Technology

ShinyHunters Claims 2-3TB FBI Jobs Data Theft Through PeopleSoft Flaw

Martin HollowayPublished 7m ago4 min readBased on 9 sources
Reading level
ShinyHunters Claims 2-3TB FBI Jobs Data Theft Through PeopleSoft Flaw
Photo by Federal Bureau of Investigation (FBI) / Public domain

ShinyHunters claims to hold 2-3TB of sensitive information about FBI employees and applicants after an alleged compromise of FBIJobs.gov. The hiring portal was offline on Wednesday, September 23, 2026, as the claims circulated. The FBI says it is aware of the claim and is actively and aggressively investigating it Engadget.

The group says it used a zero-day exploit, a security flaw unknown to the software maker, in Oracle's PeopleSoft, a common system for HR and hiring, to reach servers in Amazon Web Services GovCloud, a version of Amazon's cloud built for government use. A ShinyHunters spokesperson told 404 Media: "We hacked the FBI. We hold data on all FBI employees and applicants." 404 Media said it received confirmation from a group representative, while Reuters reported it had seen a sample of the alleged data.

That sample, as described in reporting, included names, addresses, telephone numbers, dates of birth, Social Security numbers and emergency contact details for 5,000 FBI employees. The alleged theft may also include work assignments for agents and details about FBI units handling intelligence, security and counter-espionage work, including operations focused on China and Russia.

The FBI described the incident in narrow terms. It said it was aware of a cyber-criminal group claiming a compromise of the FBIJobs.gov portal with alleged impact to employee personally identifiable information, or PII, basic identity data such as names and Social Security numbers. The scope is unconfirmed. Nextgov reported that the full scope remains unclear, and the Bureau has described its work as an investigation into a claimed compromise rather than a confirmed breach.

The claimants said the attack was not financially motivated but intended to pressure the FBI to remove or amend an earlier statement about ShinyHunters. That statement came in a May report in which the FBI said ShinyHunters exaggerated claims of access to sensitive or personal information to prompt payment from victims. Reuters described ShinyHunters as a digital extortion group.

Reuters reported on September 22, 2026 that ShinyHunters said it had breached the FBI and stolen data. Politico reported the same day that the FBI said it was probing a suspected hack after the claim. BleepingComputer published a report titled "ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach" about the claimed incident.

The FBI claim did not stand alone. ShinyHunters claims to have breached DAVID, an online platform for the Florida Department of Motor Vehicles database, a claim reported on September 8, 2026. The group has also claimed responsibility for a recently disclosed Ernst and Young data breach, reported on July 27, 2026. Separately, the FBI seized a BreachForums domain used by ShinyHunters as a data leak extortion site for widespread Salesforce attacks, an action reported on October 10, 2025.

The broader context here matters more than the headline terabyte figure for teams that defend computer systems. Hiring portals store the kind of data that is hard to change once exposed, such as identity documents, work history and applicant contact details that remain sensitive even after hiring decisions are made. If the claimed path is accurate, a PeopleSoft front end connected to GovCloud workflows would place hiring systems next to sensitive internal assignment data. That closeness is a risk for any organization running HR, applicant tracking or contractor onboarding across connected systems.

In my view, it helps to treat the size claim and the sample as two separate questions. A sample can be checked for formatting clues, internal consistency and matches against known past leaks without accepting the 2-3TB total at face value. Extortion groups have reasons to inflate totals, as the FBI noted in May, and defenders have reasons to prepare for a worst case. Both can be true at the same time. The practical work now is rotation of credentials for exposed staff, monitoring for misuse of emergency contacts, and review of the boundaries between public-facing software and restricted internal systems.

Looking ahead, what this episode could improve is basic and practical. Clearer separation between applicant-facing systems and internal assignment data, faster patching for HR platforms, and shorter retention of applicant data would reduce the payoff of the next claim, real or inflated. Those steps will not make hiring systems invulnerable. They can make them less rewarding to attack, and free up attention for work that actually serves applicants and staff.