The FBI is investigating an intrusion into its jobs portal after the extortion crew ShinyHunters claimed it defaced the site and walked off with employee files.
The group says it stole 2TB to 3TB of data covering current, former and prospective agents, and lists human resources, MedLink and Criminal Justice Information Services among the systems it reached.
Its route in, according to a spokesperson who spoke to The Register, was an Oracle PeopleSoft zero-day that gave remote code execution on the servers behind fbijobs.gov. From there the crew says it moved sideways into FBI-managed servers on AWS GovCloud. The jobs site was replaced with a “This site has been seized by ShinyHunters” banner before being taken offline for maintenance.
No previous PeopleSoft pre-authentication RCE is publicly documented, though the gang weaponised a related flaw, CVE-2026-35273, in June.
The unusual part is the motive. ShinyHunters says it is not chasing a ransom, but wants the FBI to retract a May bulletin that accused the group of harassment, swatting and inflated data-theft claims. That advisory followed its raid on Instructure’s Canvas platform. The crew has given the bureau a one-week deadline and addressed its post to FBI Director Kash Patel.
Analysts see risk in the move. Cynthia Kaiser of Halcyon called the public shaming a lack of discipline that historically invites takedowns, while Flashpoint said the stunt still strengthens the brand’s credibility. Etay Maor of Cato Networks noted the post carried a September 23 timestamp while the news broke on September 22 in the US, a detail that could point to an operator working from Asia.
