Skip to content
FBI Breached via Unpatched Oracle Software Vulnerability

FBI Breached via Unpatched Oracle Software Vulnerability

First seen 25 Sep 2026, 04:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 05:56 UTC
  • •FBI breach attributed to unpatched Oracle PeopleSoft vulnerability (CVE-2026-35273).
  • •ShinyHunters exploited the vulnerability after a three-month delay in applying the patch.
  • •Sensitive employee data, including PII, potentially exposed to malicious actors.

The FBI confirmed a breach by the ShinyHunters ransomware group, which exploited a critical vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software. The vulnerability allowed unauthenticated remote code execution, enabling attackers to access sensitive employee data and operational systems. ShinyHunters conducted an automated scan to identify vulnerable systems, targeting the FBI's recruitment portal, FBIjobs.gov, which had not received a critical patch for three months. The breach potentially exposed personal identifiable information (PII) of thousands of FBI employees, including sensitive operational details. The FBI is currently investigating the breach and assessing the extent of the data compromised. Experts warn that the stolen data could have serious real-world implications, especially if sold to malicious actors.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-11
CVE-2026-35273 published
Oracle released a critical security update for PeopleSoft due to a severe vulnerability allowing remote code execution.
Emeraldbook
2026-06-12
CVE added to CISA KEV list
CISA listed CVE-2026-35273 for active exploitation, urging immediate patching.
Emeraldbook
2026-09-23
FBI confirms breach
The FBI acknowledged a breach by ShinyHunters, exposing employee PII and operational data.
Itpro
2026-09-24
ShinyHunters claims responsibility
The ransomware group stated they exploited Oracle PeopleSoft to access FBI systems, including sensitive data.
Itpro

More articles in this cluster (2)

Following this threat?

Track ShinyHunters, European Commission and CVE-2026-35273 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed