The extortion group ShinyHunters defaced FBIjobs.gov with its banner and claims to hold data on "almost ALL FBI Agents" and job applicants across the Criminal Justice, HR and Medlink services, saying it acted in retaliation for a May 2026 FBI public service announcement about its targeting of the Canvas learning-management platform. A spokesperson told The Register the group used a new Oracle PeopleSoft zero-day to gain remote code execution, and ShinyHunters provided samples of 5,000 FBI agent records to 404 Media and other outlets, which confirmed their authenticity. The FBI says it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating"; as of Wednesday morning the jobs site still carried a banner stating the special agent application portal was unavailable. The technical claim is the weakest element: no PeopleSoft pre-authenticated RCE zero-day has been detailed publicly, though ShinyHunters weaponised a related flaw, CVE-2026-35273, in June 2026 to breach enterprise networks, and reporting notes the claimed lateral movement into FBI-managed AWS GovCloud infrastructure and a 2–3 TB volume are unverified. The group has also hijacked Clop's leak site and denied being part of The Com.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-24 |
| Source | The Record |
| Reliability | Tier 2 |
| Breach classification | Unverified claim |
| CVEs | CVE-2026-35273 |