◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL◆ NOISE IN → SIGNAL OUT◆ READALCHEMIST.COM◆ FREE / NO PAYWALL
THE DIGITAL ALCHEMIST
SecurityIMPACT 88

5,000 Records, One Sentence From the FBI

ShinyHunters says it owns the Bureau's HR system. The FBI's fourteen-word acknowledgment neither confirms nor denies it, and that gap is the story operators should be watching.

2026-09-235 MIN READ#ShinyHunters · #FBI · #Oracle PeopleSoft · #zero-day · #data breach · #federal cybersecurity
Dirksen Federal Building, US Courthouse by Chicago Crime Scenes (BY) via Openverse
Dirksen Federal Building, US Courthouse by Chicago Crime Scenes (BY) via Openverse

"We hacked the FBI." That's the entire pitch ShinyHunters posted to its dark-web leak site Tuesday, and it is doing a lot of work for four words.

The group says it broke into FBI-managed systems through an unpatched Oracle PeopleSoft zero-day, moved laterally into AWS GovCloud infrastructure, and walked out with between two and three terabytes of data on current and former employees and job applicants. It handed 404 Media a sample of roughly 5,000 records. Reuters ran names and addresses against credit bureau records and dark-web intelligence archives and found matches in at least ten cases, including details that appeared to correspond to FBI Director Kash Patel.

This isn't a ransom story. It's a hostage story where the hostage is the Bureau's credibility.

The Sentence Built to Say Nothing

The FBI's entire public response: the bureau said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."

Translation: we have seen the tweet. We are not going to tell you if it's true, because true has consequences we're not ready to manage in public.

That sentence confirms FBIjobs.gov had a problem worth investigating, while conceding nothing about scope, volume, or which internal services were touched. ShinyHunters claims the intrusion reached Criminal Justice, HR, and Medlink services. The FBI hasn't addressed that.

ShinyHunters wants the FBI to retract a May 15 advisory describing the group's harassment tactics. That's not a criminal enterprise chasing a payday. It's a criminal enterprise trying to win a public relations dispute with federal law enforcement, using stolen HR data as leverage.

The Claim, By the Numbers
5,000Sample records sharedwith reporters3Data claimed stolen(TB)10Reuters-verifiedname/address matches
Figures as claimed by ShinyHunters and reported by 404 Media, Reuters, and BleepingComputer, Sept. 22, 2026.
The Digital Alchemist
The Digital Alchemist

A Second Zero-Day, or the Same Playbook With Better Timing?

This isn't ShinyHunters' first PeopleSoft target. Oracle patched a critical, unauthenticated PeopleSoft PeopleTools flaw, CVE-2026-35273, on June 10 after Mandiant found it had already been exploited in the wild for two weeks. Hackers affiliated with the group had used chained vulnerabilities against roughly 300 PeopleSoft instances across more than 100 organizations before that patch landed.

Now ShinyHunters says it found a fresh, unpatched flaw in the same product Monday night and used it immediately against the FBI. No CVE. No public advisory. No emergency mitigation guidance from Oracle, as of this writing.

If that claim is accurate, the same enterprise HR platform that already burned 100-plus organizations in June has a second hole in it, and the only entity that currently knows the details is the group exploiting it.

You do not need the FBI to confirm a breach to know your exposure. If you run PeopleSoft anywhere in your HR or applicant-tracking stack, the operating assumption should be that an unpatched remote-code-execution path exists right now. Waiting for Oracle's next advisory or the Bureau's next statement is not a security posture. It's a bet that nobody hits you first.

What to watch: an Oracle emergency alert naming a second PeopleSoft CVE distinct from CVE-2026-35273; whether the FBI's "investigating" language upgrades to a confirmed-incident notice under federal breach disclosure rules; a DOJ Inspector General referral; and whether other organizations running PeopleSoft report intrusions in the next two to three weeks that trace back to the same access ShinyHunters says it's already reselling.

Sources
  1. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
  2. 'We Hacked the FBI': ShinyHunters Hands Over 5,000 Employee Records
  3. ShinyHunters claims FBI hack: 'This is NOT financially motivated'
  4. ShinyHunters hackers say they breached FBI, stole employee data
  5. FBI investigates claim notorious hacking group stole employee data
  6. CVE-2026-35273: Oracle PeopleSoft RCE Zero-Day Explained
  7. Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks
  8. Hacker group ShinyHunters claims massive breach of FBI employee data
  9. ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day | CyberInsider
  10. ShinyHunters Claims FBI Data Breach: Hacker Group Says It Stole Records of All Employees and Applicants | LatestLY
  11. ShinyHunters claims FBI data theft, demands bureau retract cyber warning - Nextgov/FCW
  12. ShinyHunters claims FBI data theft, demands bureau retract cyber warning - Government Executive
  13. Hacker Group ShinyHunters Claims FBI Breach as 5,000-Record Sample Raises Fears for Agents' Families | IBTimes UK
  14. ShinyHunters claims FBI breach exposed employees and applicants
  15. ShinyHunters hackers say they breached FBI, stole employee data
  16. Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data | TechCrunch
  17. ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate FBI comment
  18. ShinyHunters hackers say they breached Federal Bureau of Investigation, no immediate comment from FBI | Top News | lufkindailynews.com
  19. The ShinyHunters hackers claimed they hacked the FBI’s system and stole employees’ data - media reports | УНН
  20. Active Exploitation of Oracle PeopleSoft Zero-Day (CVE-2026-35273)
  21. Oracle PeopleSoft PeopleTools Zero-Day (CVE-2026-35273) Actively Exploited: Urgent Patch Required to Prevent Ransomware and Data Breaches – Rescana
  22. Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
  23. CVE-2026-35273 in Oracle PeopleSoft PeopleTools EMHub Under Active Exploitation
  24. Oracle Security Alert Advisory - CVE-2026-35273
  25. Oracle Critical Security Patch Update Advisory - September 2026
  26. Zeroday Emergency Response Team
  27. FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
  28. Technical Advisory: ShinyHunters Breach of Instructure Canvas LMS
  29. ShinyHunters: All You Need to Know | Red Piranha
  30. 2026 Canvas data breach
  31. Cyber Intel Brief: ShinyHunters Claims Breach of Canvas LMS
  32. How the Instructure Canvas Breach Exposes 275 Million Students and Faculty to Spear Phishing, Extortion, and Identity Fraud - UC Berkeley Law
  33. Threat Advisory: ShinyHunters Canvas Attack
  34. Canvas/Instructure cyberattack – Key developments and action items for higher education institutions
  35. ShinyHunters 2026 Breach Tracker (January–May 2026)
← back to the feed
NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%NVDA 230.86 ▲ 1.09%AAPL 330.32 ▼ 0.81%MSFT 512.80 ▼ 0.02%GOOGL 338.24 ▼ 1.70%AMZN 248.23 ▼ 0.37%META 725.93 ▲ 0.10%TSLA 354.11 ▼ 0.20%AMD 615.73 ▲ 0.65%AVGO 343.64 ▼ 2.15%PLTR 190.04 ▲ 1.60%COIN 189.29 ▲ 1.54%MSTR 160.50 ▲ 4.84%