ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
The cybercrime group ShinyHunters claims to have breached FBI systems, including Criminal Justice, HR, and Medlink services, allegedly stealing data on nearly all FBI agents and job applicants. They demonstrated their claim by defacing a subdomain of the FBI jobs website. The group disputes certain characterizations made about them in an FBI report and demands its retraction. The FBI is investigating the unauthorized activity but has not confirmed the breach. ShinyHunters claims to have exploited a zero-day vulnerability in Oracle PeopleSoft, possibly CVE-2026-35273, to conduct the breach. A sample of stolen data was provided and partially verified as authentic by third parties, though the origin remains unconfirmed.
AI Analysis
Technical Summary
ShinyHunters, a known cybercrime and extortion group, alleges they compromised FBI systems by exploiting a zero-day vulnerability in Oracle PeopleSoft software, potentially CVE-2026-35273. They claim to have stolen 2-3 TB of sensitive data including personal information of FBI employees and job applicants. To support their claim, they defaced the FBI jobs subdomain and posted a seizure message. The group disputes negative assertions made in an FBI FLASH report about their tactics and affiliations. The FBI has acknowledged the investigation but has not disclosed further details. Independent reviewers have found some of the leaked data sample to appear authentic, though full verification is pending.
Potential Impact
If confirmed, the breach exposes sensitive personal information of thousands of FBI employees and applicants, potentially compromising privacy and operational security. The defacement of an FBI subdomain indicates a successful unauthorized access to public-facing infrastructure. The exploitation of a zero-day vulnerability in Oracle PeopleSoft suggests a critical security flaw affecting organizations using this software. The incident may undermine trust in FBI cybersecurity measures and could have broader implications if the stolen data is used for further attacks or identity theft.
Mitigation Recommendations
The FBI is actively investigating the incident. Organizations using Oracle PeopleSoft should monitor vendor advisories for patches related to CVE-2026-35273 or other zero-day vulnerabilities. Since the vulnerability exploited is a zero-day, no confirmed patch status is available; check Oracle's official advisories for updates. No specific mitigation steps from the FBI or Oracle are provided in the source content. Users should await official guidance and apply patches promptly once available.
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Description
The cybercrime group ShinyHunters claims to have breached FBI systems, including Criminal Justice, HR, and Medlink services, allegedly stealing data on nearly all FBI agents and job applicants. They demonstrated their claim by defacing a subdomain of the FBI jobs website. The group disputes certain characterizations made about them in an FBI report and demands its retraction. The FBI is investigating the unauthorized activity but has not confirmed the breach. ShinyHunters claims to have exploited a zero-day vulnerability in Oracle PeopleSoft, possibly CVE-2026-35273, to conduct the breach. A sample of stolen data was provided and partially verified as authentic by third parties, though the origin remains unconfirmed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ShinyHunters, a known cybercrime and extortion group, alleges they compromised FBI systems by exploiting a zero-day vulnerability in Oracle PeopleSoft software, potentially CVE-2026-35273. They claim to have stolen 2-3 TB of sensitive data including personal information of FBI employees and job applicants. To support their claim, they defaced the FBI jobs subdomain and posted a seizure message. The group disputes negative assertions made in an FBI FLASH report about their tactics and affiliations. The FBI has acknowledged the investigation but has not disclosed further details. Independent reviewers have found some of the leaked data sample to appear authentic, though full verification is pending.
Potential Impact
If confirmed, the breach exposes sensitive personal information of thousands of FBI employees and applicants, potentially compromising privacy and operational security. The defacement of an FBI subdomain indicates a successful unauthorized access to public-facing infrastructure. The exploitation of a zero-day vulnerability in Oracle PeopleSoft suggests a critical security flaw affecting organizations using this software. The incident may undermine trust in FBI cybersecurity measures and could have broader implications if the stolen data is used for further attacks or identity theft.
Defensive Guidance
The FBI is actively investigating the incident. Organizations using Oracle PeopleSoft should monitor vendor advisories for patches related to CVE-2026-35273 or other zero-day vulnerabilities. Since the vulnerability exploited is a zero-day, no confirmed patch status is available; check Oracle's official advisories for updates. No specific mitigation steps from the FBI or Oracle are provided in the source content. Users should await official guidance and apply patches promptly once available.
Technical Details
- Classification
- {"confidence":0.84,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/shinyhunters-claims-fbi-hack-demands-retraction-of-threat-report/","fetched":true,"fetchedAt":"2026-09-23T07:17:50.169Z","wordCount":1074}
Threat ID: 6ab37d1ef7a7c541066ec144
Added to database: 09/23/2026, 07:17:50 UTC
Last enriched: 09/23/2026, 07:17:56 UTC
Last updated: 09/23/2026, 09:53:19 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.