NewsTradingSentimentEventsCommunityBriefing
Tech

ShinyHunters Claims Breach of FBI Jobs Portal

By Tech Desk · · 2 min read
A dark server rack with blinking status lights in a dim room.

Extortion group ShinyHunters alleges it stole sensitive data from FBI agents and applicants via an Oracle vulnerability.

Key points

  • ShinyHunters claims to have stolen data on FBI agents and applicants via an Oracle PeopleSoft zero-day exploit.
  • The FBI confirmed it is investigating unauthorized activity affecting its jobs website, FBIjobs.gov.
  • Experts note the group uses social engineering and identity abuse rather than brute-force attacks.

The cyber extortion group ShinyHunters has claimed to have compromised the U.S. Federal Bureau of Investigation, alleging it stole sensitive data belonging to current agents and job applicants. The group posted a statement on its dark web site asserting that it holds information on nearly all FBI personnel, including those in Special Agent roles and other administrative positions. They specifically named internal services such as Criminal Justice and Human Resources as targets of their intrusion.

The FBI has acknowledged the incident, stating in a statement to Reuters that it is aware of claims regarding unauthorized activity affecting its jobs website, FBIjobs.gov. The agency said it is currently investigating the matter. This claim marks a significant escalation in the group's operations, as they have previously targeted educational institutions and other organizations but had not publicly claimed a breach of a major law enforcement body until now.

Alleged use of zero-day exploit

A spokesperson for ShinyHunters told The Register that the group exploited a newly discovered zero-day vulnerability in Oracle PeopleSoft to gain remote code execution on the FBI's systems. They claimed this allowed them to deface the FBI's public jobs site with a banner stating it had been seized. However, the site now displays a standard maintenance message, reading that scheduled maintenance is underway. While the group names a specific vulnerability, there are no independent technical details yet confirming the existence of a pre-authenticated remote code execution flaw in PeopleSoft.

Security experts note that ShinyHunters has previously weaponized similar flaws, such as CVE-2026-35273, to break into enterprise networks for extortion. The group’s recent playbook has shifted away from brute-force perimeter attacks toward abusing trusted identity paths, such as help-desk social engineering and malicious OAuth applications. This approach allows attackers to move laterally within networks using legitimate credentials, making detection more difficult for defenders.

Dispute over prior threats

The breach claim appears linked to a May 2026 public service announcement by the FBI, which detailed ShinyHunters' targeting of Canvas, an online learning management system. The FBI had urged victims not to pay ransoms in that advisory. ShinyHunters responded by calling the agency's allegations "substantial false allegations" and accused the FBI of spreading disinformation to disrupt their operations. They also rejected claims that they are part of a larger decentralized collective, dismissing such narratives as industry propaganda.

Expert analysis on attribution

Etay Maor, VP of threat intelligence at Cato Networks, described the claim as an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups. He noted that while nation-states have previously compromised law enforcement organizations, such as in the 2015 OPM breach, a cybercrime brand publicly claiming an FBI compromise is distinct. Maor pointed out a timestamp on the group's post that suggests activity in Asia, a detail investigators may examine alongside technical evidence to determine the group's true location.

Maor also emphasized that ShinyHunters is a resilient criminal brand that has outlasted takedowns and arrests by evolving its methods and attracting new operators. He suggested the group is not a fixed set of people or infrastructure, but rather a flexible network. The larger lesson for organizations, according to Maor, is the need to secure identity paths and trusted integrations, as these are increasingly the primary vector for sophisticated cyber extortion campaigns.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories