news.mlab.sh
Back to the feed
threat-intel

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

CriticalCVSS 9.8
Summary

The cyber extortion group ShinyHunters claims to have breached the FBI and stolen data on current and former employees, including Special Agents and job applicants. They exploited a zero-day vulnerability in Oracle PeopleSoft to gain remote code execution and deface the FBI’s jobs site. The FBI is investigating the claims, and this incident highlights a shift in ShinyHunters’ tactics, focusing on exploiting trusted identity paths and SaaS integrations, rather than solely relying on technical vulnerabilities.

The cyber extortion group ShinyHunters has publicly claimed it successfully breached the U.S. Federal Bureau of Investigation and obtained sensitive data on current and former FBI employees, as well as individuals who applied for jobs. The group stated this in a post on their dark web site, asserting that the data included information on Special Agents and other roles within the agency. The group cited compromised FBI services including Criminal Justice (CJ), HR, and Medlink.

The development follows a May 2026 public service announcement (PSA) from ShinyHunters detailing their targeting of Canvas, an online Learning Management System (LMS), and urging victims not to pay a ransom. In response, ShinyHunters released a counter PSA, dismissing the FBI’s efforts as “substantial false allegations” and claiming their actions were unsuccessful.

ShinyHunters claims to have exploited a new Oracle PeopleSoft zero-day vulnerability to gain remote code execution and deface the FBI’s jobs site with a banner reading: "Scheduled Maintenance Underway. We're Sniffing Out Site Updates for You!" Visiting the site now displays this message. The group also weaponized a similar flaw (CVE-2026-35273) in June 2026 to break into enterprise networks and extort victims.

The FBI has acknowledged the claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating. Etay Maor, VP of threat intelligence at Cato Networks, noted that ShinyHunters’ recent playbook has shifted to exploiting trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter.

ShinyHunters has demonstrated resilience, successfully evading takedowns, arrests, and forum seizures by evolving its methods and attracting new operators. The September 23 timestamp on the group’s post, despite the news emerging on September 22 in the U.S., suggests activity in Asia, a detail investigators will examine alongside technical evidence.

Read the full article at The Hacker News