The FBI is treating the compromise of its FBIJobs.gov recruitment portal as a breach affecting its own workforce: in a memo obtained by the New York Times, senior officials told staff they are "operating under the premise that the threat actor is also exfiltrating [personal information] of all F.B.I. employees". ShinyHunters claims it stole data on almost every agent and job applicant, and samples the group shared with journalists contain agents' personal contact details, family-member information, office and duty assignments and, in some cases, personnel specialties. The intake portal remained offline on Monday and the bureau has not confirmed the type or volume of data involved or attributed the intrusion. Google's Mandiant published a blog on Friday about CVE-2026-35273, an Oracle PeopleSoft flaw disclosed in June that it first reported as a zero-day exploited between 27 May and 9 June against academic institutions, and warned the group had restarted exploitation and "adapted to published defensive guidance, targeting organizations that implemented [workarounds] but did not patch the vulnerability", deploying web shells on dozens of systems across higher education, technology, IT services, healthcare, agriculture, transportation and government. Dutch police confirmed an arrest in the investigation; Krebs on Security identified the suspect as a 23-year-old convicted Dutch cybercriminal.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-29 |
| Source | The Record |
| Reliability | Tier 2 |
| CVEs | CVE-2026-35273 |