The FBI is investigating claims that the ShinyHunters cybercrime group compromised FBIJobs.gov and obtained a large collection of personnel and applicant information, including records that appear to identify employees working in sensitive intelligence, surveillance, and counterintelligence roles. ShinyHunters says it entered through a previously unknown Oracle PeopleSoft vulnerability and ultimately stole between two and three terabytes of data, but those central claims remain unverified. The FBI’s public statement stops short of confirming either a breach of its enterprise systems or the theft of data.
The bureau said on September 23 that it was aware of a cybercriminal group claiming a compromise of the FBIJobs.gov portal and an impact to employee personally identifiable information. Investigators have not determined whether the initial point of compromise was a third-party provider or part of the FBI’s own enterprise, according to the agency. The FBI said it is working with third parties that support FBIJobs.gov as the investigation continues.
Evidence published outside the FBI has given the incident considerably more weight than a typical criminal leak claim. ShinyHunters provided journalists with a spreadsheet containing roughly 5,000 records it says came from the intrusion. Reuters independently verified personal details belonging to more than 22 people in that dataset by comparing the information with credit records and previous data leaks. Reuters also matched career information or job titles for eight people against court filings, news reports, public professional profiles, and social media posts. The outlet could not authenticate the spreadsheet in full or establish that all listed assignments are current.
The records reviewed by Reuters contain names, addresses, telephone numbers, dates of birth, Social Security numbers, emergency-contact information, field-office assignments, and job information. Reuters found 14 people identified with China-related work, nine with Russia-related roles, three with Iran- or Hezbollah-focused intelligence work, 18 associated with interception, covert access, surveillance, or clandestine technical operations, and another 11 listed in human intelligence roles. Some of the unit names were sensitive or had received little previous public attention.
404 Media separately reported that the sample included people connected to the FBI’s Remote Operations Unit, a little-publicized technical unit involved in developing or using tools that remotely access target devices. The publication had previously received a roughly 5,000-record sample containing names, addresses, telephone numbers, and information related to employees’ spouses. The presence of operational assignments alongside personal and family information is one of the clearest reasons the incident carries risks far beyond conventional identity theft.
FBIJobs Sits Close to Sensitive Personnel Systems
The architecture documented for FBIJobs.gov helps explain how a recruiting platform could contain or interact with data carrying much greater sensitivity than a typical careers website. A Department of Justice privacy assessment published in 2022 describes the FBI Candidate Gateway as an internet-accessible recruiting and hiring system hosted on AWS GovCloud. At that time, the system used Oracle PeopleSoft HRS 9.2, Oracle Database 19c, and Drupal, and it integrated with the FBI’s internal HR Source environment.
The same document says HR Source resides on FBINet and that the Candidate Gateway exchanged information with it using accredited cross-domain mechanisms. Applicant profile information, completed applications, employment questionnaires, messages to FBI recruiting personnel, and offers could move from the internet-facing Candidate Gateway into HR Source. Information could also move in the other direction, including job postings, application information, questionnaires, recruiter communications, and employment offers.
The Candidate Gateway was documented as collecting sensitive but unclassified PII including names, Social Security numbers, dates of birth, citizenship information, addresses, phone numbers, applicant information, employment records, and some health-related information. Once an application was submitted, the 2022 assessment said application PII was transferred into HR Source, with the Candidate Gateway later purging that information subject to retention requirements.
That documentation does not establish what the FBIJobs environment looked like on September 21, 2026. Four-year-old architecture records cannot prove which software releases were still running, whether the same integrations remained in place, or which systems ShinyHunters accessed. They do establish that the recruiting environment historically had direct functional ties to internal personnel processes and that PeopleSoft and AWS GovCloud were part of the documented design.
That distinction has become central to the incident. ShinyHunters claims it moved from the PeopleSoft environment into FBI-managed AWS GovCloud systems and accessed services associated with human resources, MedLink, and criminal justice information. BleepingComputer reported those claims but said it could not independently verify the alleged zero-day, lateral movement, or two-to-three-terabyte data haul. The FBI has made no public statement confirming access to those internal services.
A Claimed New PeopleSoft Zero-Day
ShinyHunters says the intrusion began Monday night after the group found another PeopleSoft zero-day and immediately used it against FBI infrastructure. The group told BleepingComputer that the vulnerability provided remote code execution and remained unpatched at the time of the attack. It also claimed that the same flaw was being used against other organizations, including Fortune 500 companies. None of those technical claims has been independently substantiated.
As of September 24, Oracle has not published a public security alert identifying a new PeopleSoft vulnerability tied to the FBI incident. The relevant public Oracle alert remains CVE-2026-35273, disclosed June 10, which affects the Environment Management component in supported PeopleTools 8.61 and 8.62 releases. Oracle rates the flaw at CVSS 9.8 and says it can be exploited remotely without authentication to achieve remote code execution.
That earlier flaw matters since Google Threat Intelligence Group and Mandiant already tied ShinyHunters activity to its exploitation. Google observed activity attributed to UNC6240, which it associates with ShinyHunters, between May 27 and June 9. The exploitation occurred before Oracle’s June 10 alert, meaning CVE-2026-35273 was used as a zero-day during the campaign.
Google’s investigation documented attackers targeting exposed PSEMHUB endpoints, deploying customized MeshCentral agents, mapping internal PeopleSoft environments, executing lateral-movement scripts, staging stolen information, and connecting infrastructure back to the ShinyHunters data-leak operation. Google notified more than 100 organizations whose addresses corresponded with potentially vulnerable endpoints, with 68 percent of those organizations operating in higher education.
There is no evidence at this point that CVE-2026-35273 was the vulnerability used against FBIJobs.gov. ShinyHunters is explicitly claiming that it found a different PeopleSoft flaw. The FBI’s 2022 documentation confirms PeopleSoft was part of the Candidate Gateway architecture, but it does not identify the PeopleTools version running during the September 2026 incident. Connecting the FBI intrusion to CVE-2026-35273 without further evidence would go beyond what is publicly established.
The Data May Carry Counterintelligence Value
The clearest concern in the material reviewed so far is the combination of personal identifiers and operational information. A name or telephone number alone has limited intelligence value. A record tying the same person to a specific counterintelligence target, surveillance capability, human intelligence program, or technical unit can provide an adversary with a much more useful profile.
Reuters found personnel listed in China intelligence and technology-transfer roles, Russia operations, Iran and Hezbollah intelligence work, telecommunications interception, covert-access programs, clandestine technical operations, electronic surveillance, and human intelligence management. Reuters could not establish that each assignment remained current, but it independently corroborated career information for several people.
Current assignments are also not the only concern. Historical records can reveal organizational structures, relationships between field offices and headquarters units, previous areas of responsibility, and personnel who have worked in sensitive programs. Combined with commercial data, social media, previous leaks, and open records, that information can support targeting far beyond the original dataset.
Emergency contacts and spouse information add another layer of exposure. Reuters reported emergency-contact details in the spreadsheet, and 404 Media said its sample contained information about employees’ spouses. Family members can present an alternate route for social engineering, impersonation, harassment, or attempts to collect information about an employee whose own security practices are harder to defeat.
Applicants also represent a valuable target set. FBI applicants expect communications about interviews, background checks, scheduling, medical requirements, and hiring decisions. The FBI’s privacy documentation confirms that the Candidate Gateway handled applicant contact information, questionnaires, supporting material, and communications with recruiters. Someone possessing real application information could use that context to create convincing impersonation attempts directed at people already expecting contact from the bureau.
ShinyHunters Says the Attack Was Retaliation
ShinyHunters says the operation was driven by a dispute with the FBI rather than a conventional ransom demand. The group objected to FBI reporting published in May describing ShinyHunters as a cybercriminal organization involved in large-scale data theft and extortion and warning that actors using the name can make real or exaggerated claims of access, harass victims and their relatives, conduct swatting, or claim to possess compromising material.
The group denies those parts of the FBI’s characterization and has demanded that the bureau correct or remove them. BleepingComputer and CBS reported that ShinyHunters gave the FBI one week to do so. The group has described the action as nonfinancial and has rejected the FBI’s use of terms such as ransom, coercion, and extortion to describe its conduct.
ShinyHunters told Reuters on Wednesday that it was trying to prevent the 5,000-record sample from circulating further and said it would not release more data at that time. The group has previously told Reuters that it obtained material related to employee and applicant vetting, contracted background investigations, and sensitive medical information, but Reuters has not verified what other records the group possesses.
That uncertainty is significant given the group’s own stated data volume. Two to three terabytes would represent far more information than the spreadsheet reporters have reviewed, but there is currently no independent evidence confirming the size of the alleged collection. The same applies to the claim that the attackers obtained records covering almost every FBI employee and applicant.
What Is Confirmed and What Is Still a Claim
The strongest publicly supported facts are narrower than some of the early coverage suggested. The FBI is investigating ShinyHunters’ claim of a compromise involving FBIJobs.gov and possible employee PII exposure. ShinyHunters supplied journalists with thousands of records containing information that can be tied to real FBI and Justice Department personnel. Reuters has independently corroborated personal details for more than 22 individuals and career information for eight, and reporting from Reuters and 404 Media indicates that the dataset contains information associated with sensitive units and job functions.
Reporting also indicates that FBIJobs.gov was disrupted following the incident. CBS reported that the application site and Special Agent Applicant Portal displayed a system-unavailable notice Tuesday, and The Record reported that ShinyHunters had replaced material on the site with imagery associated with the group. BleepingComputer published a screenshot supplied by ShinyHunters showing an alleged defacement. The FBI’s own September 23 statement does not independently confirm the defacement.
Several larger claims remain open. There is no public confirmation that ShinyHunters stole two to three terabytes, obtained records on almost every FBI employee and applicant, reached the Criminal Justice Information Services environment, accessed MedLink, moved laterally across FBI-managed AWS GovCloud infrastructure, or used an undisclosed PeopleSoft zero-day. There is also no Oracle advisory or independent technical analysis confirming the new vulnerability claimed by the group as of September 24.
The incident is serious without treating those unverified claims as established facts. A dataset already shown to contain genuine personnel information and apparent intelligence assignments can create privacy, operational-security, and counterintelligence risks on its own. What remains unknown is whether the 5,000-record sample represents the main exposure or a small portion of a far larger compromise.
The next major development will likely come from forensic findings, a new FBI disclosure, or an Oracle security advisory. Until one of those surfaces, the safest assessment is that ShinyHunters has presented credible evidence that it obtained sensitive FBI-related personnel information, but the entry point, total scope, affected systems, and claimed PeopleSoft zero-day remain under investigation.
How Can Netizen Help?
Founded in 2013, Netizen is an award-winning technology firm that develops and leverages cutting-edge solutions to create a more secure, integrated, and automated digital environment for government, defense, and commercial clients worldwide. Our innovative solutions transform complex cybersecurity and technology challenges into strategic advantages by delivering mission-critical capabilities that safeguard and optimize clients’ digital infrastructure. One example of this is our popular “CISO-as-a-Service” offering that enables organizations of any size to access executive level cybersecurity expertise at a fraction of the cost of hiring internally.
Netizen also operates a state-of-the-art 24x7x365 Security Operations Center (SOC) that delivers comprehensive cybersecurity monitoring solutions for defense, government, and commercial clients. Our service portfolio includes cybersecurity assessments and advisory, hosted SIEM and EDR/XDR solutions, software assurance, penetration testing, cybersecurity engineering, and compliance audit support. We specialize in serving organizations that operate within some of the world’s most highly sensitive and tightly regulated environments where unwavering security, strict compliance, technical excellence, and operational maturity are non-negotiable requirements. Our proven track record in these domains positions us as the premier trusted partner for organizations where technology reliability and security cannot be compromised.
Netizen holds ISO 27001, ISO 9001, ISO 20000-1, and CMMI Level III SVC registrations demonstrating the maturity of our operations. We are a proud Service-Disabled Veteran-Owned Small Business (SDVOSB) certified by U.S. Small Business Administration (SBA) that has been named multiple times to the Inc. 5000 and Vet 100 lists of the most successful and fastest-growing private companies in the nation. Netizen has also been named a national “Best Workplace” by Inc. Magazine, a multiple awardee of the U.S. Department of Labor HIRE Vets Platinum Medallion for veteran hiring and retention, the Lehigh Valley Business of the Year and Veteran-Owned Business of the Year, and the recipient of dozens of other awards and accolades for innovation, community support, working environment, and growth.
Looking for expert guidance to secure, automate, and streamline your IT infrastructure and operations? Start the conversation today.


Leave a comment