ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data
ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) (TL-2026-2760), also tracked as FBIjobs.gov breach, is a high-severity data breach, first published 2026-09-28. It is attributed to ShinyHunters with medium confidence, affects FBI FBIjobs.gov recruitment portal and associated HR systems (claimed, maps to 13 MITRE ATT&CK techniques (T1018, T1021.004, T1036.005), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-2760
- Threat ID
- TL-2026-2760
- Also known as
- FBIjobs.gov breach, FBI Jobs portal defacement
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-28
- Last reviewed
- 2026-09-28
- Attribution
- ShinyHunters
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- government administration, police - law enforcement, human-resources, education
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)
Malware and tooling: MeshCentral
ShinyHunters claims it defaced fbijobs.gov and stole 2-3 TB of HR data covering nearly every FBI agent and FBI job applicant, and demanded the FBI retract its May 2026 PSA on the group. The FBI confirms it is investigating claims of unauthorized activity affecting FBIjobs.gov but has not confirmed the breach or its scope.
How ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) works
On or about 21-22 September 2026 the ShinyHunters extortion brand defaced the FBI's recruitment portal fbijobs.gov, replacing agency imagery with a Pokemon mascot and a 'This site has been seized by ShinyHunters' banner; the portal later showed a scheduled-maintenance message and was still unavailable on 25 September. Around 22-23 September the group posted on its dark-web site claiming to hold data on 'almost ALL FBI Agents and individuals who filed an application', naming affected systems as Criminal Justice (CJ), HR, Medlink, PEGA, PHIRE and FBIJOBS, with a claimed volume of 2-3 TB. The group provided roughly 5,000 records to journalists (including 404 Media and Reuters). The sample reportedly contained names, home addresses, phone numbers, Social Security numbers, duty assignments, job classifications (special agents, intelligence analysts, attorneys, student trainees) and in some cases names of spouses, siblings and other family members. Reuters partially verified the sample against credit-bureau records (at least 10 matches, including the FBI Director) but could not confirm the data came from FBI systems.
The group says the operation was 'not financially motivated'. Its stated goal is retaliation for FBI Private Industry/Public Service Announcement PSA260515 (15 May 2026), which described ShinyHunters' harassment, swatting threats and exaggerated-access extortion tactics, linked the group's activity to attacks on the Canvas LMS (Instructure), and advised victims not to pay. ShinyHunters called the PSA 'substantial false allegations' and 'disinformation', denied ties to 'The Com' and Scattered Spider, and threatened to publish the full dataset unless the FBI retracted or amended the notice by a deadline reported as one week from the incident (Monday 28 September per CyberScoop).
Initial access is claimed, not confirmed: the group asserts a previously unknown Oracle PeopleSoft zero-day used for remote code execution, followed by access to servers in AWS GovCloud. No CVE has been assigned to the alleged flaw and Oracle has not confirmed it. Context: ShinyHunters (tracked by Google as UNC6240) exploited a different PeopleSoft PeopleTools flaw, CVE-2026-35273 (unauthenticated SSRF-to-RCE via PSEMHUB/PSIGW, CVSS 9.8, PeopleTools 8.61/8.62), as a zero-day from 27 May to 9 June 2026 against 100+ organizations, mostly universities; Oracle patched it out-of-band on 10 June 2026. Public reporting calls the FBI vector 'similar' but does not tie it to that CVE, so it is NOT listed in this record's cve_list. The FBI said the point of breach (third party vs. FBI enterprise) is still undetermined. The Hacker News additionally reports claims of sensitive medical data (diagnoses, prescriptions) via the Medlink system; this is unverified. Post-exploitation ATT&CK mappings beyond initial access, defacement and data collection (MeshCentral persistence, SSH credential spraying via a fanout script, Azure-name masquerading, archive-and-exfiltrate) are taken from the documented CVE-2026-35273 ShinyHunters campaign (HivePro, CSA) and are NOT confirmed for the FBI incident. Risks to those exposed include counterintelligence targeting, doxxing, harassment/swatting and physical-safety threats to agents and their families.
MITRE ATT&CK techniques used in TL-2026-2760
Discovery
Lateral Movement
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Execution
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools
Initial Access
T1078.004 Cloud Accounts; T1190 Exploit Public-Facing Application
Credential Access
Collection
T1213 Data from Information Repositories; T1560.001 Archive via Utility
Impact
Affected products and versions in ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)
- FBI — FBIjobs.gov recruitment portal and associated HR systems (claimed: CJ, HR, Medlink, PEGA, PHIRE)
Vulnerable versions: Unconfirmed - Oracle — PeopleSoft Enterprise PeopleTools (claimed unnamed zero-day; related CVE-2026-35273)
Vulnerable versions: 8.61; 8.62 (CVE-2026-35273 only)
Fixed in: CPU187 (10 June 2026) for CVE-2026-35273
Remediation for ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)
Patches
- Apply Oracle out-of-band update CPU187 (10 June 2026) for CVE-2026-35273 on PeopleTools 8.61/8.62; no patch exists for the unconfirmed FBI-claimed zero-day
Immediate actions
- Treat FBI-affiliated personnel and applicants as exposed: monitor for credential-stuffing, phishing and vishing built on leaked PII
- Restrict external access to PeopleSoft Environment Management Hub (/PSEMHUB/*) and PSIGW (/PSIGW/HttpListeningConnector) endpoints
- Hunt PeopleSoft/WebLogic hosts for MeshCentral agents (meshagent*-azure-ops.exe) and README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT marker files
- Do not pay or negotiate extortion demands; follow FBI PSA260515 guidance and report to IC3
Workarounds
- Block internet exposure of PeopleSoft integration gateway and Environment Management endpoints
- Rotate credentials and SSH keys reachable from PeopleSoft hosts
Longer-term hardening
- Segment HR/recruitment platforms from enterprise networks and cloud tenants
- Minimize retention of applicant and family PII; enforce field-level encryption and access logging
- Monitor for swatting/doxxing risk to exposed personnel and brief them on impersonation and social-engineering attempts
Timeline of ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)
- FBI publishes PSA260515 describing ShinyHunters' Canvas/Instructure-related extortion, harassment and swatting tactics and urging victims not to pay
- ShinyHunters (UNC6240) begins exploiting PeopleSoft zero-day CVE-2026-35273 against 100+ organizations, mostly universities (related campaign; not confirmed as the FBI vector)
- Exploitation window of CVE-2026-35273 closes (27 May-9 June) as ShinyHunters/UNC6240 activity against PeopleSoft hosts is disclosed
- Oracle releases out-of-band emergency update CPU187 for CVE-2026-35273 after a 14-day exploitation window
- Alleged intrusion into FBI systems on Monday night, per ShinyHunters claims reported by Nextgov
- fbijobs.gov defaced with Pokemon mascot and 'This site has been seized by ShinyHunters' banner; portal later shows maintenance message
- Reuters partially verifies sample against credit-bureau records (10+ matches incl. FBI Director) but cannot confirm data originated from FBI systems
- ShinyHunters posts claim on its dark-web site (2-3 TB, nearly all FBI agents and applicants) and shares ~5,000 records with journalists; FBI confirms it is investigating
- FBIjobs.gov remains unavailable; group says 'we got what we wanted'
- Monday deadline for FBI to retract or amend PSA260515 or face publication of the full dataset; FBI says it is 'actively and aggressively investigating'
Sources cited for ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)
- ShinyHunters trades financial extortion for a reckless war of ego with the FBI
- FBI investigating alleged ShinyHunters job site breach
- ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
- ShinyHunters claims FBI breach, says it exploited PeopleSoft zero-day
- ShinyHunters claims FBI data theft, demands bureau retract cyber warning
- FBI hack: ShinyHunters countdown ticks down, claims 'we got what we wanted'
- ShinyHunters claims FBI systems hack, sensitive data on almost ALL FBI agents
- Hackers Claim Breach Exposed 'Very Sensitive Data' on Nearly All FBI Agents, Job Applicants
- FBI investigates after ShinyHunters hackers claim theft of agents' personal data
- TechRadar: ShinyHunters say they stole 2TB of employee data, seeking an apology not money
- FBI PSA260515: ShinyHunters extortion and harassment tactics (IC3)
- CVE-2026-35273 analysis (Horizon3.ai)
- CSA Research Note: Oracle PeopleSoft Zero-Day, ShinyHunters Breaches 100 Universities
- Oracle PeopleSoft Under Siege: Zero-Day CVE-2026-35273 Fuels ShinyHunters Intrusions (HivePro)
More in data breach
- Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection
Detection coverage for TL-2026-2760
As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2760 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2760
6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.