The FBI's online recruitment portals are still offline after the ShinyHunters extortion group claimed it broke in using an unpatched Oracle PeopleSoft flaw. The bureau confirmed last week that it is investigating the claim. ShinyHunters told The Register that it exploited a zero-day vulnerability and also accessed managed servers on AWS GovCloud, stealing personnel files of current, former, and aspiring FBI employees. The group says it is not seeking payment; instead, it wants the FBI to retract what it calls false allegations in a recent public service announcement.
According to the group, the stolen data includes personal information of tens of thousands of agents and applicants, plus medical records. Reuters reported that the group claims access to multiple systems, including FBIJobs, BEAST, MedLink, and BICS, and that one leaked document lists roles of FBI staff in sensitive units. Reuters could verify some career details against court filings, news articles, and public profiles.
Mandiant's analysis ties the incident to renewed exploitation of CVE-2026-35273, a PeopleSoft vulnerability ShinyHunters used earlier in 2026 against academic institutions. The researchers say the group modified its original exploit to bypass web application firewall rules by URL-encoding a single character in the request path, reaching the vulnerable endpoint on systems that were protected only by WAF rules. Mandiant notes the campaign has expanded to higher education, technology, healthcare, and government, and that after gaining access the group deploys web shells, a legitimate remote management tool, and fileless commands.