INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters Claims FBI Hack Exposes Almost All Agents

| 2026-09-23 07:13 CRITICAL HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The FBI is currently investigating claims of unauthorized activity affecting its job portal, [IOC HIDDEN • LOGIN REQUIRED], following a breach allegedly perpetrated by the notorious cybercrime group ShinyHunters. According to reports, the hackers exploited a zero-day vulnerability in Oracle's PeopleSoft product to access sensitive information, including names, phone numbers, and home addresses of nearly 5,000 FBI employees. The stolen data was provided to media outlet 404 Media as evidence, with at least some samples appearing authentic but the origin of the data yet to be confirmed. ShinyHunters claims it breached FBI systems and accessed sensitive information, while denying any affiliation with another group known as The Com. The hackers also framed their statement as an exercise of First Amendment rights rather than an act of ransom or extortion. As a result, 2-3 TB of data was allegedly stolen from the breach, which is believed to have occurred using CVE-2026-35273 vulnerability.
Technical Mitigations AI-generated
• Implementing a robust PeopleSoft security patch management process to prevent exploitation of zero-day vulnerabilities. • Conducting regular vulnerability assessments and penetration testing on FBI systems to identify potential entry points for attackers like ShinyHunters. • Utilizing advanced threat detection tools, such as anomaly-based intrusion detection systems (IDS), to monitor network activity and detect suspicious behavior.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

fb•••••.gov
ap•••••.gov
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters CVE-2026-35273CVE-2026-35273
Target & Sectors
Global Scope educationeducation technologytechnology
Incident Timeline
‎2026/09/23
ShinyHunters claimed to have breached the FBI's systems, accessing sensitive information on nearly all agents and job applicants.
threat_actor ShinyHunters
victims 5,000 FBI employees
organisation Oracle’s
organisation PeopleSoft
data_breach 2 TB
organisation Criminal Justice
organisation Halcyon’s
organisation CyberScoop
organisation First Amendment
organisation Canvas
Tactical Metrics
Metrics
victims
5,000
Fbi Employees
Metrics
data_breach
2
Tb
Intelligence Sources