# ShinyHunters Alleges Major Breach of FBI Jobs Portal

*Published September 25, 2026*
*Source: [https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html](https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/shinyhunters-alleges-major-breach-of-fbi-jobs-portal) or [see plans](https://www.sec-news.ai/pricing).*

## Article

The cyber extortion group ShinyHunters has claimed responsibility for breaching the FBI's jobs portal, asserting that they obtained sensitive data belonging to current and former FBI employees as well as job applicants. The group declared that they accessed various FBI services, including Criminal Justice, HR, and Medlink, through this breach. ShinyHunters stated that they exploited a zero-day vulnerability in Oracle PeopleSoft to achieve remote code execution on the FBI site. The FBI is currently investigating these claims and is working with third-party providers associated with the affected portal to mitigate risks.

The breach reportedly involves approximately 2 terabytes of data, including highly sensitive information such as medical records and personal details of FBI agents. ShinyHunters has denied any financial motivation behind the attack and claims their actions are a response to what they perceive as disinformation spread by the FBI about their organization. They also dismissed allegations of being linked to the decentralized collective known as 'The Com,' attributing such claims to misinformation within the cybersecurity community.

This incident follows ShinyHunters' previous actions against the Clop ransomware group, indicating their ongoing presence in the cybercrime landscape. The breach, if confirmed, underscores the need for heightened security measures and scrutiny of identity verification processes within public-sector agencies. As the investigation continues, the FBI is likely to focus on the origins of the vulnerability exploited in the attack and any potential connections to other cybercriminal entities.
