ShinyHunters Claims Access to FBI Systems
Days after hijacking Clop’s Dark Web leak site, ShinyHunters claims it breached the FBI, defaced part of its recruitment website, and stole sensitive information belonging to employees and job applicants.
The group says it gained initial access on September 21, 2026, through a previously unknown vulnerability in Oracle PeopleSoft before moving into additional FBI-managed infrastructure. It claims to have stolen between 2 TB and 3 TB of data.
The FBI has confirmed only that it is aware of claims involving unauthorized activity affecting FBIJobs.gov and is investigating. It has not confirmed the broader breach claims, the alleged PeopleSoft zero-day, or the volume of data stolen.
What Happened in the Alleged FBI Breach?
ShinyHunters claims it compromised FBI systems on the night of September 21 by exploiting a new, unpatched vulnerability in Oracle PeopleSoft. According to the group, the flaw provided remote access to a server associated with the FBI’s recruitment infrastructure.
The following day, apply.fbijobs.gov was defaced with ShinyHunters’ familiar “seized” banner and Umbreon artwork before the page was taken down and later restored.

FBI jobs portal allegedly defaced by ShinyHunters.
ShinyHunters claims it subsequently reached additional FBI-managed systems, including infrastructure hosted in AWS GovCloud, and accessed services it identified as Human Resources, Criminal Justice, and Medlink. The group says it exfiltrated between 2 TB and 3 TB of data relating to current and former employees and job applicants.
A Sample of Alleged FBI Data Was Reviewed
There is some evidence beyond the defacement itself. 404 Media reviewed a sample of approximately 5,000 records allegedly obtained in the incident and reported that the material included names, addresses, phone numbers, and information about FBI employees’ spouses.
The sample does not independently establish the claimed 2–3 TB theft or prove access to every system named by ShinyHunters. The full scope of the incident remains unclear while the FBI investigates.
Why Did ShinyHunters Target the FBI?
ShinyHunters says the operation was retaliation rather than an attempt to obtain a ransom.
In a statement addressed to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, the group disputed claims it says appeared in an FBI Q2 FLASH report. It specifically rejected allegations involving threats against victims and their families, swatting, and exaggerated or fabricated claims about sensitive information.
ShinyHunters also denied being part of “The Com,” a loosely organized cybercrime community associated with actors linked to groups such as Scattered Spider and Lapsus$.
The group gave the FBI one week to correct or remove the disputed report, explicitly describing its actions as non-financially motivated. It also framed the incident as a defense of its reputation and invoked the First Amendment.

ShinyHunters posted a message on their data leak site, directed at FBI leadership.
These statements reflect ShinyHunters’ own account of its motives and conduct. Its denials do not independently establish that the FBI’s descriptions were inaccurate.
ShinyHunters Previously Exploited an Oracle PeopleSoft Zero-Day
The FBI claim is notable because ShinyHunters has already been linked to exploitation of another PeopleSoft zero-day this year. Between May and June 2026, activity attributed to UNC6240, associated with ShinyHunters, exploited CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools. Mandiant warned more than 100 organizations with potentially vulnerable endpoints before Oracle addressed the flaw.
The vulnerability ShinyHunters now claims it used against the FBI is presented as a new, previously unknown PeopleSoft flaw. No public technical evidence currently confirms that vulnerability, but the earlier campaign gives organizations running PeopleSoft a reason to monitor the claim closely.
The FBI Claim Followed ShinyHunters’ Clop Takeover
Just days earlier, ShinyHunters hijacked and defaced Clop’s Dark Web leak site amid a dispute over the rival group’s Oracle E-Business Suite campaign.
The two incidents targeted very different organizations, but both involved visible compromises followed by public messages directed at the target.
That makes it especially important to distinguish observable evidence from ShinyHunters’ claims. The FBIJobs.gov defacement was publicly visible, while the alleged wider FBI access, PeopleSoft zero-day, AWS GovCloud compromise, and terabytes of stolen data still require independent confirmation.
How Can SOCRadar Help?
High-profile incidents can develop across threat actor channels, Dark Web sites, vulnerability disclosures, and exposed internet-facing assets before their full scope becomes clear.
SOCRadar can support monitoring through:
- Dark Web Monitoring: Tracks threat actor communications, leak sites, and mentions of organizations or their third parties.
- Vulnerability Intelligence: Helps teams follow emerging vulnerabilities and changes in exploitation activity.
- Attack Surface Management: Identifies internet-facing assets and technologies that could become exposed when new vulnerabilities emerge.

SOCRadar’s Dark Web Monitoring
Together, these capabilities can help security teams follow emerging threats while separating new intelligence from confirmed technical exposure.
Conclusion
ShinyHunters’ FBI claim comes only days after the group hijacked Clop’s leak site. This time, however, the group says its objective is not financial: it wants the FBI to correct or remove a report it considers inaccurate.
For other organizations, the alleged PeopleSoft zero-day is the more consequential part of the story. ShinyHunters has already been linked to exploitation of a separate PeopleSoft zero-day this year, making the latest claim difficult to dismiss even though it remains unconfirmed.
For now, the FBIJobs.gov defacement, the FBI’s investigation, and the reviewed sample of alleged personnel data provide more grounding than the group’s broader claims. If evidence of the new PeopleSoft flaw emerges or similar activity appears elsewhere, the incident could quickly become a wider enterprise security concern.

