In short: On the evening of September 21, 2026, hacking group ShinyHunters claimed to have breached FBIjobs.gov — the FBI's recruitment and employee data portal — via a zero-day flaw in Oracle PeopleSoft. The group says it exfiltrated 2–3 TB of data, including home addresses, phone numbers, spousal Social Security numbers, and security-clearance details for "nearly all FBI agents." The FBI has confirmed it is investigating but has not confirmed the breach's scope. Here is what is known and what it means for data security.
What happened
On September 21–22, 2026, ShinyHunters posted claims on hacking forums that it had breached FBIjobs.gov — the portal the FBI uses to manage job applications and personnel records. The group passed data samples to TechCrunch, 404 Media, and other outlets; journalists compared portions of the samples against public records and found the data appeared authentic. However, the total claimed volume has not been independently verified by security researchers.
The FBI's only official statement: "The FBI is aware of claims of unauthorized activity affecting FBIjobs.gov and is currently investigating." The bureau did not confirm that data was stolen. Oracle and Amazon have not commented on the claimed attack path.
The attack is not financially motivated. ShinyHunters stated their demand publicly: the FBI must retract or formally correct a May 2026 FBI threat report that characterised the group's methods, within seven days. "This is NOT financially motivated," the group stated in communications shared with journalists. For background on how threat actors like ShinyHunters operate, see our cybersecurity blog.
How attackers got in (according to ShinyHunters)
The group claims the initial access vector was a zero-day vulnerability in Oracle PeopleSoft — an HR management platform used broadly by US federal agencies for personnel management and job-application processing. SecurityWeek researchers linked this operation to CVE-2026-35273, the same Oracle PeopleSoft flaw ShinyHunters reportedly exploited in a June 2026 attack against a separate organisation.
After initial access, the group claims it moved laterally into AWS GovCloud — Amazon's cloud environment for US government sensitive workloads — gaining access to HR systems, the MedLink medical records system, and criminal justice and security-clearance databases.
This described attack path has not been independently confirmed. Oracle and Amazon have made no public statements about the incident.
What ShinyHunters claims was stolen
The group claims to have exfiltrated 2–3 TB of data. Samples shared with journalists contain approximately 5,000 records; portions of those samples, cross-checked against public sources, appeared to match real individuals. The claimed data categories include:
- Full names, home addresses, dates of birth, and phone numbers of FBI agents;
- Spouses' personal data, including Social Security numbers;
- Educational history, prior government service records, and security-clearance levels;
- Medical records from the MedLink system;
- Application data from individuals who applied through FBIjobs.gov.
Home addresses and family data are the most immediately dangerous category for affected individuals. For a law enforcement officer, a leaked home address is not an abstract breach — it is a direct physical-safety risk. Security-clearance metadata, meanwhile, has significant intelligence value for foreign state actors seeking to identify or approach individuals with access to classified information.
Who ShinyHunters are and why this matters
ShinyHunters is one of the most prolific data theft and extortion groups of the 2020s. Confirmed or attributed operations include: the 2024 Snowflake platform breach used to steal Ticketmaster records (560 million) and AT&T subscriber data (30 million accounts); and the August 2026 McKesson breach in which the group claimed 284 million patient records. The group has no established state affiliation and operates for financial and reputational ends.
This incident sets a significant precedent: ShinyHunters has directly targeted the agency investigating it. Regardless of the final confirmed scope, the attack highlights a systemic problem: government HR portals handling sensitive employee data for law enforcement agencies are susceptible to the same attack techniques used against commercial platforms. Stay updated on security incidents in our news section.
What to do to protect your data
This incident primarily affects US federal employees. But it illustrates principles that apply to anyone whose data is held by organisations they cannot fully control.
You cannot control how an organisation protects your data. You can, however, limit the blast radius of someone else's breach:
- Use unique passwords for every service. A breached FBIjobs.gov password should not unlock your email or banking account. A password manager handles this automatically.
- Enable two-factor authentication. With 2FA active, a stolen password alone is not enough to gain access — the attacker needs the second factor too.
- Watch for suspicious activity. Turn on SMS or push alerts for account logins and financial transactions, and act immediately if something looks wrong.
- Encrypt your traffic on all devices. When a server you trusted is compromised, connection-level encryption prevents data from being intercepted in transit. LiMP VPN provides exactly that layer — protecting you from traffic interception and network-level surveillance on every connection.
Digital security is built in layers. Strong unique passwords, 2FA, and an encrypted channel together significantly narrow what an attacker can do with stolen credentials. See LiMP VPN plans — starting at $0.99 per month.
Sources
- Anti-Malware.ru — ShinyHunters Claims FBI Breach (Sep 23, 2026)
- TechCrunch — ShinyHunters claims it breached the FBI (Sep 22, 2026)
- The Hacker News — ShinyHunters Claims FBI Breach (Sep 22, 2026)
- Хакер — ShinyHunters взломала ФБР (Sep 23, 2026)
- SecurityWeek — ShinyHunters Claims FBI Hack, Demands Retraction (Sep 22, 2026)
