ShinyHunters claimed to have infiltrated systems related to the recruitment portal FBIJobs.gov and obtained data of employees, former employees and candidates. However, at the time of publication, the US Federal Bureau of Investigation (FBI) had only confirmed that it was investigating illegal activities related to this portal; The scale of the leak and the method of intrusion have not yet been verified by an independent agency. The distinction between the attack group's statements and confirmed facts is the most important point when evaluating the incident.

Latest statement from ShinyHunters
According to The Hacker News, ShinyHunters said the group accessed many FBI services, including recruitment, human resources, healthcare and criminal justice systems. The group also claims to hold about 2 TB of data, including personally identifiable information and sensitive health records. These are all statements from the threat actor, not the conclusion of the investigation.
The FBI said it is aware of the reported breach of FBIJobs.gov and the alleged impact regarding employee personal data. The agency is coordinating with recruitment portal support vendors to identify the point of intrusion, mitigate risk, and clarify whether the incident is located in third-party systems or the FBI's corporate environment.
Developments over time
In May 2026, the FBI issued a public warning about ShinyHunters' activities, describing how the group targeted the Canvas learning platform and advising victims not to pay the ransom. In June, researchers documented a group exploiting CVE-2026-35273 in Oracle PeopleSoft to compromise enterprise networks.
On September 22, information about the announcement of an attack on the FBI began to appear in the US. On September 23, ShinyHunters publicly announced on the data leak site, saying this was a response to the FBI's previous warning. At the same time, the apply.fbijobs.gov portal switched to a maintenance notice. The fact that the website is out of service does not by itself prove all data claims.
The point of entry remains an open question
A ShinyHunters representative told the media that the group used a new zero-day vulnerability in Oracle PeopleSoft to remotely execute code and change the look and feel of the recruitment website. Until there is a technical announcement from Oracle, the FBI or an independent investigation unit, this hypothesis should be considered unconfirmed.
PeopleSoft typically handles high-value HR, recruiting, and internal process data. If such a system is compromised, the impact can spread across privileged accounts, application integrations, and associated data stores. But the actual scope can only be determined by access logs, system snapshots, malware traces, and comparison of data believed to have been stolen.
Why is ShinyHunters a difficult crime brand to identify?
ShinyHunters should not be understood simply as a fixed group with an immutable membership list and infrastructure. Experts describe this as a criminal brand capable of maintaining operations through multiple arrests, forum takedowns and personnel changes. This model helps new campaigns inherit the hidden reputation of the old name, while also complicating the process of attributing responsibility.
The group denies being part of the decentralized criminal community commonly known as “The Com” and also denies ties to the Scattered Spider. However, technical overlaps such as fake support calls, login fraud, OAuth abuse, and SaaS token theft make it difficult to separate the groups using tactics alone.
From belt breaking to identity appropriation
A notable point in the recent operating method is the prioritization of identity trusted paths instead of just scanning for vulnerabilities at the network perimeter. An attacker could convince the help desk to reset MFA, register a malicious OAuth application, or use a stolen integration token. When logged in with a valid identity, they can reduce the number of traditional technical alerts.
So even if the PeopleSoft zero-day claim is not substantiated, the incident still reminds organizations to simultaneously monitor HR applications, vendors, privileged accounts, and cloud login sessions. A public web portal may be just the visible surface of a complex chain of trust relationships behind the scenes.
Risk if data is confirmed
If HR and medical data is truly exposed, the consequences go far beyond changing passwords. Candidate profiles may contain addresses, employment history, contact information and background check data. Health records can be used for pressure, targeted fraud or to build intelligence profiles on law enforcement officers.
Legally and operationally, stakeholders will have to determine the responsibilities between the host agency and the provider, the duty to notify affected people, the length of stay of the attacker and the extent of data that has been retrieved. In terms of social trust, a statement aimed at a leading investigative agency has great propaganda value, even before the data is proven.
How to carefully evaluate a leak claim
Organizations should not consider screenshots or claims on the dark web as sufficient evidence. The verification process needs to check for comparable data samples, timestamps, consistency of database structure, and the possibility that the data comes from an old leak or another provider.
At the same time, you should not wait for the attacker to publish data before starting to respond. Security teams need to preserve logs, disable suspicious sessions, rotate integration tokens, audit OAuth applications, review changes to admin accounts, and contact the relevant third parties directly.
Lessons for organizations
Recruitment and human resources systems must be classified as sensitive assets, not regular support websites. Organizations need to isolate networks, apply anti-phishing MFA, limit service account permissions, set alerts for large data exports, and test help desk identity verification processes.
Vendor governance also needs to include physical access rights, data storage locations, patch deadlines, and the ability to provide logs when problems occur. Drills should assume the starting point is a valid account or SaaS integration, rather than just assuming the malware gets past the firewall.
Conclusion
ShinyHunters' claims are serious, but the public evidence is currently not enough to confirm that the entire FBI has been hacked or that 2 TB of data has been stolen. It is a known fact that the FBI is investigating activity related to FBIJobs.gov and coordinating with vendors. Until technical results are available, the appropriate approach is to remain cautious, separate claims from assertions, and prioritize protecting identities and the application supply chain.
VNCyberS compiled from The Hacker News, FBI and Reuters















