News.Bloomberglaw ShinyHunters Hack Exposes Sensitive FBI Employee Data
Article Content
- •ShinyHunters claims to have stolen data on 38,000 FBI personnel, including sensitive medical records.
- •The breach was reportedly facilitated through a vulnerability in Oracle PeopleSoft used by the FBIJobs.gov portal.
- •The FBI is investigating the breach and has not confirmed the extent of the data compromised.
On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security numbers, and sensitive psychiatric and medical evaluation records. ShinyHunters asserts that they exploited a vulnerability in Oracle PeopleSoft, used for the FBI's recruitment portal, to access 2 to 3 terabytes of data. The breach poses significant counterintelligence risks, as the data could be valuable to foreign intelligence services. The FBI is actively investigating the breach and has not confirmed the claims regarding the extent of the data compromised. Security experts warn that the exposure of such sensitive information could lead to harassment, swatting, or extortion of FBI personnel. The FBI's jobs portal has been taken offline as a precautionary measure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (76)
Following this threat?
Track Clop, ShinyHunters and MeshAgent in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…