The ShinyHunters FBI breach is a claimed hack of the FBIJobs.gov careers portal on September 21, 2026, which the FBI formally treated as a cybersecurity incident the next day. The group says it stole 2–3 TB of data on agents and job applicants through a critical Oracle PeopleSoft flaw (CVE-2026-35273). If you’ve ever applied to the FBI or work there, you should assume your personal details may be exposed and lock down your identity now.
Here’s what happened, what data is at risk, how the attack worked, and the exact steps you can take today.
| Detail | What we know | |
|---|---|
| Breach date | September 21, 2026 (per NBC News) | |
| Claimed by | ShinyHunters, a global cyber-extortion group | |
| Target | FBIJobs.gov applicant portal (run with third-party providers) | |
| Claimed data | 2–3 TB on current, former and prospective FBI staff | |
| Confirmed data types in affected system | SSNs, dates of birth, phone numbers, addresses, emergency contacts | |
| Vulnerability | Oracle PeopleSoft CVE-2026-35273, CVSS 9.8 | |
| Current status | Portals offline; FBI investigation ongoing | |
What Happened in the ShinyHunters FBI Breach
On September 22, 2026, ShinyHunters announced it had hacked the FBI’s jobs site and defaced FBIJobs.gov with its logo. It claimed to hold sensitive data on “almost all” FBI agents plus a large set of applicant records.
The same day, the FBI designated the matter a cybersecurity incident, according to a Justice Department notice to lawmakers reported by NBC News. The bureau’s first public line was brief: it was “aware of claims” and investigating.
By the following week, both applicant portals were still down. Help Net Security reported that apply.fbijobs.gov and the special agent application page remained offline as of September 28.
Has the breach been verified?
Partly. Reuters and 404 Media reported that samples from the hackers matched real FBI and Justice Department personnel. NBC News said a former agent confirmed a sample document about them was authentic.
What’s still unverified is the group’s bigger claim. ShinyHunters says it pivoted from the jobs portal into other FBI systems, including HR, medical (MedLink) and cloud servers, but it hasn’t shown proof of that.
ShinyHunters FBI Breach Timeline
Here’s how events unfolded, from the original zero-day to the arrest announcement.
| Date (2026) | Event | |
|---|---|
| May 15 | FBI issues a public warning about ShinyHunters attacks on learning platforms | |
| May 27 – June 9 | PeopleSoft flaw exploited as a zero-day | |
| June 10 | Oracle releases an emergency security alert and patch | |
| June 12 | CISA adds CVE-2026-35273 to its Known Exploited Vulnerabilities list | |
| September 15 | Dutch police arrest a suspected ShinyHunters member in Amsterdam | |
| September 21 | ShinyHunters breaches FBIJobs.gov | |
| September 22 | Group claims the hack; FBI designates it a cybersecurity incident | |
| September 25 | FBI tells staff to assume their personal data may be exposed | |
| September 28 | Portals still offline; group says it won’t publish the data | |
| September 29 | Arrest made public; FBI issues a video warning to the group | |
What Data Was Exposed
The FBI hasn’t said how many people are affected. Investigators are still working that out.
What we do know is what the affected system holds. According to the Justice Department notice, it contains:
- Social Security numbers
- Dates of birth
- Phone numbers and home addresses
- Emergency contact information
TechCrunch also reported the hackers claimed names, home addresses and phone numbers of agents and their spouses. The FBI told employees on Friday, September 25, to work on the premise that their personal information may have been taken and to report unsolicited contacts.
That makes this more than an embarrassment. For law enforcement staff, exposed home addresses are a physical safety issue, not just a fraud risk.
Who Is ShinyHunters?
ShinyHunters is an international cyber-extortion group with members around the world. It’s known for large-scale data theft, then threatening to leak what it steals unless victims pay.
The FBI’s May warning described the group’s pressure tactics in detail. They include threatening messages, harassing phone calls and texts, and false claims about holding embarrassing material.
Stolen data typically ends up on leak sites hosted on the Tor network. The group has hit companies in tech, finance and retail, and Rapid7 linked it to the wave of PeopleSoft attacks on universities earlier this year.
How ShinyHunters Got In: The PeopleSoft Flaw
The attack path runs through Oracle PeopleSoft, a widely used HR and campus management system.
| Vulnerability detail | Value | |
|---|---|
| CVE | CVE-2026-35273 | |
| Severity | CVSS 9.8 (Critical) | |
| Affected versions | PeopleSoft PeopleTools 8.61 and 8.62 | |
| Component | Environment Management Hub (PSEMHUB) | |
| Attack type | Unauthenticated remote code execution over HTTP | |
| Oracle alert released | June 10, 2026 | |
| Added to CISA’s exploited list | June 12, 2026 | |
A “patched” bug that still worked
Here’s the uncomfortable part. Oracle issued an emergency fix in June, after attackers exploited the flaw as a zero-day between May 27 and June 9.
According to Help Net Security, the FBI-linked attack used a modified exploit that slipped past firewall rules with a simple URL-encoding trick. Blocking the plain path wasn’t enough when the attacker could encode one letter of it.
Rapid7 tied the original wave to ShinyHunters (tracked as UNC6240). It found more than 100 targeted organizations, and 68% were colleges and universities.
Why ShinyHunters Targeted the FBI
This wasn’t a typical ransom play. The group said its goal was to force the FBI to retract a public warning about it.
That warning was an FBI public service announcement from May 15, 2026, describing ShinyHunters attacks on learning management systems. The hackers set a September 29 deadline for its removal.
Then the group backed down. On September 28, a spokesperson told NBC News it would not publish the stolen FBI data and called the episode “a marketing campaign.”
The Dutch Arrest and the FBI’s Warning
On September 29, Dutch police said they had arrested a 24-year-old Amsterdam man on September 15, suspected of being a ShinyHunters hacker. Dutch authorities and the FBI described him as a leader of the group.
The FBI didn’t link that arrest directly to its own breach, which happened after he was detained. Instead, Cyber Division Assistant Director Brett Leatherman used it to warn the rest of the group in a video message.
His advice to the remaining members was blunt: “reach out first while the choice is still yours.”
A rough year for FBI security
CBS News counts this as the third significant cyber incident affecting the FBI in 2026. Earlier events included suspicious activity in March and an Iranian-linked attack on Director Kash Patel’s email.
What You Should Do If You Applied to the FBI
If you’ve submitted an application through FBIJobs.gov, act as if your data is exposed. Most of these steps are free and take under an hour.
- Freeze your credit with Equifax, Experian and TransUnion. A freeze blocks new accounts in your name.
- Get an IRS Identity Protection PIN so nobody can file a tax return with your SSN.
- Turn on multi-factor authentication for email, banking and any account tied to your application.
- Treat surprise calls, texts and emails with suspicion, especially ones that mention the FBI, your application or a “security review.”
- Verify any contact through a known number before sharing details or clicking a link.
- Report suspicious activity to the FBI’s Internet Crime Complaint Center at ic3.gov.
Watch for voice and video scams too. ShinyHunters is known for phone-based social engineering, and our explainer on deepfake-as-a-service shows how cheap convincing impersonation has become.
Warning signs of a follow-on scam
- A caller claims to be from “FBI HR” and asks you to confirm your SSN
- A message says your application needs “re-verification” through a link
- Someone threatens to leak your data unless you pay
- An unexpected password reset arrives for an account you rarely use
What Businesses Running PeopleSoft Should Do
If your organization uses PeopleSoft, this breach is a direct warning. ShinyHunters claims it’s using the same technique against large companies.
Security researchers at Rapid7 and Oracle recommend:
- Apply Oracle’s CVE-2026-35273 patch immediately, and confirm it actually took effect
- Disable the Environment Management Hub or remove the PSEMHUB application if you don’t need it
- Block external access to vulnerable endpoints at the network edge, including encoded path variations
- Limit access to trusted internal networks only
- Monitor outbound SMB traffic (TCP 445) to unknown destinations
- Hunt for signs of compromise even after patching
HR systems hold the most sensitive data in any company. If you’re reviewing long-term defenses, our guide to post-quantum cryptography covers how encryption standards are changing, and our look at palm recognition shows where biometric access is heading.
What the FBI Has Said So Far
The FBI’s public statements have been careful. It hasn’t confirmed the scale of the theft, and it hasn’t said the hackers reached systems beyond the jobs portal.
In its fuller statement, the bureau said it is “actively and aggressively investigating” and working with the third-party providers behind FBIJobs.gov. A later statement said it had sent multiple bureau-wide messages within 24 hours of public reporting.
Not everyone inside the FBI was satisfied. NBC News reported that some employees were frustrated to learn about the breach from the media first.
The Bigger Lesson From the ShinyHunters FBI Breach
This incident shows how a single third-party HR platform can expose an entire workforce. The FBI’s own statement stresses it is working with “third-party providers that support FBIJobs.gov.”
It also shows that patching isn’t the finish line. If a firewall rule blocks one spelling of a path, attackers will try another.
For individuals, the lesson is simpler. Your data is only as safe as the weakest system that stores it, so a credit freeze and MFA are worth setting up before the next breach, not after.
For technical details, read Oracle’s official Security Alert for CVE-2026-35273.
Frequently Asked Questions
The FBI hasn’t publicly confirmed every claim, but it designated the event a cybersecurity incident on September 22, 2026. Reuters, 404 Media and NBC News all reported that samples matched real FBI personnel.
The affected system holds Social Security numbers, dates of birth, phone numbers, addresses and emergency contacts. The FBI is still working out how many people are affected.
They used a critical Oracle PeopleSoft flaw, CVE-2026-35273, rated 9.8 out of 10. Reports say a modified exploit got around firewall rules that were meant to block it.
On September 28, the group told NBC News it would not publish the data. You shouldn’t rely on that promise, so protect your identity anyway.
Possibly. The FBI hasn’t said how far back the records go, so freezing your credit and enabling MFA is a sensible precaution.
Dutch police arrested a 24-year-old Amsterdam man on September 15, 2026, suspected of being a ShinyHunters hacker. The FBI hasn’t tied him directly to its own breach.
