securityaffairs.com 23 Sept 2026, 13:56 UTC

ShinyHunters Claims FBI Breach, but Evidence Remains Unverified

ShinyHunters Claims FBI Breach, but Evidence Remains Unverified
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

SHINYHUNTERS claimed on 22 September 2026 that it had breached the FBI and stolen sensitive information relating to current and former employees and job applicants. The group reportedly offered about 5,000 records as evidence, potentially including names, addresses, telephone numbers, Social Security numbers, assignments and family details.

Reuters partially matched at least 10 samples—including information apparently linked to FBI Director Kash Patel—with credit-bureau records and previously leaked data, but could not establish where the information came from or confirm that it was taken from FBI systems.

The FBI acknowledged reports of unauthorised activity affecting FBIjobs.gov and said it was investigating. It has not confirmed a compromise of internal systems or the authenticity and source of the alleged data. ShinyHunters claimed to have used an Oracle PeopleSoft zero-day to obtain remote code execution through recruitment-related infrastructure, and alleged access to human-resources systems and a service called Medlink, with between 2 TB and 3 TB of data stolen.

However, no public CVE or vendor confirmation exists for the alleged new vulnerability. The group has previously been linked by Google and Mandiant to exploitation of PeopleSoft flaw CVE-2026-35273, addressed by Oracle in June, but that history does not prove the latest claim.

FBI recruitment services reportedly experienced disruption, including a defaced page later showing a scheduled-maintenance message, although this alone does not demonstrate a wider breach. ShinyHunters said the operation was retaliation for a May 2026 FBI advisory describing its tactics and warning victims against paying. Until the investigation confirms the intrusion, the incident remains an unverified claim.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline