ShinyHunters' claimed PeopleSoft zero-day breach of FBI jobs portal remains unconfirmed as group resumes mass exploitation of CVE-2026-35273
ShinyHunters claims it stole 2-3 TB of FBI employee and applicant data from FBIJobs.gov using an Oracle PeopleSoft zero-day to pressure the FBI into retracting a May 2026 bulletin; the FBI is investigating but has not confirmed the breach, while Mandiant and…
ShinyHunters told 404 Media, BleepingComputer and The Register that it breached the FBI jobs portal (FBIJobs.gov; BleepingComputer names apply.fbijobs.gov) through an unpatched Oracle PeopleSoft remote-code-execution zero-day — used for initial access on Monday night, per BleepingComputer — then moved laterally into FBI-managed AWS GovCloud infrastructure, claiming compromise of FBI Criminal Justice, HR and Medlink services. The group says it downloaded 2-3 TB of PII and PHI on current and former employees and job applicants, covering 'all' FBI employees and applicants per 404 Media or 'almost all' agents and applicants per TechCrunch. It defaced the jobs site, which 404 Media reported remained unavailable, and says its demand is removal or retraction of a May 2026 FBI FLASH report / public service announcement rather than payment; 404 Media describes the goal as coercion. The group shared a sample of roughly 5,000 records with 404 Media containing names, home addresses, phone numbers, dates of birth, job titles and, in some cases, spouse details; The Register's review of sample files also describes emails, Social Security numbers, field offices and emergency contacts. 404 Media partially verified the sample using OSINT Industries and Darkside, found three entries referencing the FBI's Remote Operations Unit (its hacking team), and cited Reuters reporting that some titles relate to China or Russia investigations. The FBI says it is investigating a claimed compromise of FBIJobs.gov and possible employee PII exposure, has not confirmed the breach or data theft, and has not determined whether the entry point was a third party or FBI systems. Separately, Mandiant and Google Threat Intelligence report that UNC6240, also known as ShinyHunters, has resumed mass exploitation of CVE-2026-35273 — a CVSS 9.8 unauthenticated RCE in the PeopleSoft PSEMHUB (Environment Management Hub) servlet that was first exploited as a zero-day in May-June 2026, mainly against universities, and patched by Oracle out-of-band on June 10, 2026. The renewed campaign evades literal-path WAF rules by requesting the URL-encoded path '/%50SEMHUB/', which WebLogic decodes and routes to the vulnerable servlet, then abuses Java deserialization to plant JSP web shells (e.g., x.jsp), run fileless commands, and deploy a signed Ple64.exe loader for the SIDEEYE backdoor, MeshAgent, and Neo-reGeorg tunnels. Dozens of systems have been hit across higher education, technology, IT services,…
Coverage timelineoldest first · each row is one article
- · 4d ago‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
404 Media· 86
ShinyHunters claims a PeopleSoft zero-day breach exposing personal data on FBI employees and applicants.
- · 4d agoShinyHunters claims FBI hack: 'This is NOT financially motivated'
The Register · Security· 80
ShinyHunters claims an Oracle PeopleSoft zero-day let it steal 2–3 TB of FBI employee data.
- · 4d agoHacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
TechCrunch · Security· 91
Vulnerabilities in this storyAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS |
|---|