ShinyHunters Claims FBI Staff Data Breach Via Oracle PeopleSoft Zero-Day
ShinyHunters claims to have stolen 2-3TB of FBI employee data via an Oracle PeopleSoft zero-day.
Why it matters: Federal cybersecurity lapses risk exposing sensitive personnel data, elevating compliance and legal liabilities for agencies and contractors managing this information.
- On Sept. 22, 2026, ShinyHunters claimed exploiting Oracle PeopleSoft zero-day CVE-2026-35273 to access FBI systems.
- Between 2 and 3 terabytes of FBI staff and applicant personal data were allegedly stolen.
- FBIjobs.gov site was defaced with ShinyHunters’ logo and taken offline for investigation.
- FBI is investigating but hasn’t confirmed data breach; Oracle issued a security advisory on this flaw in June 2026.
On September 22, 2026, the cybercrime group ShinyHunters publicly claimed to have exploited a zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft software to access FBI systems and extract between 2 and 3 terabytes of data. This data reportedly includes sensitive personal details of thousands of current and former FBI employees and job applicants, highlighting a significant cybersecurity risk for federal law enforcement personnel databases.
Shortly after the claim, ShinyHunters defaced the FBI’s recruitment website, FBIjobs.gov, displaying their logo alongside a message translated as "All FBI data has been compromised." The site was promptly taken offline to investigate and mitigate potential damage.
The FBI spokesperson confirmed awareness of the website’s unauthorized access claims, stating, "We are aware of the claim of unauthorized access to FBIjobs.gov and are currently investigating." The bureau has not publicly confirmed any breach or compromise of personnel data at this time.
This incident is linked to a larger campaign by ShinyHunters that began in June 2026, targeting more than 100 organizations—including numerous educational institutions—by exploiting the same Oracle PeopleSoft zero-day vulnerability. Oracle issued an official security advisory on June 10, 2026, warning clients to apply immediate patches and mitigation instructions.
The FBI’s apparent exposure raises questions about the effectiveness of cybersecurity defenses for critical federal agencies, especially regarding compliance frameworks like FISMA and CISA designed to protect sensitive government information. Legal and compliance professionals managing federal data must monitor this investigation closely, as confirmed data exposure could trigger significant regulatory, privacy, and national security risks.
By the numbers:
- 2-3 terabytes — amount of FBI data ShinyHunters claim to have stolen
- September 22, 2026 — date ShinyHunters announced FBI breach claim
- June 10, 2026 — Oracle issued security alert for PeopleSoft zero-day (CVE-2026-35273)
Yes, but: The FBI has not independently confirmed any data breach or verified that personnel information was actually compromised, so claims remain unverified at this time.
What's next: The FBI investigation is ongoing; agencies and contractors should prepare for potential regulatory actions pending breach confirmation.