FBI Recruitment Portal Breached? ShinyHunters Demands a Report Be Pulled
A defaced FBI recruitment portal, 2 to 3 TB of allegedly stolen data, and a one-week ultimatum. That is the situation the FBI would be facing following a breach claimed by the ShinyHunters group. The entry point? A zero-day flaw in Oracle PeopleSoft. Here’s what we know.
The ShinyHunters group regularly makes headlines, and very often it is because of attacks against major organizations. For example, last March, I published an article about the breach of the European Commission, where 350 GB of data had been stolen from AWS servers. This time, the target is different: the FBI.
The ShinyHunters hackers claim they discovered a zero-day vulnerability in Oracle PeopleSoft and immediately exploited it against the U.S. federal agency. For those who do not know PeopleSoft (I did not either), it is an Oracle software suite used for human resources, recruitment, and payroll management.
At this stage, the FBI has neither confirmed nor denied the intrusion, but an investigation is underway. Oracle has not commented either. But here is ShinyHunters’ version.
A foothold: the FBI recruitment portal
According to ShinyHunters, the flaw was discovered on the evening of Monday, September 21, and exploited shortly after. It allegedly allowed remote code execution on an FBI server, notably on a server associated with the domain apply.fbijobs.gov.
The hackers then claim they moved laterally to other FBI-managed infrastructure, including systems hosted on AWS GovCloud, before downloading between 2 and 3 TB of data. Three services would be affected: Criminal Justice (CJ), Human Resources (HR), and Medlink. In each case, access reportedly came from the FBI’s PeopleSoft environment.
The FBI Jobs portal was also briefly defaced with a message stating that the site had been “taken over by ShinyHunters”. The message referred to the theft of personal and health-related data concerning employees, former employees, and applicants. Among this data, there would reportedly be names, addresses, and phone numbers of agents and their spouses.
No ransom, but a report must be taken down
"We have compromised the FBI. We hold highly sensitive data on nearly EVERY FBI agent and the people who have applied for a job at the FBI", the message reads. The deadline given is one week, otherwise the data would be published.
ShinyHunters is not demanding money. That is surprising. In reality, the hackers sent a message to FBI Director Kash Patel and to Brett Leatherman, who heads the Cyber Division, to make a demand. They want the FBI FLASH report published in Q2 2026 to be corrected or removed.
What is this report? The document is an alert published on May 15 following the attack on Instructure’s Canvas e-learning platform. The FBI noted, among other things, the group’s habit of exaggerating the scope of access it obtained in order to pressure victims into paying. An allegation the hackers dispute... while claiming to have hacked the FBI. Incidentally, the FBI has already been targeted this year: in March, the Iran-linked Handala group hacked Kash Patel’s personal email account.
PeopleSoft, a favored target for ShinyHunters
ShinyHunters has shown a particular interest in Oracle’s PeopleSoft solution, and this is not the first time they have exploited a flaw in it. In June 2026, Oracle published a security advisory for CVE-2026-35273 (CVSS score of 9.8): a very nice unauthenticated remote code execution vulnerability exploitable through the Environment Management component of PeopleTools 8.61 and 8.62. According to a Google report, ShinyHunters had exploited it as a zero-day between May 27 and June 9, targeting PSEMHUB endpoints. More than 100 organizations were alerted, including 68% in higher education.
Does this attack against the FBI really rely on a new flaw? Or is it a bypass of the June patch, or an unpatched server? It is impossible to say for now, but the lead is an interesting one.


