ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data

ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) (TL-2026-2760), also tracked as FBIjobs.gov breach, is a high-severity data breach, first published 2026-09-28. It is attributed to ShinyHunters with medium confidence, affects FBI FBIjobs.gov recruitment portal and associated HR systems (claimed, maps to 13 MITRE ATT&CK techniques (T1018, T1021.004, T1036.005), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-2760

Threat ID
TL-2026-2760
Also known as
FBIjobs.gov breach, FBI Jobs portal defacement
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-28
Last reviewed
2026-09-28
Attribution
ShinyHunters
Attribution confidence
MEDIUM
Motivation
UNKNOWN
Target sectors
government administration, police - law enforcement, human-resources, education
Target regions
North America
Detection rules
9
Indicators of compromise
25

Malware and tooling in ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)

Malware and tooling: MeshCentral

ShinyHunters claims it defaced fbijobs.gov and stole 2-3 TB of HR data covering nearly every FBI agent and FBI job applicant, and demanded the FBI retract its May 2026 PSA on the group. The FBI confirms it is investigating claims of unauthorized activity affecting FBIjobs.gov but has not confirmed the breach or its scope.

How ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) works

On or about 21-22 September 2026 the ShinyHunters extortion brand defaced the FBI's recruitment portal fbijobs.gov, replacing agency imagery with a Pokemon mascot and a 'This site has been seized by ShinyHunters' banner; the portal later showed a scheduled-maintenance message and was still unavailable on 25 September. Around 22-23 September the group posted on its dark-web site claiming to hold data on 'almost ALL FBI Agents and individuals who filed an application', naming affected systems as Criminal Justice (CJ), HR, Medlink, PEGA, PHIRE and FBIJOBS, with a claimed volume of 2-3 TB. The group provided roughly 5,000 records to journalists (including 404 Media and Reuters). The sample reportedly contained names, home addresses, phone numbers, Social Security numbers, duty assignments, job classifications (special agents, intelligence analysts, attorneys, student trainees) and in some cases names of spouses, siblings and other family members. Reuters partially verified the sample against credit-bureau records (at least 10 matches, including the FBI Director) but could not confirm the data came from FBI systems.

The group says the operation was 'not financially motivated'. Its stated goal is retaliation for FBI Private Industry/Public Service Announcement PSA260515 (15 May 2026), which described ShinyHunters' harassment, swatting threats and exaggerated-access extortion tactics, linked the group's activity to attacks on the Canvas LMS (Instructure), and advised victims not to pay. ShinyHunters called the PSA 'substantial false allegations' and 'disinformation', denied ties to 'The Com' and Scattered Spider, and threatened to publish the full dataset unless the FBI retracted or amended the notice by a deadline reported as one week from the incident (Monday 28 September per CyberScoop).

Initial access is claimed, not confirmed: the group asserts a previously unknown Oracle PeopleSoft zero-day used for remote code execution, followed by access to servers in AWS GovCloud. No CVE has been assigned to the alleged flaw and Oracle has not confirmed it. Context: ShinyHunters (tracked by Google as UNC6240) exploited a different PeopleSoft PeopleTools flaw, CVE-2026-35273 (unauthenticated SSRF-to-RCE via PSEMHUB/PSIGW, CVSS 9.8, PeopleTools 8.61/8.62), as a zero-day from 27 May to 9 June 2026 against 100+ organizations, mostly universities; Oracle patched it out-of-band on 10 June 2026. Public reporting calls the FBI vector 'similar' but does not tie it to that CVE, so it is NOT listed in this record's cve_list. The FBI said the point of breach (third party vs. FBI enterprise) is still undetermined. The Hacker News additionally reports claims of sensitive medical data (diagnoses, prescriptions) via the Medlink system; this is unverified. Post-exploitation ATT&CK mappings beyond initial access, defacement and data collection (MeshCentral persistence, SSH credential spraying via a fanout script, Azure-name masquerading, archive-and-exfiltrate) are taken from the documented CVE-2026-35273 ShinyHunters campaign (HivePro, CSA) and are NOT confirmed for the FBI incident. Risks to those exposed include counterintelligence targeting, doxxing, harassment/swatting and physical-safety threats to agents and their families.

MITRE ATT&CK techniques used in TL-2026-2760

Discovery

T1018 Remote System Discovery

Lateral Movement

T1021.004 SSH

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Execution

T1059.004 Unix Shell

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools

Initial Access

T1078.004 Cloud Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1110.003 Password Spraying

Collection

T1213 Data from Information Repositories; T1560.001 Archive via Utility

Impact

T1491.002 External Defacement

Affected products and versions in ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)

  • FBI — FBIjobs.gov recruitment portal and associated HR systems (claimed: CJ, HR, Medlink, PEGA, PHIRE)
    Vulnerable versions: Unconfirmed
  • Oracle — PeopleSoft Enterprise PeopleTools (claimed unnamed zero-day; related CVE-2026-35273)
    Vulnerable versions: 8.61; 8.62 (CVE-2026-35273 only)
    Fixed in: CPU187 (10 June 2026) for CVE-2026-35273

Remediation for ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)

Patches

  • Apply Oracle out-of-band update CPU187 (10 June 2026) for CVE-2026-35273 on PeopleTools 8.61/8.62; no patch exists for the unconfirmed FBI-claimed zero-day

Immediate actions

  • Treat FBI-affiliated personnel and applicants as exposed: monitor for credential-stuffing, phishing and vishing built on leaked PII
  • Restrict external access to PeopleSoft Environment Management Hub (/PSEMHUB/*) and PSIGW (/PSIGW/HttpListeningConnector) endpoints
  • Hunt PeopleSoft/WebLogic hosts for MeshCentral agents (meshagent*-azure-ops.exe) and README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT marker files
  • Do not pay or negotiate extortion demands; follow FBI PSA260515 guidance and report to IC3

Workarounds

  • Block internet exposure of PeopleSoft integration gateway and Environment Management endpoints
  • Rotate credentials and SSH keys reachable from PeopleSoft hosts

Longer-term hardening

  • Segment HR/recruitment platforms from enterprise networks and cloud tenants
  • Minimize retention of applicant and family PII; enforce field-level encryption and access logging
  • Monitor for swatting/doxxing risk to exposed personnel and brief them on impersonation and social-engineering attempts

Timeline of ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)

  • FBI publishes PSA260515 describing ShinyHunters' Canvas/Instructure-related extortion, harassment and swatting tactics and urging victims not to pay
  • ShinyHunters (UNC6240) begins exploiting PeopleSoft zero-day CVE-2026-35273 against 100+ organizations, mostly universities (related campaign; not confirmed as the FBI vector)
  • Exploitation window of CVE-2026-35273 closes (27 May-9 June) as ShinyHunters/UNC6240 activity against PeopleSoft hosts is disclosed
  • Oracle releases out-of-band emergency update CPU187 for CVE-2026-35273 after a 14-day exploitation window
  • Alleged intrusion into FBI systems on Monday night, per ShinyHunters claims reported by Nextgov
  • fbijobs.gov defaced with Pokemon mascot and 'This site has been seized by ShinyHunters' banner; portal later shows maintenance message
  • Reuters partially verifies sample against credit-bureau records (10+ matches incl. FBI Director) but cannot confirm data originated from FBI systems
  • ShinyHunters posts claim on its dark-web site (2-3 TB, nearly all FBI agents and applicants) and shares ~5,000 records with journalists; FBI confirms it is investigating
  • FBIjobs.gov remains unavailable; group says 'we got what we wanted'
  • Monday deadline for FBI to retract or amend PSA260515 or face publication of the full dataset; FBI says it is 'actively and aggressively investigating'

Sources cited for ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov)

More in data breach

Detection coverage for TL-2026-2760

As of 2026-09-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2760 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2760

6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats