THE FBI is investigating claims by the ShinyHunters hacking group that it stole 2–3 terabytes of data from FBIJobs.gov, the agency’s recruitment website, after exploiting an alleged previously unknown vulnerability in Oracle PeopleSoft. The group briefly replaced the site’s homepage with a message claiming it had been seized.
It told The New York Times that the stolen material included details on current and former agents, applicants and their relatives, including names, home addresses, phone numbers, spouses’ names and some medical information. Bloomberg reported that a sample may also contain sensitive information about employees’ professional areas, including counter-intelligence work involving China, Russia and Iran, and operations against street gangs. No data had been published at the time of the report.
The FBI has not confirmed that the breach took place. In a 23 September post on X, it said the point of compromise remained unknown, including whether it involved a third-party provider or the FBI’s own enterprise. The agency said it was investigating with support providers and working to mitigate risks, while FBIJobs.gov remained inaccessible. Personnel were reportedly warned to take protective steps during the investigation.
ShinyHunters said the alleged attack was not financially motivated or intended to extort the FBI, but was meant to pressure it to amend a May advisory that the group considered misleading. The group claimed it had “weaponised” a PeopleSoft zero-day, but Oracle had not commented, and ShinyHunters had not leaked the data or explained what it would do if its demands were rejected.