On 22 September 2026, the ShinyHunters extortion group claimed it had breached the FBI through an Oracle PeopleSoft vulnerability, moved into FBI-managed AWS GovCloud infrastructure, and stolen 2 to 3 terabytes of data on current, former and prospective FBI employees. The FBI's job application site was defaced and taken offline. The FBI confirmed it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating", but has not confirmed that its systems were breached or data stolen. Mandiant separately reported that ShinyHunters was again exploiting a PeopleSoft flaw, CVE-2026-35273, and getting past web application firewall rules by URL-encoding a single character. This page covers what is confirmed, what is only claimed, and why the alleged pivot from a web application into a government cloud matters for machine identity security.
Key takeaways
- Most of this incident is claimed, not confirmed. ShinyHunters says it took 2 to 3 TB from FBI systems, including HR, medical and investigative platforms. The FBI has confirmed only that it is investigating claims about FBIjobs.gov.
- Confirmed signals: the apply.fbijobs.gov site was defaced and has stayed offline. 404 Media and Reuters verified parts of leaked samples against public information.
- Mandiant reports ShinyHunters is again exploiting CVE-2026-35273 in PeopleSoft's Environment Management Hub, patched on 10 June 2026. It bypasses WAF rules by requesting
/%50SEMHUB/instead of/PSEMHUB/. - The claimed path runs from a public web application into FBI-managed AWS GovCloud storage. How that cloud access was obtained has not been disclosed, which makes the PeopleSoft host's service identities and reachable secrets the key question.
- The lesson: an internet-facing HR or ERP server is also a store of machine credentials into back-end systems. Patch it, keep it off the internet, and be ready to rotate every secret it can reach.
At a glance
| Organisations | Federal Bureau of Investigation (FBIjobs.gov and, as claimed, internal HR, medical and investigative systems); Oracle PeopleSoft customers in several sectors |
|---|---|
| When | Claimed intrusion on the night of 21 September 2026; defacement and claims on 22 September; Mandiant update 25 September 2026 |
| Attacker | ShinyHunters (tracked by Mandiant as UNC6240), which says the attack was retaliation for an FBI advisory, not for money |
| Entry point | Claimed: an Oracle PeopleSoft vulnerability on the FBI jobs portal. Mandiant links the group's current campaign to CVE-2026-35273 |
| Identities abused | Not disclosed. The claimed pivot into FBI-managed AWS GovCloud implies use of cloud credentials or service identities reachable from the compromised server |
| Impact | FBI jobs portals defaced and offline; claimed theft of 2 to 3 TB of personnel, applicant and medical data; samples partly verified by 404 Media and Reuters |
| Category | NHI, Human identity. Incident class: confirmed NHI breach claimed by the attacker (FBI investigating; breach and data theft not confirmed by the FBI) |
What happened
On 22 September 2026, ShinyHunters told BleepingComputer it had used an Oracle PeopleSoft vulnerability "Monday night to access FBI systems before moving laterally into FBI-managed AWS GovCloud infrastructure". It said it stole between 2 and 3 TB of data on current and former FBI employees and job applicants, and compromised "FBI Criminal Justice, HR, Medlink, and additional services". The apply.fbijobs.gov site was defaced with the message "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS". The FBI told BleepingComputer: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." It has not confirmed a breach or data theft. BleepingComputer says it has not verified the zero-day, the lateral movement or the volume of data.
Some claims have been partly checked. 404 Media, which first reported the story, received a sample of about 5,000 purported employee records and verified that some details were accurate. Reuters matched the career details of eight people in leaked documents to public information, but could not verify that all job assignments were authentic or current. Help Net Security reports that both FBI job portals were still offline on 28 September. ShinyHunters says the attack was retaliation for a May 2026 FBI advisory about the group, and demanded the advisory be corrected or removed within a week.
On 25 September, Mandiant published an update on a wider campaign. ShinyHunters was again exploiting CVE-2026-35273, a flaw in PeopleSoft's Environment Management Hub that it first used as a zero-day against universities in May and June 2026. Oracle patched it on 10 June. Mandiant found the group had changed its exploit to get past WAF rules that blocked the vulnerable endpoint: "The threat actor bypassed these string-based WAF rules by URL-encoding a single character in the request path, requesting /%50SEMHUB/ in place of /PSEMHUB/." Organisations that had patched were protected; those that relied only on WAF rules were not. After access, the group deploys web shells and the MeshAgent remote management tool, according to Help Net Security. Vectra notes that, based on 404 Media's reporting, the FBI jobs portal runs PeopleSoft. Unlike many earlier ShinyHunters campaigns, the reported entry point was an unpatched application rather than a stolen login.
Timeline
| Date | Event |
|---|---|
| May 2026 | ShinyHunters exploits a PeopleSoft Environment Management Hub zero-day against universities; the FBI publishes an advisory about the group. |
| 10 June 2026 | Oracle releases a patch for CVE-2026-35273. |
| 21 September 2026 | ShinyHunters says it accessed FBI systems that night. |
| 22 September 2026 | FBI jobs site defaced; ShinyHunters claims the breach; the FBI confirms it is investigating. |
| 25 September 2026 | Mandiant reports renewed CVE-2026-35273 exploitation with a WAF bypass. |
| 28 September 2026 | FBI job portals remain offline (Help Net Security). |
How it happened: the identity attack path
Only the first steps are supported by independent reporting. The rest is ShinyHunters' account.
- An internet-facing ERP application. PeopleSoft runs HR, payroll and applicant systems and, in this case, a public jobs portal.
- A patched flaw left exploitable. Where organisations blocked the vulnerable endpoint with WAF rules instead of patching, a one-character encoding change got past them (Mandiant).
- Code execution on the server. Mandiant says the group deploys web shells and remote management tools after access.
- A claimed pivot into government cloud. ShinyHunters says it moved from the portal into FBI-managed AWS GovCloud storage. Moving from a web server into cloud storage usually relies on credentials or roles available to that server, but how it was done has not been disclosed.
- Bulk data access. The group claims 2 to 3 TB taken from HR, medical and investigative systems.
Impact
- Confirmed: defacement of the FBI jobs site and extended outage of the FBI job portals; an FBI investigation into the claims.
- Partly verified: leaked samples containing some accurate personal details of FBI and Justice Department staff, according to 404 Media and Reuters.
- Claimed, not confirmed: theft of 2 to 3 TB of data, including medical and investigative records, and access to FBI-managed AWS GovCloud.
- Wider campaign: Mandiant reports compromised PeopleSoft systems across higher education, technology, healthcare, agriculture, transportation and government worldwide.
What this means for NHI and AI agent security
This is not an identity-first attack. It started, as far as anyone can tell, with an unpatched application, and many details are unconfirmed. It is on our list because of the alleged second step. An HR portal on the internet was, according to the attackers, a way into government cloud storage. Web and ERP servers rarely stand alone. They hold database credentials, integration secrets and cloud roles that let them talk to back-end systems. Once the server is compromised, those machine identities decide how far the attacker can go.
That is why responders are advising PeopleSoft customers to look beyond the patch. Exabeam's Steve Povolny, quoted by Infosecurity Magazine, told them to "evaluate the PeopleSoft host and its service identities" and "be ready to rotate every secret reachable from those servers". Our Service Account Security Guide and Cloud Workload Identity Guide cover how to limit what a compromised application server can reach. We have covered ShinyHunters' identity-led campaigns before, in the Salesforce data theft campaign.
Recommendations
- Patch CVE-2026-35273 and do not rely on WAF rules. Apply Oracle's June patch, and disable the Environment Management Hub or remove the PSEMHUB application if unused.
- Take ERP admin and integration interfaces off the internet. Restrict PeopleSoft application and web servers to trusted networks.
- Scope the server's machine identities. Give application servers least-privilege cloud roles and database accounts, so a compromise cannot reach unrelated storage. See our Cloud PAM and CIEM Guide.
- Know and rotate reachable secrets. Inventory credentials on and reachable from ERP hosts, and rotate them after any suspected compromise. See our Leaked Credential Response Playbook.
- Hunt for post-exploitation activity. Look for web shells, MeshAgent or MeshCentral tooling, and bulk data queries or unusual cloud API calls from application servers. Ship logs off-host, since the attackers claim to wipe local evidence. See our ITDR Guide.
Frequently asked questions
Did ShinyHunters really breach the FBI?
It is not confirmed. The FBI says it is investigating claims about unauthorised activity affecting FBIjobs.gov. The jobs site was defaced and taken offline, and parts of leaked samples have been verified by 404 Media and Reuters. ShinyHunters' claims of 2 to 3 TB stolen and access to AWS GovCloud remain unverified.
Which vulnerability was used?
ShinyHunters says it used an Oracle PeopleSoft flaw. Mandiant reports the group is exploiting CVE-2026-35273, patched on 10 June 2026, and bypassing WAF rules by URL-encoding a character in the request path. Whether this was the exact flaw used against the FBI has not been confirmed.
Why is this on an NHI breach list?
Because of the claimed pivot from a public web application into FBI-managed cloud storage. That kind of movement relies on the machine identities and secrets available to the compromised server, which is why responders advise reviewing the server's service identities and rotating every reachable secret.
Related NHI Mgmt Group resources
ShinyHunters Salesforce data theft campaign 2025 · Oracle E-Business Suite Cl0p zero-day 2025 · CISA Private-CISA GitHub leak 2026 · Public Sector Identity Security Guide · Service Account Security Guide
How NHI Mgmt Group can help
Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as attackers turn compromised application servers into routes to cloud data. Our NHI Foundation Level Training Course gives teams the practical grounding to scope the service identities behind those servers.
References
- BleepingComputer: ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach (22 September 2026)
- Infosecurity Magazine: ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day (23 September 2026)
- Vectra AI: ShinyHunters Breached the FBI by Bypassing the Fix (28 September 2026)
- Help Net Security: FBI job portals remain offline after ShinyHunters claims breach via PeopleSoft zero-day (28 September 2026)