Skip to content
RegionAmericas

HighII Cyber Warfare & Critical Infrastructure22 September 2026, Tuesday

ShinyHunters claims it stole 2–3 TB of FBI staff and applicant data through an Oracle PeopleSoft zero-day

The ShinyHunters group claimed it entered through an unpatched flaw in the Oracle PeopleSoft system behind the FBI's job application portal, moved to servers in AWS GovCloud and took 2–3 TB of data. 404 Media verified part of a sample of about 5,000 records; the FBI said it had opened an investigation.

WASHINGTON

According to reports by BleepingComputer and The Register dated 22 September 2026, the group says that on Monday night it used an as-yet-unpatched zero-day allowing remote code execution in the Oracle PeopleSoft system at apply.fbijobs.gov, and then moved laterally to AWS GovCloud servers managed by the FBI. The 2–3 TB of data allegedly stolen covers current, former and prospective FBI employees; the group also claims to have accessed human resources, MedLink and Criminal Justice Information Services systems. According to TechCrunch, the data include the names, home addresses and phone numbers of agents and their spouses.

404 Media said it had obtained a sample of about 5,000 records and verified that some of the information matched public records. The FBI said only that it was aware of claims of unauthorised activity affecting FBIjobs.gov and was investigating; Oracle and AWS did not comment. The group said the attack was not financially motivated and that it wanted the FBI to correct, within 1 week, what it had written about the group in its FLASH bulletin of 15 May 2026. TechCrunch noted that this is the second known breach of FBI systems in 2026.

The existence of the zero-day, the lateral movement and the volume of data stolen could not be independently verified by BleepingComputer. If the records are genuine, 2–3 TB of personnel data poses a counter-intelligence risk with respect to foreign intelligence services.

Talay assessment

Bottom line

If verified, the claim would mean a 2–3 TB leak from the personnel layer of the most sensitive US law enforcement agency; the real risk is counter-intelligence, not money. The flaw being unpatched in Oracle PeopleSoft also leaves other public and private organisations using the same software exposed. The most likely path is partial confirmation and an emergency patch announcement; the FBI should not be expected to give in to the group's demand.

Likely effects

  • Counter-intelligenceNegative6 months+

    The leak of home addresses and phone numbers of agents and their spouses produces a target list for coercion and recruitment attempts by foreign services.

  • Enterprise HR systemsNegativeWeeks

    If the unpatched remote code execution flaw in Oracle PeopleSoft is confirmed, public agencies and universities using the same system will face pressure to patch urgently.

  • Turkish public institutionsUncertain1–6 months

    Connecting corporate HR and recruitment portals to cloud environments is also common in Türkiye; the incident puts lateral movement controls on public portals holding personal data inventories on the agenda.

Possibilities, ranked

  1. 1
    Partial confirmation and patch55%

    The FBI confirms part of the breach, Oracle issues an emergency patch and CISA adds the flaw to its catalogue of known exploited vulnerabilities.

    Watch: An out-of-band Oracle security alert for PeopleSoft and a CISA KEV entry

  2. 2
    Data released piecemeal30%

    The FBI rejects the demand, and the group leaks the data gradually after the 1-week deadline.

    Watch: A new FBI-titled post on the group's leak site

  3. 3
    Claim proves exaggerated15%

    The investigation shows the data were limited to the job application portal and that there was no move into GovCloud.

    Watch: The list of affected systems in the FBI's official statement

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • Data claimed 2–3 TB
  • Verified sample ≈5,000 records
  • Deadline set by the group 1 week

Sources

  1. BleepingComputer — ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
  2. The Register — ShinyHunters claims FBI hack: 'This is NOT financially motivated'
  3. TechCrunch — Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data