On September 22, 2026, the ShinyHunters group claimed it had compromised systems of the U.S. Federal Bureau of Investigation (FBI) and stolen personal data of current and former employees, as well as job applicants. The FBI confirmed that it is investigating “unauthorized activity affecting the fbijobs.gov portal,” but emphasized that the initial access vector and the true scope of the leak have not yet been established. Organizations using Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 should immediately verify that they have installed the patch for CVE-2026-35273—a critical vulnerability with a CVSS score of 9.8 that is being mentioned in connection with this incident.
What the hackers claim and what has been officially confirmed
According to a statement by ShinyHunters published on their darknet resource, the group gained access to the FBI’s HR, MedLink, Criminal Justice and other internal systems. The hackers also claim they defaced the FBI Jobs site by placing a banner reading “This site has been seized by ShinyHunters”—an ironic reference to splash pages law enforcement agencies use when they seize cybercriminal infrastructure. At the time of publication, the apply.fbijobs.gov portal displays a maintenance notice.
However, the FBI’s official position is much more restrained. The Bureau acknowledged that it had received a report of a compromise of the fbijobs.gov portal and possible impact on employees’ personal data, but noted that the point of entry—whether a third-party contractor or its own infrastructure—remains undetermined. The FBI has not confirmed the fact of a data leak, the site defacement, or the identity of the attackers.
Claims about the theft of 2–3 terabytes of data, access to AWS GovCloud, compromise of internal services, and possession of information on “almost all” FBI employees have not been confirmed by any primary source. 404 Media reported that it received from the hackers a sample of roughly 5,000 records, some of which were partially verified via open sources; however, the overall authenticity of the dataset has not been established.
CVE-2026-35273: a critical vulnerability, not a “new zero‑day”
A ShinyHunters representative told reporters they had used “a new zero-day in Oracle PeopleSoft.” However, this assertion does not match the timeline. The CVE-2026-35273 vulnerability was publicly documented by Oracle on June 10, 2026—more than three months before the reported incident. According to the Oracle security advisory, the vulnerability affects the Updates Environment Management component in Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62.
Key technical characteristics of the vulnerability, according to the Oracle risk matrix:
- CVSS 3.1: 9.8 (critical)
- Attack vector: network, via HTTP
- Authentication: not required
- User interaction: not required
- Impact: high on confidentiality, integrity and availability
- Result of exploitation: remote code execution (RCE)
The patch is included in the Oracle Critical Patch Update for June 2026. The vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on June 12, 2026, with a remediation deadline of June 15, 2026. Thus, this is not a zero-day, but a critical vulnerability with an available patch that should have been applied back in June.
According to initial reports, ShinyHunters had used CVE-2026-35273 to attack corporate networks as early as June 2026. However, no official source confirms that this particular vulnerability was used to gain access to FBI systems.
We have previously written about the active exploitation of vulnerabilities in Oracle products that have been added to the CISA KEV catalog—this incident further confirms that the vendor’s products remain a priority target for attackers.
Context: motivation and group profile
ShinyHunters claims the attack was a response to an FBI public warning dated May 15, 2026, in which the Bureau described the group’s tactics in attacks on the Canvas learning management system and urged victims not to pay ransom. In the same warning, the FBI noted that ShinyHunters uses “real or exaggerated claims of access to sensitive information” to pressure victims—a detail worth keeping in mind when assessing the group’s current claims.
The hackers gave the FBI a week to “correct or remove” the May report, without specifying whether they intend to publish any stolen data. The group also rejected any connection to The Com community—a decentralized coalition of English-speaking cybercriminals that law enforcement reports have associated with ShinyHunters.
As noted by Etay Maor of Cato Networks, ShinyHunters is a resilient criminal brand that has survived arrests, forum takedowns and infrastructure seizures by adapting its methods and attracting new participants. The group’s current tactics have shifted from purely technical perimeter breaches to abusing trusted identity paths: social engineering via support desks, malicious OAuth applications, and stolen SaaS integration tokens.
Practical recommendations
- Oracle PeopleSoft: if the patch from Oracle’s June 2026 Critical Patch Update has not yet been applied to PeopleTools versions 8.61 and 8.62, it must be installed immediately. The remediation deadline in the CISA KEV catalog expired on June 15, 2026.
- Audit of external portals: organizations using PeopleSoft for HR or recruiting portals accessible from the internet should review logs for signs of anomalous activity since June 2026.
- Protecting the identity chain: given the tactics attributed to ShinyHunters, tighten controls over password reset procedures via support desks, audit OAuth applications with access to corporate data, and rotate SaaS integration tokens.
- Leak monitoring: organizations whose employees have applied for jobs with the FBI should consider notifying them of the potential risk of personal data compromise before final investigation results are available.
The incident involving the alleged FBI hack still raises more questions than answers: the scale of the leak, the initial access vector, and even the attackers’ identity remain unconfirmed. However, one key point is confirmed—the critical Oracle PeopleSoft vulnerability CVE-2026-35273 with a CVSS score of 9.8 is being actively exploited and has an available patch. For organizations using PeopleTools 8.61 or 8.62, applying this patch is not a recommendation but a mandatory action that is already three months overdue.