5
min read
September 25, 2026

ShinyHunters Went After the FBI. The Entry Point Was an HR System.

Some breach headlines make you roll your eyes. Others make you stop and read the whole thing twice. On Tuesday, September 22, visitors to FBIjobs.gov were greeted with a message reading "This site has been seized by ShinyHunters."

According to 404 Media, the group's claim was about as blunt as it gets: "We hacked the FBI. We hold data on all FBI employees and applicants."

Yes, the same ShinyHunters behind the Madison Square Garden leak back in June. And the Instructure Canvas data breach. They've had a busy year.

Before going further, a caveat. Most of what we know right now comes from the attackers themselves. The FBI has said only that it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."

It has not confirmed that any data was taken. Still, the details that have come out so far are worth looking at closely, because the way this reportedly happened should feel very familiar to anyone who runs security for a company.

What ShinyHunters Is Claiming

Based on reporting from 404 Media, BleepingComputer, SecurityWeek and Axios, here is what the group says it did:

  1. Got in through Oracle PeopleSoft. The group says it used a previously unknown PeopleSoft vulnerability that allows remote code execution. SecurityWeek noted it may be CVE-2026-35273, a PeopleSoft flaw ShinyHunters was already confirmed to be exploiting back in June. That link hasn't been confirmed.
  2. Moved laterally into AWS GovCloud. From there, the attackers say they reached FBI-managed cloud infrastructure and pulled down 2 to 3 terabytes of data from the Bureau's Criminal Justice, HR and Medlink services.
  3. Covered their tracks. They claim they tried to wipe evidence to hide how the zero-day works, and that they're now using the same flaw against Fortune 500 companies.

To back this up, the group handed 404 Media a sample of 5,000 employee records containing names, home addresses, phone numbers, dates of birth and spouse information. Axios reported that some of the spouse data includes Social Security numbers. 404 Media checked some of the phone numbers against other sources, and several appeared to be real.

"Not Extortion, Maybe Coercion"

The motive is where this one gets strange. ShinyHunters says the attack isn't about money. It's retaliation for an FBI FLASH report from May that described the group's tactics, including exaggerating what they've stolen and harassing victims with things like swatting.

The group wants the FBI to correct or pull that report within a week. Their own description of the demand: "not extortion, maybe coercion."

So the group accused of pressuring victims with stolen data is pressuring the FBI with stolen data to say it doesn't do that. I'll let that sit for a second.

Former FBI cyber official Cynthia Kaiser told CyberScoop that going after law enforcement like this "demonstrates a lack of discipline that historically has led to takedowns." She's probably right. But a future arrest doesn't do much for the agents whose home addresses are now sitting on a criminal forum.

Why the HR Stack Keeps Getting Hit

Take the FBI out of the story and look at the path. An enterprise HR application with a flaw nobody knew about. A connection from that application into cloud infrastructure. A huge pile of personal data sitting where the attacker landed. None of that is unique to a federal agency. Plenty of mid-sized companies are set up the exact same way.

HR systems are some of the most valuable targets in any organization, and they tend to get less attention than they should. Think about what lives in them: home addresses, Social Security numbers, bank details, background checks, medical and benefits information, performance notes, family members.

For an agency like the FBI, add one more thing. A list of people with security clearances, where they sleep at night, and who they're married to is a gift to anyone doing social engineering or worse.

And then there are the applicants. Most people who apply for a job with the FBI never end up working there. Their data was still apparently sitting in these systems, waiting. We saw the same thing with MSG, where years of retained data ended up in a public dump. If you don't need it anymore, it shouldn't be there. Data you've deleted can't be stolen.

The Blast Radius Problem

The detail I keep coming back to is the lateral movement. A vulnerability in a single application is bad. A vulnerability in a single application that leads straight into your cloud environment, and then into multiple unrelated services, is a very different problem.

A few questions every security team should be asking right now:

Do you know what your HR platform is connected to? Integrations, service accounts, API keys and cloud roles pile up over years. Each one is a possible bridge for someone who gets a foothold in one system.

How much access do those connections actually have? If a job portal can reach criminal justice or medical data, something went wrong well before any attacker showed up. Service identities should be scoped to what they need and nothing more.

Would you notice 2 or 3 terabytes leaving? That's not a quiet trickle. Bulk data movement from systems that don't normally move bulk data should set off alarms right away, not show up in a report next quarter.

How long do you keep applicant and former employee data? Set retention rules and enforce them automatically. Leaving this to manual cleanup means it won't happen.

Are you patching the "boring" enterprise apps as fast as the exciting ones? PeopleSoft doesn't get headlines, but it runs payroll and HR at thousands of organizations. If ShinyHunters really is turning this flaw on private companies, the window to check your exposure is now.

What Comes Next

We'll learn a lot more over the next week or so. The FBI may confirm or deny the scope. Oracle may issue guidance. ShinyHunters' one-week deadline will come and go, and we'll find out what they meant by "maybe coercion."

Whatever the final numbers look like, the takeaway for everyone else is already clear. The most sensitive data most organizations hold isn't in a vault somewhere. It's in the HR system, it's connected to a lot more than people realize, and it's often been there far longer than it needs to be.

If one of the most security-conscious organizations in the country can be exposed through a job portal, it's worth taking a hard look at your own.

Albert is DoControl's Principal Solutions Engineer, where he leverages his extensive background in both pre-sales and post-sales consulting to help organizations strengthen their data protection strategies. Albert has built a reputation as a trusted technical consultant who bridges the gap between complex security solutions and real-world business needs.

His unique background in technical support has proven invaluable in winning customer trust, demonstrating his ability to translate technical expertise into measurable business outcomes. He brings this same combination of technical depth and customer-focused thinking to his writing, offering practical insights for security and IT professionals navigating the evolving SaaS security landscape.

The worst time to discover exposed data is after someone else finds it. 🔎

Your sensitive data could already be somewhere it shouldn’t be. Take our free risk assessment and find out before someone else does.

Get updates to your inbox

Our latest tips, insights, and news
Tablet top edge with front camera and purple slider control with four dots.