EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/criminal-hacking/2026-shinyhunters-fbijobs-breach-claim
001/430

File EL-0430CriticalOngoingCriminal Hacking / Alleged Breach / Extortion

FBIJobs.gov Breach (ShinyHunters Claim)

Also filed as ShinyHunters FBI Hack · FBI Jobs Portal Hack

ShinyHunters claims it breached the FBI's recruitment portal, FBIJobs.gov, through an Oracle PeopleSoft flaw and stole 2–3 TB of personal data on FBI staff and applicants. The FBI says it is "aggressively" investigating but has not confirmed a breach, and the portal has been taken offline.

  • #fbi
  • #law-enforcement
  • #government
  • #shinyhunters
  • #oracle-peoplesoft
  • #extortion
  • #unverified
Notoriety9/10
Event
21 Sept 2026
Disclosed
22 Sept 2026
Target
Federal Bureau of Investigation
Actor
ShinyHunters (claimed)
Scale
2–3 TB (claimed)
Status
Ongoing

01Summary

On 22 September 2026 ShinyHunters claimed it had breached FBI systems the night before through a previously unknown Oracle PeopleSoft vulnerability, entering via the FBIJobs.gov recruitment portal. It claims to hold 2–3 TB of data on "almost ALL FBI Agents and individuals who filed an application" and defaced the jobs site. The group said the attack was revenge for an FBI advisory about it published in May 2026. It threatened to publish the data unless the advisory was retracted within a week. On 23 September the FBI acknowledged the claim but said the point of breach, whether a third party or the FBI's own enterprise, was still undetermined. FBIJobs.gov remained offline. A former FBI agent told NBC News a sample document appeared authentic. No vendor advisory or CVE has been issued for the alleged new flaw. Earlier in 2026 ShinyHunters was linked to exploitation of a separate, patched PeopleSoft vulnerability.

02Key revelations

  1. 01A criminal group publicly targeted the FBI in retaliation for an FBI advisory about it.
  2. 02The FBI could not immediately say whether the breach point was a third-party vendor or its own systems.

03Technical analysis

Attack vector
Alleged exploitation of an Oracle PeopleSoft vulnerability (unconfirmed)
Attack method
Claimed intrusion, data theft, website defacement and public extortion

04Threat actor

ShinyHunters is a prolific data-theft and extortion group behind many 2026 breaches (Charter, Carnival, McKesson, Carhartt, RingCentral, Abbott). It often uses voice-phishing and posts victims on its leak site.

Aliases

  • ShinyHunters

Attribution sources

  • ShinyHunters leak-site statement
  • BleepingComputer
  • NBC News

05Victims and impact

Countries affected

  • United States

06Data exposed

Data types

  • Personal information of FBI employees (claimed)
  • Job applicant records (claimed)

07Timeline

  1. 2026-05-01FBI publishes an advisory on ShinyHunters (May 2026).
  2. 2026-09-21Alleged intrusion (Monday night).
  3. 2026-09-22ShinyHunters announces the breach and defaces FBIJobs.gov.
  4. 2026-09-23FBI confirms it is investigating; the portal stays offline.

08On the record

The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third-party or the FBI's enterprise — we are actively and aggressively investigating this matter.

FBI, Statement, 23 September 2026

This type of information could be used by criminals to target or physically harm FBI agents.

Cynthia Kaiser (former senior FBI cyber official), NBC News

You often see a mixture of truth and lies when dealing with threat actors like this.

Cynthia Kaiser, NBC News

09Reaction and fallout

Public reaction

Concern for the physical safety of agents if the data is real and published.

10Significance and legacy

Significance

One of the most brazen criminal attacks on a US federal law enforcement agency. If confirmed, it would expose the bureau's own workforce.

11Disclosure and media

Publishing organisations

  • BleepingComputer
  • NBC News
  • Federal News Network
  • Forbes
  • The Hacker News

12Related files

Related events

  • 2026-fbi-surveillance-system-breach
  • 2026-kash-patel-personal-email-leak

13Resolution

FBI investigation ongoing, portal offline, and ShinyHunters' one-week deadline pending at the time of writing.

14Sources

References

  1. [1]Federal News Network: https://federalnewsnetwork.com/cybersecurity/2026/09/fbi-investigates-apparent-breach-of-its-jobs-website-hackers-claim-to-have-sensitive-employee-data/
  2. [2]NBC News: https://www.nbcnews.com/tech/security/fbi-investigating-hacking-groups-claim-massive-breach-agent-info-rcna599370
  3. [3]BleepingComputer: https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
  4. [4]Forbes: https://www.forbes.com/sites/antoniopequenoiv/2026/09/23/fbi-aggressively-investigating-alleged-hack-compromising-all-employees-personal-data/
Fact sheetEL-0430

Dates

Event
21 Sept 2026
Disclosed
22 Sept 2026
Ongoing
Yes

Target

Organisation
Federal Bureau of Investigation — FBIJobs.gov recruitment portal
Type
Federal Law Enforcement Agency
Sector
Government / Law Enforcement
Country
United States
Gov. level
Federal

Actor

Name
ShinyHunters (claimed)
Type
Criminal Gang
Motivation
Retaliation for the FBI's May 2026 advisory about the group. ShinyHunters demanded the advisory be retracted within a week or it would publish the data.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
2–3 TB (claimed)
Sensitivity
Highly Sensitive
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.