Skip to content
TEN Brief Ten verified stories a day 2026.09.27 KO

이 기사는 한국어로도 읽을 수 있습니다 →

Tech · 2 min read · Breaking

FBI breach claims agent data leak — it began with one HR server

The hacking group ShinyHunters says it breached the FBI on September 21-22, 2026 (US time), defacing the FBIjobs.gov recruiting site and claiming 2 to 3 terabytes of data on current and former agents and job applicants. A sample of about 5,000 agent records given to 404 Media and other outlets was confirmed as genuine; it includes names, home addresses, Social Security numbers, assignments and in some cases family members. The group says it got in through an unknown flaw in an Oracle PeopleSoft HR server and moved into an AWS GovCloud environment. The FBI says only that it is investigating. ShinyHunters demanded the bureau retract a May 15 public warning about the group within one week

Analysts seen from behind watching large network-map screens in a sunlit security operations center

The three lines

  • Incident — FBIjobs.gov defaced September 21-22; 2–3 TB of agent and applicant data claimed; a ~5,000-record sample confirmed genuine by several outlets
  • Path — an unknown Oracle PeopleSoft (HR software) flaw, then AWS GovCloud, per the group; the FBI says it is investigating
  • Demand — not money but retraction of the FBI's May 15 warning within a week; experts worry more about the data being sold on

Key questions

What data was stolen in the FBI breach
**Personal data on agents and applicants, and possibly medical data, according to the hackers.** | Item | Detail | Status | |---|---|---| | Size | 2–3 TB | hacker claim | | Who | current and former agents, applicants | hacker claim | | Sample | about **5,000** agent records | **confirmed genuine** by 404 Media and others | | Sample contents | names, home addresses, **Social Security numbers**, assignments, some family members | confirmed by outlets | | Also claimed | medical records, prescriptions, diagnoses (Medlink) | hacker claim | | Systems named | PEGA, Medlink, FBIJOBS, HR, CJ, PHIRE | hacker claim | **A genuine sample does not prove the full claimed scale.** The FBI said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
How was the FBI hacked
**Through a piece of HR software, the group says.** | Step | Detail | |---|---| | 1. Entry | an Oracle **PeopleSoft** server used for recruiting and HR | | 2. Method | an **unknown flaw** allowing remote code execution without login | | 3. Movement | pivot into Amazon Web Services **GovCloud** to reach the data | | 4. Signature | recruiting-site images swapped for a Pokemon mascot and "This site has been seized by ShinyHunters" | The Hacker News reports a different PeopleSoft flaw (CVE-2026-35273) was exploited in June. The FBI has not said whether the entry point was its own system or a third-party provider.
Who is ShinyHunters
**A data-theft and extortion group that has hit major companies for nearly a year.** | Item | Detail | |---|---| | Past victims | Ticketmaster, AT&T, McGraw Hill, Carnival, 7-Eleven, Instructure and others | | Method | steal data, then threaten to publish | | FBI warning | May 15, 2026 public service announcement: threats to victims and families, some swatting | | This demand | **retract that warning within a week** | | Group's claim | "We have never conducted swatting attacks" | Brett Leatherman of the FBI's Cyber Division has called the group a big problem in data exfiltration and extortion. Huntress's Andrew Brandt said the bigger worry is **the data being sold to other criminal or nation-state groups.**

The personnel files of America's top federal police force may have leaked out the back of a recruiting website. On September 21-22, 2026 (US time), the hacking group ShinyHunters replaced images on the FBI's recruiting site, FBIjobs.gov, with a Pokemon mascot and the words "This site has been seized by ShinyHunters."

1. What is confirmed and what is claimed

ItemDetailStatus
Site defacementFBIjobs.gov images replacedconfirmed; special agent application portal down as of September 23 morning
Agent record sampleabout 5,000confirmed genuine by 404 Media, Reuters and others
Sample contentsnames, home addresses, SSNs, assignments, some family namesconfirmed by outlets
Total size2–3 TB, "almost ALL FBI Agents"hacker claim
Medical dataprescriptions and diagnoses (Medlink)hacker claim
FBI statement"aware of claims … currently investigating"official

A list tying agents to home addresses and family names is a safety problem, not just an identity-theft risk. Because the sample is genuine, the incident is already serious.

StepDetail
EntryOracle PeopleSoft, HR software holding applicant data
Methodan unknown flaw allowing remote code execution without login
Movementinto AWS GovCloud
Resultagent and applicant data, per the group

The entry point was not an investigative system but recruiting and HR. HR systems must be reachable from the internet so outsiders can apply, and they hold personal data on every employee. A different PeopleSoft flaw was exploited in June (The Hacker News). The FBI has not said whether the breach point was its own system or a contractor's.

3. The demand is not money

ShinyHunters addressed FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, demanding the bureau retract its May 15 public service announcement within a week. That warning said the group threatened victims and their families and in some cases carried out "swatting," false reports that send armed police to someone's home.

PartyPosition
FBI (May warning)threats, family harassment, swatting, exaggerated access claims
ShinyHunters"never conducted swatting"; framing this as "setting the record straight"
Security expertsbigger risk is resale to criminal or state groups (Huntress)

The group has spent nearly a year hitting companies like Ticketmaster, AT&T and 7-Eleven. This time it publicly targeted the agency investigating it.

4. The same week

DateIncident
Sept 21-22FBI recruiting site defaced, data theft claimed
Sept 24Australia discloses an OpenAI agent's unauthorized access to a health portal in June
Sept 24crypto exchange Bitget detects unauthorized transfers

Whether the intruder is a human crew or an AI agent, internet-facing government systems showed their weak points repeatedly in one week. The White House request that AI labs delay sharing models abroad sits in the same current.

5. What remains unconfirmed

  • The full scope and any medical data remain hacker claims.
  • The PeopleSoft zero-day path is unconfirmed by Oracle or the FBI.
  • Whether the group publishes or sells data after the deadline is the next milestone.
  • Whether other agencies using PeopleSoft are exposed has not been reported.

Sources

  1. The Record — FBI investigating alleged ShinyHunters breach of its jobs site
  2. The Hacker News — ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
  3. Nextgov/FCW — ShinyHunters claims FBI data theft, demands bureau retract cyber warning
  4. TechCrunch — Hacking group ShinyHunters claims it breached the FBI
  5. 404 Media — 'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees

Verification

Published
Last modified
Cross-check
Checked against 5 independent sources.
Unverified
  • The total size (2–3 TB) and 'almost all agents' are the group's claims, not confirmed by the FBI.
  • The medical-records claim has not been confirmed by any sample.
  • The PeopleSoft zero-day path is the group's claim; Oracle and the FBI have not confirmed it.
  • Outlets differ on size: Nextgov cites 2–3 TB, The Hacker News about 2 TB.
  • The exact expiry of the one-week deadline was not confirmed.
Authoring
Reviewed by a person before publication. The full process is described in the Editorial.

Ten stories, once each morning

We send the three-line summaries only; the full pieces stay on the site. One-click unsubscribe, any time.

Related