FBI investigates jobs-portal breach amid PeopleSoft attacks
ShinyHunters claims FBI personnel data from FBIJobs.gov via PeopleSoft, while Mandiant says it is again exploiting CVE-2026-35273.
ShinyHunters told reporters it breached FBIJobs.gov through an Oracle PeopleSoft flaw, reached FBI-managed servers on AWS GovCloud, and stole files on current, former, and prospective employees. Journalists reviewed a sample of about 5,000 records with addresses, phone numbers, job titles, and in some cases spouses; later reporting adds Social Security numbers, field offices, emergency contacts, and medical records, while the group claims two to three terabytes or data on tens of thousands of people, including China and Russia investigators and the Remote Operations Unit. Outlets disagree on the bug: the group and some reports describe a PeopleSoft zero-day distinct from CVE-2026-35273, BleepingComputer says the jobs site was hit with a WAF bypass plus a new PSEMHUB zero-day, and the FBI says the entry point is still undetermined. The bureau told staff it declared a cyber security incident, left applicant portals offline, and notified potentially affected personnel; ShinyHunters says it wants a May 2026 FBI FLASH corrected rather than a ransom and will not publish the trove, though the 5,000-person sample has already circulated. Separately, Mandiant and Google say ShinyHunters-linked UNC6240 resumed mass exploitation of CVE-2026-35273, a CVSS 9.8 unauthenticated RCE patched on June 10, using URL encoding to bypass WAF rules and deploying JSP web shells, SIDEEYE (also called SideEye), Neo-reGeorg, and MeshAgent—SecurityWeek says MeshCentral—across education, healthcare, technology, government, and other sectors after an earlier wave affecting more than 100 organizations.
- ShinyHunters claims an Oracle PeopleSoft flaw on FBIJobs.gov led into FBI systems on AWS GovCloud and files on current, former, and prospective employees; the FBI says it is investigating and has not determined whether the entry point was…
- A journalist-reviewed sample covered about 5,000 people and included addresses, phone numbers, titles, and some spouses; other reported fields include emails, Social Security numbers, field offices, emergency contacts, and medical records.…
- The group says it sought no ransom and will not publish the trove, framing the incident as a rebuttal of a May 2026 FBI FLASH, but copies of the 5,000-person sample have circulated. Applicant portals remained offline; the FBI told staff it…
- Sources disagree on the FBI bug: some call it a PeopleSoft zero-day different from CVE-2026-35273; BleepingComputer says a WAF bypass plus a new unknown PSEMHUB zero-day. Named internal systems include FBIJobs, BEAST, MedLink, and BICS.
- CVE-2026-35273 is a CVSS 9.8 unauthenticated PeopleSoft PSEMHUB RCE, exploited as a zero-day from May 27 to June 9 and patched by Oracle on June 10. Mandiant says published workarounds without that patch are now being bypassed via URL…
- Mandiant and Google say ShinyHunters-linked UNC6240 resumed attacks, placing JSP web shells on dozens of systems plus SIDEEYE (also reported as SideEye), Neo-reGeorg, and MeshAgent; SecurityWeek instead names MeshCentral.
- The earlier wave affected 100-plus organizations, including Nissan, NAIC, and the University of Nottingham per SecurityWeek. The new wave spans education, healthcare, technology, government, agriculture, IT services, and transportation,…
- The Record says Dutch police arrested a suspected 24-year-old member in Amsterdam. The Register quotes the crew as saying it rebranded from GnosticPlayers to ShinyHunters in 2020.
Coverage timelineoldest first · each row is one article
- · 7d agoShinyHunters Claims FBI Breach Exposed Data of All Employees and Applicants
GBHackers· 74
ShinyHunters claims it stole FBI employee and applicant data via an unverified PeopleSoft zero-day; the FBI is investigating.
- · 6d agoShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The Hacker News· 82
ShinyHunters claims it breached the FBI via an Oracle PeopleSoft zero-day RCE, stealing sensitive data on agents and job applicants.
- · 6d ago
Vulnerabilities in this storyAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS |
|---|