Skip to main content

ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

0
Critical
Analysis
Published: 09/23/2026 (09/23/2026, 07:13:49 UTC)
Source: SecurityWeek

Description

The cybercrime group ShinyHunters claims to have breached FBI systems, including Criminal Justice, HR, and Medlink services, allegedly stealing data on nearly all FBI agents and job applicants. They demonstrated their claim by defacing a subdomain of the FBI jobs website. The group disputes certain characterizations made about them in an FBI report and demands its retraction. The FBI is investigating the unauthorized activity but has not confirmed the breach. ShinyHunters claims to have exploited a zero-day vulnerability in Oracle PeopleSoft, possibly CVE-2026-35273, to conduct the breach. A sample of stolen data was provided and partially verified as authentic by third parties, though the origin remains unconfirmed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 07:17:56 UTC

Technical Analysis

ShinyHunters, a known cybercrime and extortion group, alleges they compromised FBI systems by exploiting a zero-day vulnerability in Oracle PeopleSoft software, potentially CVE-2026-35273. They claim to have stolen 2-3 TB of sensitive data including personal information of FBI employees and job applicants. To support their claim, they defaced the FBI jobs subdomain and posted a seizure message. The group disputes negative assertions made in an FBI FLASH report about their tactics and affiliations. The FBI has acknowledged the investigation but has not disclosed further details. Independent reviewers have found some of the leaked data sample to appear authentic, though full verification is pending.

Potential Impact

If confirmed, the breach exposes sensitive personal information of thousands of FBI employees and applicants, potentially compromising privacy and operational security. The defacement of an FBI subdomain indicates a successful unauthorized access to public-facing infrastructure. The exploitation of a zero-day vulnerability in Oracle PeopleSoft suggests a critical security flaw affecting organizations using this software. The incident may undermine trust in FBI cybersecurity measures and could have broader implications if the stolen data is used for further attacks or identity theft.

Defensive Guidance

The FBI is actively investigating the incident. Organizations using Oracle PeopleSoft should monitor vendor advisories for patches related to CVE-2026-35273 or other zero-day vulnerabilities. Since the vulnerability exploited is a zero-day, no confirmed patch status is available; check Oracle's official advisories for updates. No specific mitigation steps from the FBI or Oracle are provided in the source content. Users should await official guidance and apply patches promptly once available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.84,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/shinyhunters-claims-fbi-hack-demands-retraction-of-threat-report/","fetched":true,"fetchedAt":"2026-09-23T07:17:50.169Z","wordCount":1074}

Threat ID: 6ab37d1ef7a7c541066ec144

Added to database: 09/23/2026, 07:17:50 UTC

Last enriched: 09/23/2026, 07:17:56 UTC

Last updated: 09/23/2026, 09:53:19 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses