"ShinyHunters says it hacked the FBI through a PeopleSoft zero-day"
Key takeaways
- ShinyHunters claims 2 to 3TB stolen from FBI systems via an unpatched PeopleSoft flaw
- The Bureau careers portal FBIjobs.gov was defaced with a fake seizure notice
- FBI has confirmed it is investigating but not verified the claims
- The breach follows a May 2026 FBI warning about the group, suggesting retaliation
A breach the FBI didn't see coming
On 22 September, the cyber-extortion group ShinyHunters said it had done something most ransomware crews only dream about: breaking into the systems of the FBI itself.
The group claims it exploited a previously unknown vulnerability in Oracle PeopleSoft, the enterprise software the Bureau uses for HR and personnel records, to get inside FBI systems and pull out between 2 and 3 terabytes of data. That haul reportedly includes personal information on almost every current FBI agent, plus records on people who applied for jobs with the Bureau and never got further than the paperwork.
ShinyHunters did not stop at quietly copying files. The group defaced the FBI's own careers site, FBIjobs.gov, along with the Special Agent Applicant Portal, replacing them with a fake law-enforcement seizure notice. For a few hours, anyone trying to apply for a job at the FBI was instead greeted with a message from the people the FBI is supposed to be chasing.
Why the FBI, and why now
ShinyHunters has spent the past year running one of the most prolific extortion operations going, tied to breaches at Salesforce customers, ticketing platforms and telecoms firms. In May 2026, the FBI published a warning describing the group's methods in detail and telling victims not to pay ransom demands.
The group is framing this breach as payback. Whether or not that is the full story, it fits a pattern security researchers have flagged for a while: once a law enforcement agency names and profiles a criminal group publicly, that group increasingly treats the statement as a challenge rather than a deterrent.
What's actually confirmed
The FBI has acknowledged it is aware of claims concerning unauthorised activity affecting its jobs site and says it is investigating. It has not confirmed the scale of the breach, the PeopleSoft zero-day claim, or the 2-3TB figure. Oracle has not issued a public statement tying a specific PeopleSoft CVE to this incident as of publication.
That gap between claim and confirmation matters. ShinyHunters has a track record of both real breaches and exaggerated ones, and extortion groups have every incentive to inflate numbers. Treat the headline figures as the group's own claims until the FBI or Oracle says otherwise.
Why it matters beyond the FBI
PeopleSoft runs HR, payroll and personnel systems for a huge number of government agencies, universities and large enterprises worldwide. If there genuinely is an unpatched zero-day in play, this is not just an FBI problem. Any organisation running PeopleSoft should be watching Oracle's security advisories closely over the coming weeks.
There's a broader lesson here too. The systems that get breached are rarely the flashy ones. It's the boring HR and applicant-tracking software running in the background, patched on nobody's priority list, that ends up being the door in.