the time the dust settled, security researchers at Arctic Wolf and CSO Online had tied the same campaign to more than 300 PeopleSoft instances across over 100 organizations, with universities taking the brunt of it. Google attributes that wave to a group it tracks as UNC6240.

That's the part worth sitting with if you run enterprise software. A single unpatched instance of a decades-old HR and finance platform gave one crew a foothold into dozens of unrelated institutions, and now, apparently, into a federal law enforcement agency. PeopleSoft runs payroll and HR for governments and universities alike - Fortune 500 companies too. It's not glamorous software. It's also not going anywhere, which is exactly why it keeps showing up as the door hackers walk through.

ShinyHunters has been busy elsewhere too. Between September 18 and 19, the group hijacked the dark-web leak site belonging to Cl0p, another major extortion gang, and started using that infrastructure for its own posts. That's not a small move in the ransomware underworld. Leak sites are how these groups pressure victims into paying: taking over a rival's is either an alliance or a hostile takeover, depending on who you ask. Nobody's saying which.

Frankly, the FBI angle will get the attention. But the PeopleSoft campaign is the one that should actually worry companies. Whether or not ShinyHunters really holds agents' home addresses, the underlying vulnerability already hit universities, corporations, and now allegedly a federal agency running the same enterprise software millions of organizations still depend on.

The FBI has one week to decide whether it retracts a public warning about a group that just, by its own account, broke into the bureau to make that point. It hasn't said whether it will.

Also read: OpenAI's AI Agent Hacked Australia's Medicare Portal in JuneBernie Sanders Proposes 20-Year Prison Terms to Ban Superintelligent AIOil Prices Sink After Trump's Three-Hour Meeting With Iran's Delegation

This article is posted in News News, check it out for more related stories.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论