01Summary
On 22 September 2026 ShinyHunters claimed it had breached FBI systems the night before through a previously unknown Oracle PeopleSoft vulnerability, entering via the FBIJobs.gov recruitment portal. It claims to hold 2–3 TB of data on "almost ALL FBI Agents and individuals who filed an application" and defaced the jobs site. The group said the attack was revenge for an FBI advisory about it published in May 2026. It threatened to publish the data unless the advisory was retracted within a week. On 23 September the FBI acknowledged the claim but said the point of breach, whether a third party or the FBI's own enterprise, was still undetermined. FBIJobs.gov remained offline. A former FBI agent told NBC News a sample document appeared authentic. No vendor advisory or CVE has been issued for the alleged new flaw. Earlier in 2026 ShinyHunters was linked to exploitation of a separate, patched PeopleSoft vulnerability.
02Key revelations
- 01A criminal group publicly targeted the FBI in retaliation for an FBI advisory about it.
- 02The FBI could not immediately say whether the breach point was a third-party vendor or its own systems.
03Technical analysis
- Attack vector
- Alleged exploitation of an Oracle PeopleSoft vulnerability (unconfirmed)
- Attack method
- Claimed intrusion, data theft, website defacement and public extortion
04Threat actor
ShinyHunters is a prolific data-theft and extortion group behind many 2026 breaches (Charter, Carnival, McKesson, Carhartt, RingCentral, Abbott). It often uses voice-phishing and posts victims on its leak site.
Aliases
- ShinyHunters
Attribution sources
- ShinyHunters leak-site statement
- BleepingComputer
- NBC News
05Victims and impact
Countries affected
- United States
06Data exposed
Data types
- Personal information of FBI employees (claimed)
- Job applicant records (claimed)
07Timeline
- 2026-05-01FBI publishes an advisory on ShinyHunters (May 2026).
- 2026-09-21Alleged intrusion (Monday night).
- 2026-09-22ShinyHunters announces the breach and defaces FBIJobs.gov.
- 2026-09-23FBI confirms it is investigating; the portal stays offline.
08On the record
The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third-party or the FBI's enterprise — we are actively and aggressively investigating this matter.
This type of information could be used by criminals to target or physically harm FBI agents.
You often see a mixture of truth and lies when dealing with threat actors like this.
09Reaction and fallout
Public reaction
Concern for the physical safety of agents if the data is real and published.
10Significance and legacy
Significance
One of the most brazen criminal attacks on a US federal law enforcement agency. If confirmed, it would expose the bureau's own workforce.
11Disclosure and media
Publishing organisations
- BleepingComputer
- NBC News
- Federal News Network
- Forbes
- The Hacker News
13Resolution
FBI investigation ongoing, portal offline, and ShinyHunters' one-week deadline pending at the time of writing.
14Sources
References
- [1]Federal News Network: https://federalnewsnetwork.com/cybersecurity/2026/09/fbi-investigates-apparent-breach-of-its-jobs-website-hackers-claim-to-have-sensitive-employee-data/
- [2]NBC News: https://www.nbcnews.com/tech/security/fbi-investigating-hacking-groups-claim-massive-breach-agent-info-rcna599370
- [3]BleepingComputer: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
- [4]Forbes: https://www.forbes.com/sites/antoniopequenoiv/2026/09/23/fbi-aggressively-investigating-alleged-hack-compromising-all-employees-personal-data/









