Update, September 23: The FBI has issued a more detailed statement acknowledging that ShinyHunters is claiming a compromise of FBIJobs.gov and an impact to FBI employee personally identifiable information. The bureau said investigators have not yet determined whether the initial breach occurred through a third-party provider or the FBI’s own enterprise and that it is working with providers supporting FBIJobs.gov.
Independent reporting has also provided additional corroboration for portions of the allegedly stolen data. Journalists reviewing a sample of approximately 5,000 purported FBI employee records have verified information associated with FBI and Justice Department personnel, while Reuters reported that the material includes details about personnel working in sensitive intelligence and counterintelligence roles. The origin of the records and ShinyHunters’ broader claim of stealing between 2TB and 3TB of data have not been independently established.
ShinyHunters says the alleged attack was retaliation for FBI reporting about the group. In a statement addressed to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, the group disputed FBI claims that ShinyHunters actors exaggerate access, harass victims and their families, engage in swatting or falsely claim to possess compromising information.
The group demanded that the FBI correct or remove the disputed material within one week and said its actions against the bureau were not financially motivated. The language ShinyHunters disputes also appears in a May 15 FBI Internet Crime Complaint Center Public Service Announcement concerning the group, which remained publicly accessible at time of this update.
Despite the growing evidence that genuine FBI personnel information may have been compromised, the most significant technical claims remain unverified. Neither the FBI nor Oracle has confirmed ShinyHunters’ claim that a previously unknown Oracle PeopleSoft vulnerability was used for initial access, and the claimed theft of 2TB to 3TB of data has not been independently established.
The FBI says it is investigating unauthorized activity affecting FBIJobs.gov after ShinyHunters claimed it breached bureau systems by exploiting a previously unknown remote code execution vulnerability in Oracle PeopleSoft.
The cybercrime group claims it used the alleged PeopleSoft zero-day for initial access before moving laterally into additional FBI systems, including FBI-managed AWS GovCloud infrastructure containing employee and applicant information.
ShinyHunters claims it stole between 2TB and 3TB of data covering current and former FBI personnel, job applicants and other internal records. It has also alleged access to systems associated with criminal justice, human resources and medical functions.
The FBI has not confirmed those broader claims. However, the bureau has acknowledged that it is investigating reported unauthorized activity affecting FBIjobs.gov.
The alleged zero-day, claimed AWS GovCloud access and reported theft of between 2TB and 3TB of data remain unverified.
FBI Jobs site allegedly defaced
ShinyHunters has provided additional evidence supporting at least some unauthorized activity involving the FBI’s recruitment infrastructure.
A screenshot shared by the group appears to show the FBI Jobs application website defaced with ShinyHunters branding and a message claiming that FBI employee and applicant information had been compromised.

The group claims the FBI detected the intrusion and terminated access to multiple affected systems. The FBI Jobs service was subsequently reported to be displaying a maintenance message.
ShinyHunters has also provided samples it claims came from the intrusion. A sample containing approximately 5,000 purported FBI employee records was reviewed by journalists, who reported independently verifying some contact information against people and numbers associated with U.S. Department of Justice personnel.
That provides some corroboration that portions of the material may be genuine, but it does not establish that the records were obtained through the claimed PeopleSoft zero-day or directly from the broader FBI environments described by ShinyHunters.
BreachNews is not publishing personal information, employee records or other sensitive data allegedly obtained during the incident.
ShinyHunters claims a new PeopleSoft zero-day
The most significant allegation surrounding the incident is that ShinyHunters discovered another previously unknown vulnerability in Oracle PeopleSoft capable of remote code execution.
The group claims it found the flaw shortly before the FBI intrusion and is now exploiting the same vulnerability against other organizations, including Fortune 500 companies.
ShinyHunters also claims it attempted to remove evidence of its activity from compromised servers, potentially complicating efforts to identify the vulnerability and reconstruct the initial attack path.
Oracle had not publicly confirmed the existence of the newly claimed vulnerability at time of publication.
ShinyHunters has previously been linked to exploitation of PeopleSoft zero-days. Earlier in 2026, the group targeted organizations through a separate Oracle PeopleSoft vulnerability before a patch became available, with security researchers identifying more than 100 potentially affected organizations during that campaign.
The vulnerability now claimed in connection with the FBI appears to be separate from that earlier activity and has not yet been publicly assigned a CVE or independently documented.
Claimed FBI data includes personnel and applicants
ShinyHunters claims the stolen information includes sensitive personally identifiable information belonging to current and former FBI employees as well as individuals who applied for positions with the bureau.
The group has also claimed possession of health-related information, although the FBI has not confirmed that such data was exposed.
If information was taken from recruitment or personnel systems, the potential impact could be significant because federal law enforcement employment records may contain extensive identity, employment, background and health-related information.
The exact fields allegedly exposed across the claimed dataset have not been independently established.
Attack framed as retaliation for FBI warning
ShinyHunters says the FBI intrusion was retaliation for a 2026 bureau warning concerning the group’s operations and extortion tactics.
The group disputes FBI descriptions involving exaggerated access claims, harassment tactics and its relationship with the broader cybercriminal ecosystem commonly referred to as “The Com.”
ShinyHunters gave the FBI 1 week to remove or correct portions of the report and claims the demand is not financially motivated.
Those statements represent ShinyHunters’ characterization of its own activity and do not override the FBI’s assessment of the group.
FBI has faced previous high-profile compromises
The latest incident follows previous compromises involving systems and communications associated with the bureau and its leadership.
Earlier this year, BreachNews reported that Iran-linked hackers allegedly breached FBI Director Kash Patel’s personal email account, highlighting the intelligence value associated with communications belonging to senior U.S. officials.
The bureau has also faced attacks targeting infrastructure used for sensitive law enforcement operations. BreachNews previously reported on the confirmed compromise of an FBI wiretap system by China-linked hackers during a broader telecommunications espionage campaign.
Those incidents provide no evidence supporting ShinyHunters’ latest allegations, but they illustrate the potential consequences if access to sensitive FBI personnel or operational infrastructure is ultimately confirmed.
FBI confirmation adds weight to the initial claim
The FBI’s acknowledgement that it is investigating unauthorized activity affecting FBIjobs.gov means the incident has moved beyond ShinyHunters’ initial unsupported statement.
The alleged defacement and partially verified employee sample provide additional evidence that some unauthorized access may have occurred.
However, the most significant elements remain unconfirmed, including ShinyHunters’ claim of a new PeopleSoft zero-day, lateral movement into AWS GovCloud, access to multiple FBI internal services and theft of between 2TB and 3TB of data.
The PeopleSoft allegation could become the most consequential part of the incident if independently confirmed. ShinyHunters claims it is already using the same vulnerability against additional organizations, raising the possibility of a broader campaign beyond the FBI.
The FBI claim emerged alongside other recent ShinyHunters extortion activity. BreachNews separately reported on the group’s claim that it stole sensitive data from Fresenius Medical Care, which the group threatened to publish following a September 25 deadline.
BreachNews will continue monitoring for additional confirmation from the FBI or Oracle, technical information concerning the alleged PeopleSoft vulnerability and further evidence supporting the claimed data theft.










