ShinyHunters claims it exploited an alleged pre-authentication Oracle PeopleSoft zero-day for remote code execution against an FBI jobs webpage, defaced the site, and pivoted into FBI-managed AWS GovCloud infrastructure. The group says it exfiltrated roughly 2–3 TB of data involving current, former, and prospective FBI personnel, as well as agents’ spouses; reported sample records include names, home addresses, and phone numbers, some of which were reportedly verified against public records.
The group says the intrusion was not financially motivated and demands that the FBI retract or correct allegations in a May 15 bulletin linking ShinyHunters to harassment, threatening communications, and swatting. The claims, including the alleged PeopleSoft vulnerability, lateral movement, and data theft, remain unverified: the FBI, Oracle, and AWS had not publicly confirmed the incident. If authentic, the exposure could enable targeted harassment, coercion, extortion, or counterintelligence targeting of FBI personnel and their families.

See the actors and campaigns active against you right now.
21 events from the most recent confirmed update back to the earliest known activity.
Mandiant and Google Threat Intelligence Group reported that UNC6240/ShinyHunters renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273 against organizations globally across sectors including education, technology, healthcare, transportation, and government. The actor reportedly bypassed literal-path WAF rules with an encoded PSEMHUB path and deployed JSP web shells, Neo-reGeorg, MeshAgent, and a trojanized Light Alloy installer delivering the SIDEEYE backdoor.
ShinyHunters allegedly hijacked and defaced the Clop ransomware gang’s dark-web leak site between September 18 and 19, including posting an extortion demand directed at Clop.
Dutch authorities reportedly arrested a suspected ShinyHunters associate earlier in September, before the group claimed responsibility for the alleged FBIJobs.gov intrusion.
FBI Cyber Division Assistant Director Brett Leatherman publicly urged remaining ShinyHunters members to contact investigators after Dutch authorities arrested an alleged group leader. He said the suspect and alleged co-conspirators had breached more than 140 organizations and collected at least $70 million in extortion payments since the prior year, and indicated seized infrastructure could help identify additional members.
ShinyHunters said it did not intend to publish the FBI personnel data it claimed to have stolen from the FBIJobs.gov-related intrusion, while not stating that it had deleted the alleged records. The group continued to characterize its demand for retraction of the FBI's May 15 advisory as a marketing campaign.
The FBI internally notified agents and support staff that a cybersecurity incident involving its FBIJobs.gov portal compromised personal information. The notification reportedly acknowledged exposure of personnel and applicant HR data, including names, addresses, job titles, Social Security numbers, and medical and psychiatric records; the portal remained offline.
Malwarebytes reported that samples of ShinyHunters’ purported FBI data included fitness-for-work medical examinations containing agents’ names, contact and badge details, spouse information, laboratory results, and physicians’ notes. The group claimed it accessed FBI MedLink and BEAST and alleged that roughly 60,000 current and former personnel were affected, but the FBI had not confirmed those system-access or data-theft claims.
ZDNet reported that ShinyHunters' purported 5,000-row FBI dataset included Social Security numbers, personal and emergency-contact details, geographic assignments, and affiliations with sensitive units and investigations involving China, Russia, Iran, HUMINT, data interception, and clandestine technical operations. The claims remained tied to the unverified alleged FBIJobs.gov compromise.
404 Media reported that the dataset exposing personal information for thousands of FBI officials reportedly included members of the FBI's Remote Operations Unit, a secretive team that develops exploits and device-access tools. The exposed addresses, phone numbers, and spouse details could potentially identify ROU personnel, though the actor, intrusion method, and number of affected unit members were not disclosed.
An FBI spokesperson reportedly told 404 Media that ShinyHunters exploited an Oracle PeopleSoft zero-day, pivoted into AWS GovCloud servers, and downloaded roughly 2–3 TB of data. This represented reported official confirmation of technical details that the FBI had previously not confirmed publicly.
The FBI said it had not determined whether the reported FBIjobs.gov intrusion involved a third-party provider or the FBI enterprise, and that it was working with providers supporting the jobs site to mitigate risk. FBI personnel were reportedly advised to take steps to protect themselves while the investigation continued.
Following the reported unauthorized activity affecting FBIjobs.gov, the FBI took its application service and Special Agent Applicant Portal offline. The portal had briefly displayed a counterfeit ShinyHunters seizure notice.
The FBI said it was aware of claims of unauthorized activity affecting FBIjobs.gov and was investigating. It did not confirm ShinyHunters' alleged PeopleSoft exploit, GovCloud access, or data theft.
ShinyHunters said the alleged FBI intrusion was not financially motivated and demanded that the FBI correct or retract statements accusing the group of harassment, threats, swatting, and false claims of compromising material. The FBI, Oracle, and AWS had not confirmed the alleged breach, vulnerability, lateral movement, or data theft.
Reuters reportedly matched information in at least 10 records from ShinyHunters' purported FBI data sample using credit-bureau records and previously breached data held by District 4 Labs. Reuters could not determine the records' origin or confirm they were taken from FBI internal systems.
404 Media reported receiving a sample containing about 5,000 purported FBI employee records and said some phone numbers in the sample corresponded to the named individuals and U.S. Department of Justice personnel. The alleged FBI breach, the origin of the records, and the claimed PeopleSoft exploit remained unverified.
ShinyHunters published an unverified claim that it breached the FBI via an alleged pre-authentication Oracle PeopleSoft remote-code-execution zero-day, defaced the FBI jobs site, pivoted into FBI-managed AWS GovCloud systems, and exfiltrated roughly 2–3 TB of data. The group said the alleged data included information on current, former, and prospective FBI personnel, including agents, applicants, and spouses; samples reportedly contained names, addresses, and phone numbers.
Oracle issued an emergency patch for the PeopleSoft vulnerability CVE-2026-35273 and advised organizations unable to patch to restrict PeopleSoft application and web-server access to trusted internal networks. Mandiant warned that WAF body-inspection rules alone were insufficient because ShinyHunters could bypass string-based rules using URL encoding.
ShinyHunters had reportedly been observed exploiting a PeopleSoft zero-day to steal organizational data in June. It was unclear whether that activity involved CVE-2026-35273 or a different PeopleSoft vulnerability.
In its May 15 bulletin, the FBI said ShinyHunters used harassment tactics including threatening calls and text messages to victims and their families, and in some cases swatting. The bulletin also warned that extortionists may falsely claim to possess sensitive or compromising material.
ShinyHunters reportedly attacked educational-software company Instructure, disrupting operations at thousands of U.S. universities and K-12 schools. Instructure reportedly later paid a ransom to restore its services.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
50 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcemalware.news
Open sourcecyberveille.ch
Open sourcehackread.com
Open sourcebbc.com
Open sourcecyberscoop.com
Open sourcehackread.com
Open sourcereuters.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.