ShinyHunters claims FBI jobs breach amid PeopleSoft attacks
ShinyHunters says it stole FBI personnel data via FBIJobs.gov while resuming mass attacks on Oracle PeopleSoft flaw CVE-2026-35273.
ShinyHunters, tracked by Mandiant as UNC6240, told reporters it breached FBIJobs.gov through an Oracle PeopleSoft flaw, reached FBI-managed servers on AWS GovCloud, and stole personnel files. Journalists reviewed a verified sample of about 5,000 records that included addresses, phone numbers, job titles, and in some cases spouses; later reporting also describes Social Security numbers, medical information, China- and Russia-related assignments, and Remote Operations Unit staff. Volume claims are not reconciled: about 5,000 people in the shared sample, versus a stated two to three terabytes or tens of thousands of current, former, and prospective employees. The FBI said it is investigating and has not determined whether a third party or FBI systems were the entry point; TechCrunch reported the bureau internally declared a cybersecurity incident, told staff that personal data was stolen, notified personnel, and left the jobs portal—its main applicant site since 2017—offline. Separately, Mandiant and Google said the same actor resumed mass exploitation of CVE-2026-35273, a CVSS 9.8 unauthenticated PeopleSoft remote-code-execution flaw used as a zero-day from May 27 to June 9, 2026, and patched by Oracle on June 10. Attackers are bypassing firewall rules aimed at the vulnerable PSEMHUB path and have deployed web shells on dozens of systems across education, technology, healthcare, government, and other sectors, plus a SIDEEYE backdoor (also spelled SideEye) and tunneling or remote-management tools. Sources disagree on whether the FBI breach used that CVE, a different PeopleSoft zero-day, or both, and on MeshAgent versus MeshCentral. The group said the FBI incident was not for ransom and was meant to force correction of a May 2026 FBI FLASH or advisory, later telling 404 Media it would not publish the trove even though the sample was already circulating, while Mandiant still ties the wider campaign to data-theft extortion. The Record also reported that Dutch police arrested a suspected member in Amsterdam.
- ShinyHunters (Mandiant: UNC6240) claims an Oracle PeopleSoft breach of FBIJobs.gov that reached AWS GovCloud; the FBI says it is investigating, the entry point is still undetermined, and TechCrunch reports the bureau told staff personal…
- Journalists reviewed a sample of about 5,000 personnel records with addresses, phones, titles, and some spouses; other accounts add SSNs, medical records, a claimed 2–3 TB, or data on tens of thousands of current, former, and prospective…
- The FBI declared a cybersecurity incident, notified potentially affected staff, and left job portals offline. The group says it sought no ransom and wanted a May 2026 FBI FLASH or advisory corrected, then told 404 Media it would not…
- CVE-2026-35273 is a CVSS 9.8 unauthenticated RCE in PeopleSoft PSEMHUB, used as a zero-day from May 27 to June 9, 2026. Oracle patched it on June 10; Mandiant says workarounds without that patch are now being bypassed.
- The new wave placed web shells on dozens of systems in education, technology, healthcare, government, agriculture, IT services, and transport. An earlier wave prompted notice to 100-plus organizations, including Nissan, NAIC, and the…
- Reported tooling includes JSP web shells, SIDEEYE/SideEye (Ple64.exe), Neo-reGeorg, and MeshAgent; SecurityWeek instead names MeshCentral. One report lists C2 indicators 5.199.162.157, 104.219.234.138, 162.219.30.165, and…
- Sources disagree on whether the FBI incident used CVE-2026-35273, a separate unpublished PeopleSoft zero-day, or both. The Record also reports Dutch police arrested a suspected 24-year-old member in Amsterdam.
- Sample records reference the FBI Remote Operations Unit, and some titles relate to China or Russia investigations. Named internal systems in one account include FBIJobs, BEAST, MedLink, and BICS.
Coverage timelineoldest first · each row is one article
- · 7d agoShinyHunters Allegedly Claims Breach of FBI Jobs Site and Stolen Agents’ Data
Cyber Security News· 81
ShinyHunters claims it breached FBI jobs systems, defaced the portal, and stole personnel records; the FBI is investigating.
Vulnerabilities in this storyAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS |
|---|