The news
The FBI breach claimed by hacking group ShinyHunters on September 22 has grown more serious. MS Now reported on September 26, and TechCrunch on September 28, that the bureau had declared a cyber security incident in an internal notice telling employees their names, addresses, job titles and Social Security numbers were exposed. TechCrunch called it the bureau's first acknowledgment that agents' personal data was taken. Several outlets, including Reuters, have also confirmed that the stolen files included medical records of FBI staff.
ShinyHunters first posted the claim on its dark web leak site, saying it held sensitive data on almost all FBI agents and on people who had applied for FBI jobs, according to TechCrunch. A sample shared by the group contained names, home addresses and phone numbers of agents and their spouses. The group also reportedly defaced the FBIJobs.gov recruiting portal, which went offline.
According to reporting by TechCrunch, Nextgov and Help Net Security, the attackers exploited a flaw in an Oracle PeopleSoft server that stores human resources and applicant data, then moved into FBI systems hosted in Amazon Web Services' GovCloud, a cloud region for U.S. government workloads. The Register reported the group described the PeopleSoft bug as a pre-authentication zero-day that was still unpatched as of September 25.
The group's claims have expanded since. The Register reported that ShinyHunters said the data included Social Security numbers, job titles, field office assignments and emergency contacts. Help Net Security reported claimed access to systems handling background checks, medical records and investigative information. Nextgov reported the group claimed to hold records identifying staff working on operations involving Russia, China, Hezbollah and cartels. The FBI has not publicly confirmed the scope of the breach or these wider claims, though its internal notice reportedly told staff that Social Security numbers and job titles were among the data exposed.
An FBI spokesperson told TechCrunch on September 22 that the bureau was aware of claims about unauthorized activity affecting FBIjobs.gov and was investigating. The Register reported the FBI later said the point of breach was still undetermined and that it was investigating aggressively. ShinyHunters has said it is not seeking a ransom and wants the FBI to correct a May 2026 advisory about the group; it told Nextgov it would never publish the data.
BleepingComputer reported that Dutch police confirmed arresting a 24-year-old Amsterdam man in September as part of an investigation into ShinyHunters. The group denied any connection to him.
The numbers
- Date ShinyHunters claimed the breach
- September 22, 2026
- Date MS Now reported the FBI's internal incident declaration
- September 26, 2026
- Volume of data claimed
- Terabytes (per ShinyHunters, unverified)
- Age of suspect arrested by Dutch police
- 24
Why CEOs should care
For CISOs, the attack path is familiar and uncomfortable. The entry point was reportedly an HR and recruiting system, not a mission system, yet the attackers claim it gave them a path into connected systems holding medical files and background-check material. Security leaders should confirm where their own HR, applicant tracking and benefits platforms sit, whether they are reachable from the internet, and whether they connect to cloud storage holding far more sensitive records. Companies running Oracle PeopleSoft should check exposure and apply Oracle's guidance; Help Net Security reported that Google's Mandiant found a web application firewall alone was not enough to stop related attacks.
For boards and general counsels, the incident is a reminder that employee and candidate data is a security asset, not just a compliance record. Ask how long applicant data is retained, who can reach medical or screening information, and whether it is separated from general HR records. Deleting data the company no longer needs is one of the few controls that shrinks the damage of any future breach.
For executives personally, the lesson is about targeting. Experts quoted by TechCrunch and Nextgov warned that stolen personnel data enables profiling, phishing, social engineering and approaches by foreign intelligence services. Leaders whose home addresses and family details sit in HR systems should expect more convincing lures and should route unusual requests through verified channels.
The bigger picture
The FBI case is not the only ShinyHunters campaign involving Oracle PeopleSoft. Help Net Security reported the group first exploited a PeopleSoft flaw against academic institutions in May and June 2026, and Google's Mandiant has since warned of fresh attacks that slip past firewall rules. One weakness in a widely used HR platform can reach an organization's most sensitive personnel data.
TechCrunch reported it was unclear whether the FBI had notified congressional oversight committees, as federal law may require for major incidents.
What’s next
Watch for an official FBI statement on the scope of the breach, any notification to current and former employees and applicants, and congressional inquiries. Also watch Oracle for patches or updated guidance on PeopleSoft, and the Rotterdam court proceedings in the Dutch ShinyHunters investigation.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error
Companies in this story








