← FBI

2026 FBI — ShinyHunters PeopleSoft zero-day claim; employee/applicant PII/PHI alleged (unverified)

2026 Unknown records affected Share on X

Data compromised

Actor claim (unverified): 2–3 TB including PII/PHI on current and former FBI employees, applicants, and spouses (names, addresses, phones, DOB alleged in samples). Named services: Criminal Justice, HR, Medlink. No FBI-attested census. Jobs portals were unavailable / previously showed actor defacement per trade press.

Technical writeup

Unverified leak-site / extortion claim — ShinyHunters claimed September 21–22, 2026 that it exploited a new Oracle PeopleSoft zero-day for RCE on an FBI server, moved laterally into AWS GovCloud, and stole 2–3 TB including employee/applicant PII/PHI (Criminal Justice, HR, Medlink alleged). Group defaced apply.fbijobs.gov (screenshot to press); site later showed maintenance / portals unavailable. 404 Media reviewed ~5,000-record sample and matched some phone numbers to public records; Reuters partially matched ≥9 sample rows to credit-bureau/prior-breach data but could not prove FBI-system provenance. FBI had not confirmed at indexing; BleepingComputer/TechCrunch note no independent verification of the zero-day or volume. Actor framed attack as retaliation for a May 2026 FBI FLASH on ShinyHunters (one-week demand to revise/remove; “not financially motivated”). recordsAffected 0 (no attested headcount); companyConfirmed false.

Root cause

Unverified ShinyHunters extortion claim: alleged Oracle PeopleSoft zero-day RCE → lateral movement into FBI-managed AWS GovCloud (Sep 21–22, 2026)

References