5,000 Records, One Sentence From the FBI
ShinyHunters says it owns the Bureau's HR system. The FBI's fourteen-word acknowledgment neither confirms nor denies it, and that gap is the story operators should be watching.

"We hacked the FBI." That's the entire pitch ShinyHunters posted to its dark-web leak site Tuesday, and it is doing a lot of work for four words.
The group says it broke into FBI-managed systems through an unpatched Oracle PeopleSoft zero-day, moved laterally into AWS GovCloud infrastructure, and walked out with between two and three terabytes of data on current and former employees and job applicants. It handed 404 Media a sample of roughly 5,000 records. Reuters ran names and addresses against credit bureau records and dark-web intelligence archives and found matches in at least ten cases, including details that appeared to correspond to FBI Director Kash Patel.
This isn't a ransom story. It's a hostage story where the hostage is the Bureau's credibility.
The Sentence Built to Say Nothing
The FBI's entire public response: the bureau said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
Translation: we have seen the tweet. We are not going to tell you if it's true, because true has consequences we're not ready to manage in public.
That sentence confirms FBIjobs.gov had a problem worth investigating, while conceding nothing about scope, volume, or which internal services were touched. ShinyHunters claims the intrusion reached Criminal Justice, HR, and Medlink services. The FBI hasn't addressed that.
ShinyHunters wants the FBI to retract a May 15 advisory describing the group's harassment tactics. That's not a criminal enterprise chasing a payday. It's a criminal enterprise trying to win a public relations dispute with federal law enforcement, using stolen HR data as leverage.

A Second Zero-Day, or the Same Playbook With Better Timing?
This isn't ShinyHunters' first PeopleSoft target. Oracle patched a critical, unauthenticated PeopleSoft PeopleTools flaw, CVE-2026-35273, on June 10 after Mandiant found it had already been exploited in the wild for two weeks. Hackers affiliated with the group had used chained vulnerabilities against roughly 300 PeopleSoft instances across more than 100 organizations before that patch landed.
Now ShinyHunters says it found a fresh, unpatched flaw in the same product Monday night and used it immediately against the FBI. No CVE. No public advisory. No emergency mitigation guidance from Oracle, as of this writing.
If that claim is accurate, the same enterprise HR platform that already burned 100-plus organizations in June has a second hole in it, and the only entity that currently knows the details is the group exploiting it.
You do not need the FBI to confirm a breach to know your exposure. If you run PeopleSoft anywhere in your HR or applicant-tracking stack, the operating assumption should be that an unpatched remote-code-execution path exists right now. Waiting for Oracle's next advisory or the Bureau's next statement is not a security posture. It's a bet that nobody hits you first.
What to watch: an Oracle emergency alert naming a second PeopleSoft CVE distinct from CVE-2026-35273; whether the FBI's "investigating" language upgrades to a confirmed-incident notice under federal breach disclosure rules; a DOJ Inspector General referral; and whether other organizations running PeopleSoft report intrusions in the next two to three weeks that trace back to the same access ShinyHunters says it's already reselling.
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
- 'We Hacked the FBI': ShinyHunters Hands Over 5,000 Employee Records
- ShinyHunters claims FBI hack: 'This is NOT financially motivated'
- ShinyHunters hackers say they breached FBI, stole employee data
- FBI investigates claim notorious hacking group stole employee data
- CVE-2026-35273: Oracle PeopleSoft RCE Zero-Day Explained
- Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
- Hacker group ShinyHunters claims massive breach of FBI employee data
- ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day | CyberInsider
- ShinyHunters Claims FBI Data Breach: Hacker Group Says It Stole Records of All Employees and Applicants | LatestLY
- ShinyHunters claims FBI data theft, demands bureau retract cyber warning - Nextgov/FCW
- ShinyHunters claims FBI data theft, demands bureau retract cyber warning - Government Executive
- Hacker Group ShinyHunters Claims FBI Breach as 5,000-Record Sample Raises Fears for Agents' Families | IBTimes UK
- ShinyHunters claims FBI breach exposed employees and applicants
- ShinyHunters hackers say they breached FBI, stole employee data
- Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data | TechCrunch
- ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate FBI comment
- ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate comment from FBI | Top News | lufkindailynews.com
- The ShinyHunters hackers claimed they hacked the FBI’s system and stole employees’ data - media reports | УНН
- Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
- Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273) Actively Exploited: Urgent Patch Required to Prevent Ransomware and Data Breaches – Rescana
- Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
- CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation
- Oracle Security Alert Advisory - CVE-2026-35273
- Oracle Critical Security Patch Update Advisory - September 2026
- Zeroday Emergency Response Team
- FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
- Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS
- ShinyHunters: All You Need to Know | Red Piranha
- 2026 Canvas data breach
- Cyber Intel Brief: ShinyHunters Claims Breach of Canvas LMS
- How the Instructure Canvas Breach Exposes 275 Million Students and Faculty to Spear Phishing, Extortion, and Identity Fraud - UC Berkeley Law
- Threat Advisory: ShinyHunters Canvas Attack
- Canvas/Instructure cyberattack – Key developments and action items for higher education institutions
- ShinyHunters 2026 Breach Tracker (January–May 2026)