News.Bloomberglaw ShinyHunters Hack Exposes Sensitive FBI Employee Data
Article Content
- •ShinyHunters claims to have stolen data on 38,000 FBI personnel, including sensitive medical records.
- •The breach was reportedly facilitated through a vulnerability in Oracle PeopleSoft used by the FBIJobs.gov portal.
- •The FBI is investigating the breach and has not confirmed the extent of the data compromised.
On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security numbers, and sensitive psychiatric and medical evaluation records. ShinyHunters asserts that they exploited a vulnerability in Oracle PeopleSoft, used for the FBI's recruitment portal, to access 2 to 3 terabytes of data. The breach poses significant counterintelligence risks, as the data could be valuable to foreign intelligence services. The FBI is actively investigating the breach and has not confirmed the claims regarding the extent of the data compromised. Security experts warn that the exposure of such sensitive information could lead to harassment, swatting, or extortion of FBI personnel. The FBI's jobs portal has been taken offline as a precautionary measure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (86)
Following this threat?
Track ShinyHunters, FBI and CVE-2026-21962 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…
FBI Breached via Unpatched Oracle Software Vulnerability The FBI confirmed a breach by the ShinyHunters ransomware group, which exploited a critical vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software. The vulnerability allowed unauthenticated remote code execution, enabling attackers to access sensitive employee data and operational systems. ShinyHunters…