FBI Confirms Investigation Into ShinyHunters Claims Against Its Jobs Portal
The FBI confirmed it is investigating claims of "unauthorized activity" affecting FBIjobs.gov after the extortion group ShinyHunters defaced the bureau's recruitment site on September 22, 2026, replacing agency imagery with a fake seizure banner and a Pokémon image the group has adopted as its unofficial mascot. Hours later, ShinyHunters escalated the claim, saying it had stolen data on "almost ALL FBI Agents" and job applicants — including home addresses, phone numbers, and family information — after allegedly breaching an Oracle PeopleSoft server and pivoting into an Amazon GovCloud environment. The FBI, Oracle, and Amazon have not confirmed that attack path, though people familiar with the investigation told Politico the bureau is treating the claim as credible.
Incident Details
| Attribute | Value |
|---|---|
| Target | FBIjobs.gov and Apply.fbijobs.gov (FBI recruitment/applicant portals) |
| Threat Actor | ShinyHunters (operating within the "Scattered Lapsus$ Hunters" collective) |
| Method | Alleged exploitation of an unpatched Oracle PeopleSoft HR bug, followed by a claimed pivot into an Amazon-hosted GovCloud system |
| Status | Defacement removed; applicant portals taken offline; FBI investigation ongoing, breach path unverified |
| Data Exposed | Claimed 2–3 TB of records including agent and applicant names, home addresses, phone numbers, and family details; unconfirmed by the FBI |
What Happened
On the afternoon of September 22, visitors to FBIjobs.gov found the site's official imagery replaced with a banner reading "This site has been seized by ShinyHunters" alongside the group's Pokémon mascot. An FBI spokesperson told The Record that "the FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," declining to answer further questions. By Tuesday afternoon the defacement had been removed, and both Apply.fbijobs.gov and the Special Agent Applicant portal were listed as unavailable — a status that persisted into Wednesday morning.
Later that day, ShinyHunters posted a lengthy statement on its leak site claiming a far deeper compromise: possession of data on nearly every current and former FBI employee, plus everyone who has applied for a bureau job. The group provided samples of 5,000 FBI agent records to 404 Media and other outlets, which reported the samples appeared authentic. A ShinyHunters representative told 404 Media the initial foothold came through a previously unknown bug in Oracle's PeopleSoft software used for HR and recruiting, and that the group used it to reach an Amazon GovCloud environment storing agent and applicant data, exfiltrating an estimated 2 TB to 3 TB. None of that technical narrative — the PeopleSoft flaw, the GovCloud pivot, or the total volume — has been independently confirmed by the FBI, Oracle, or Amazon.
Who Is ShinyHunters
ShinyHunters is a financially motivated data-theft and extortion group that has been active for roughly a year under its current wave of operations, though the name dates back to 2020-era breaches. The FBI's own Cyber Division has previously called the group "a big problem," and it has been linked to high-profile attacks on Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line, 7-Eleven, Coca-Cola, Cisco, Qantas, Coinbase, and the Salesforce-integration breaches that hit Instructure's Canvas platform in May 2026, disrupting K-12 and university coursework nationwide. Through 2025 and 2026, ShinyHunters increasingly operated as part of a merged collective known as "Scattered LAPSUS$ Hunters," combining Scattered Spider's social-engineering access techniques, ShinyHunters' data-theft and leak-site infrastructure, and LAPSUS$-style public extortion amplification.
Notably, the group says this attack is "not financially motivated." Its stated demand is that the FBI retract a public service announcement issued after the May Instructure breach, which ShinyHunters claims contains false allegations — including that the group conducts swatting, sends threatening texts to victims' families, or holds embarrassing photos and video for sextortion. ShinyHunters gave the bureau "a time of 1 week to correct" or remove the report before threatening to publish the full trove.
Impact Assessment
| Impact Area | Description |
|---|---|
| Personnel Safety | If verified, exposure of agents' home addresses and family details could enable swatting, harassment, or physical threats against law enforcement personnel |
| Counterintelligence Risk | Analysts warn that stolen personal data on federal agents could be leveraged by hostile foreign intelligence services for coercion or recruitment attempts |
| Operational Disruption | FBI recruitment and applicant portals remain offline, disrupting hiring pipelines for new agents and support staff |
| Reputational Exposure | A second known FBI-adjacent system compromise disclosed in 2026, following an earlier incident affecting wiretap and surveillance systems |
| Verification Gap | Core technical claims — the PeopleSoft flaw and GovCloud pivot — remain unconfirmed by the FBI, Oracle, or Amazon as of this writing |
Recommendations
For Government Agencies
- Treat any Oracle PeopleSoft HR/recruiting instance as high priority for patch review and out-of-band vulnerability scanning until Oracle issues guidance or an advisory tied to this incident
- Audit federated and cross-cloud trust relationships (e.g., on-prem PeopleSoft to Amazon GovCloud) for excessive service-account privileges or stale credentials that could enable lateral pivoting
- Establish rapid takedown and defacement-monitoring procedures for public-facing recruitment and career portals, which are lower-security surfaces than core case-management systems but carry high reputational and personnel-safety stakes
For Security Teams
- Monitor ShinyHunters' and the broader Scattered LAPSUS$ Hunters leak-site activity for sample data drops that could validate or refute the claimed breach scope
- Review PeopleSoft and other HR/ERP platforms in your own environment for outstanding patches, especially internet-facing applicant or self-service modules
- Where staff or their families could be named in a leaked government dataset, prepare incident-response and personal-safety guidance in coordination with physical security teams
For Affected Individuals
- Current and former FBI employees or job applicants should monitor official bureau communications for breach notification guidance rather than acting on unverified leak-site claims
- Consider placing fraud alerts or credit monitoring proactively, given the sensitivity of the data allegedly involved
- Report any suspicious contact — phishing, vishing, or unsolicited outreach referencing personal details — to FBI security channels immediately
Key Takeaways
- ShinyHunters defaced FBIjobs.gov on September 22, 2026, and the FBI has confirmed it is investigating "unauthorized activity" affecting the site.
- The group's follow-on claim — theft of data on nearly all FBI agents and job applicants via an Oracle PeopleSoft bug and an Amazon GovCloud pivot — remains unverified by the FBI, Oracle, or Amazon.
- ShinyHunters provided 5,000 sample agent records to journalists, which were reported as appearing authentic, lending some credibility to the broader claim even without full confirmation.
- The group states the attack is not financially motivated; its demand is retraction of an FBI public service announcement tied to the May 2026 Instructure/Canvas breach.
- If confirmed, exposure of agents' home addresses and family data would raise serious personnel-safety and counterintelligence concerns beyond typical data-breach fallout.
- This is the second known FBI-adjacent system compromise disclosed in 2026, underscoring continued targeting of federal law enforcement infrastructure by the ShinyHunters/Scattered LAPSUS$ Hunters collective.