Security News

ShinyHunters Breaches FBI Jobs Portal in Apparent Retaliation Move

The Register · 26 Sept 2026
Key Takeaway If your business relies on Oracle PeopleSoft or similar enterprise software, ensure it is fully patched and monitored, since attackers are actively exploiting zero-day flaws in these platforms to breach even high-profile organisations.

The data theft group ShinyHunters, known for stealing sensitive records from cancer patients, students, and cruise line customers, has claimed responsibility for breaching the FBI's FBIJobs.gov portal. The FBI confirmed the breach on Friday, saying it is investigating the incident and working with third-party providers who support the portal, though the exact point of entry remains unclear.

According to ShinyHunters, the attackers exploited a zero-day flaw in Oracle PeopleSoft software used by the portal, then moved into FBI-managed servers hosted on AWS GovCloud. The group claims to have obtained personnel files on current, former, and prospective FBI employees, including home addresses, phone numbers, email addresses, Social Security numbers, job titles, and emergency contacts. Unlike many of the group's past attacks, this one was reportedly not driven by a ransom demand.

ShinyHunters told The Register the breach was intended as retaliation against claims made about the group in an FBI cyber alert, framing the attack as a reputational move rather than a financial one. The FBIJobs.gov portal remained offline as of Friday while the investigation continues.

data breach ShinyHunters FBI zero-day exploit extortion

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.