The FBI jobs portal breach: what was claimed, what was verified
A defaced hiring portal, a two to three terabyte claim, and a 5,000 record sample that partly checked out. Here is what is established about the FBI jobs portal breach, and what is still only an allegation.
DATA BREACH / 2026-09-23
On Monday night, September 21, 2026, the FBI's public hiring portal stopped being a hiring portal. By Tuesday, apply.fbijobs.gov displayed a banner reading THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS alongside the extortion group's Umbreon logo, and the Special Agent Applicant Portal was pulled offline. The FBI said it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is investigating. By Wednesday the bureau had narrowed nothing: the point of breach is still undetermined, whether a third party or the FBI's enterprise, it said, while describing an active and aggressive investigation.
The claim behind the defacement is far larger than the confirmation. ShinyHunters says it exploited a previously unknown zero-day in Oracle PeopleSoft to run code on FBI servers, moved laterally into FBI-managed AWS GovCloud infrastructure, and walked out with two to three terabytes of records covering current and former employees, special agents, and the people who applied for a job at the bureau.
What ShinyHunters claims
- A new Oracle PeopleSoft zero-day gave it remote code execution on the jobs portal, used before any public advisory existed
- Lateral movement into FBI-managed AWS GovCloud, with two to three terabytes of data exfiltrated
- A named list of affected services: Criminal Justice, HR, and Medlink, the bureau's employee health system
- Data on incumbent and former employees and all applicants, including names, home addresses, phone numbers, dates of birth, social security numbers, spouse details, and in some cases medical information
- No ransom demand. The group says the operation is not financially motivated and wants a May 2026 FBI warning about it retracted within a week
What has been verified
Three things are independently established so far, and each of them is narrower than the claim. The portal was compromised at the perimeter: the defacement happened, screenshots circulated publicly, and the site was taken down rather than restored. At least part of the data is real: 404 Media received a sample of roughly 5,000 records containing names, addresses, dates of birth, and spouse details, and found phone numbers matching people with the same names at the Department of Justice. Reuters cross-referenced the spreadsheet against credit records and prior breach data and individually verified details of more than 22 people.
- 404 Media verified phone numbers in the sample against real Department of Justice personnel
- Reuters verified details of more than 22 individuals using credit records and dark web breach data
- The sample carries assignment detail: 14 staff in China-related units, nine in Russia-related roles, three tied to Iran or Hezbollah work, 18 in intercept, clandestine technical, or surveillance roles, and 11 in human intelligence positions
- Nothing has been published, and Reuters could not authenticate the full file
What remains unconfirmed is the size of it. No independent party has verified the two to three terabyte figure, the lateral movement into GovCloud, access to Criminal Justice, HR, or Medlink records, or the claim of data on nearly all agents and applicants.
Why the FBI is the target
ShinyHunters frames this as retaliation rather than business. In May 2026 the FBI issued a FLASH public service announcement naming ShinyHunters and Scattered Spider in a Salesforce data theft and extortion campaign, and accusing the groups of harassment tactics that included swatting and threats against victims' families. The group denies swatting and sextortion outright, calls the bulletin false, and posted a statement addressed to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman demanding that it be corrected or retracted. A spokesperson told The Register the operation is not financially motivated. The deadline it set was one week.
The history matters here. In June 2026 the same group told BleepingComputer it had tried to breach an FBI portal running PeopleSoft, in its words to publish a statement and set the record straight on misinformation, and that the attempt failed because it could not get into the instance. Three months later it says it did.
The PeopleSoft flaw underneath
The vulnerability the group says it used fits a flaw that has been moving through enterprise systems all year. CVE-2026-35273 is a critical remote code execution bug in Oracle PeopleSoft PeopleTools 8.61 and 8.62, in the Updates Environment Management component, reachable without credentials because the affected path lacks an authentication check. Researchers documented exploitation in the wild from May 27 to June 9, 2026, a 14 day window before Oracle's June 10 security alert, and attributed the campaign to ShinyHunters under the tracking name UNC6240.
That campaign reached more than 100 organizations and roughly 300 instances, with education the most exposed sector, and it did not stop at schools. Insurers, a university, a carmaker, and a medical device maker have all since disclosed data theft tied to the same flaw. Applicant portals sit at the center of that pattern because they hold identity data on people who never became employees, which means the exposure outlives the hiring process it came from.
What it means if your file was in it
- Treat assignment detail as a personal risk, not only a privacy one. A file that maps staff to counterintelligence, intercept, or human intelligence work is targeting material, and Reuters verified that kind of detail is in the sample
- Expect credible pretexts. A verified home address, a spouse's name, and a working phone number make a call or an email convincing in a way generic phishing never is
- Freeze credit at all three bureaus if you applied to or worked at the bureau, and consider a fraud alert on top of it: the sample includes social security numbers and dates of birth
- Do not confirm anything to an inbound contact who references your application or your file. Route every check through a number or address you already had
The lesson for everyone else
The FBI case is a story about a hiring portal, but the shape of it is ordinary: an internet-facing enterprise application, a missing authentication check, a system holding identity data, and an attacker who wants leverage more than money. Any organization running PeopleSoft should already be patched to the current Oracle alert level and should know precisely which instances are reachable from the internet, including the ones nobody remembers are PeopleSoft.
For individuals the takeaway is the one that shows up in every breach brief we publish. You cannot control whether the portal gets breached. You can shrink what a stolen file is worth: fewer broker listings, fewer stale accounts, frozen credit, and a household that recognizes a credible pretext before it is used.
WHAT WE KNOW The defacement and the takedown are established. Parts of a 5,000 record sample have been verified against real personnel by two newsrooms. The two to three terabyte figure, the GovCloud intrusion, and the claim of data on nearly all agents are allegations from the group making them, and neither the FBI nor Oracle has confirmed the mechanism. This brief will be updated as findings are published.