Claims suggest data on 'almost all' FBI agents and applicants
The U.S. Federal Bureau of Investigation (FBI) has acknowledged a security incident affecting its recruitment portal, FBIJobs.gov, after the prominent threat group ShinyHunters claimed to have perpetrated a massive data breach. The group alleges it exfiltrated sensitive personally identifiable information (PII) on a vast number of FBI agents and applicants by exploiting a zero-day vulnerability in the underlying Oracle PeopleSoft platform. While the full extent of the breach is under investigation, the claims represent a grave national security threat, as the compromised data could be used for espionage, blackmail, or to undermine federal law enforcement operations. The FBI has taken the affected portal offline as it investigates the incident with its third-party service providers.
On September 23, 2026, the FBI confirmed it was investigating claims of a breach after ShinyHunters announced the compromise online. The threat group, known for large-scale data theft and extortion, claimed the attack was in retaliation for an FBI advisory from May 2026 that detailed the group's tactics. ShinyHunters boasted of stealing "very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job."
The allegedly stolen data includes names, home addresses, phone numbers, email addresses, and potentially Social Security numbers. News organizations that reviewed a sample of the data reported that it appeared to match real FBI and Department of Justice personnel, lending credibility to the hackers' claims. The attack vector was reportedly a zero-day vulnerability in Oracle's PeopleSoft human resources software, a platform ShinyHunters has targeted in past campaigns.
The core of this attack, as claimed by ShinyHunters, is the exploitation of a zero-day vulnerability in a public-facing application, a classic initial access technique mapped to T1190 - Exploit Public-Facing Application. PeopleSoft, as a complex enterprise resource planning (ERP) application, has a large attack surface that can be difficult to secure completely.
Once initial access was gained, the threat actor likely performed actions to access and exfiltrate sensitive information from the backend database, a technique categorized as T1213 - Data from Information Repositories. The attackers' claim of obtaining data on "almost ALL" agents and applicants suggests they achieved privileged access to the primary data stores of the FBIJobs.gov portal. The motive of retaliation indicates a hacktivist element, though ShinyHunters' primary operations are typically financially motivated.
A confirmed breach of this magnitude would have severe and far-reaching consequences for U.S. national security.
No specific Indicators of Compromise (IOCs) were mentioned in the source articles.
For organizations using Oracle PeopleSoft, the following patterns could help identify related malicious activity:
/psp/, /psc/, /cs/PSAPPSRV.exe, PSAE.exeAPPSRV_*.LOG, TUXLOG.*psadminD3-WSAA: Web Session Activity Analysis.D3-SU: Software Update.D3-MFA: Multi-factor Authentication.FBI investigation reveals Accenture contractor's failure to apply a critical PeopleSoft patch caused the FBIJobs.gov breach, exposing highly sensitive data.
Promptly apply security patches from Oracle for the PeopleSoft platform to close known vulnerabilities.
Enforce MFA on all accounts, especially privileged ones, to prevent unauthorized access even if credentials are compromised.
Isolate the HR portal and its backend systems from other parts of the network to contain potential breaches.
Organizations utilizing Oracle PeopleSoft must maintain a rigorous and timely patching schedule. Given that ShinyHunters allegedly exploited a zero-day, this highlights the importance of applying patches as soon as they become available, especially those labeled as critical or addressing remote code execution flaws. Establish a process to monitor Oracle's Critical Patch Updates (CPU) and apply them to a test environment before rolling them out to production. In a case like this, where a zero-day is suspected, being on the latest patch level is the best defense against it becoming an N-day exploit. This directly hardens the application against the initial access vector.
Deploy a Web Application Firewall (WAF) in front of the FBIJobs.gov portal and other PeopleSoft instances. The WAF should be configured with a strict rule set to filter malicious inbound requests that are characteristic of exploitation attempts, such as SQL injection, command injection, and path traversal. Even if a zero-day vulnerability exists, a well-configured WAF can often block the generic attack patterns used to exploit it. Furthermore, use IP-based allow-listing to restrict access to administrative interfaces to only trusted internal networks or specific jump boxes, drastically reducing the attack surface available to external actors like ShinyHunters.
Continuously monitor all accounts with access to the PeopleSoft application and its underlying database for anomalous behavior. This includes service accounts and privileged user accounts. Establish a baseline of normal activity for each account, such as typical login times, source IP addresses, and data access patterns. Configure alerts for deviations from this baseline, such as a service account attempting an interactive logon, a user accessing the system from a new geographic location, or an account attempting to query an unusually large number of records. This can help detect a compromised account being used to exfiltrate data, as was allegedly done in this breach.
ShinyHunters claims responsibility for hacking FBIJobs.gov and stealing sensitive data.
The FBI confirms it is aware of the claims and is actively investigating a 'cybersecurity incident'.
The FBIJobs.gov portal is taken offline as the investigation continues.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.