Skip to content
TECH CEO Daily

FBI breach claimed by ShinyHunters exposed employees' personal and medical data, reports say

The hacking group says it pulled records on agents and job applicants from the bureau's recruiting systems. Reports say stolen files include medical and psychiatric records.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1ShinyHunters claimed on September 22 that it stole data on most FBI agents and applicants via an Oracle PeopleSoft HR server.
  • 2MS Now reported on September 26 that the FBI declared a cyber security incident internally, telling staff their names, addresses, job titles and SSNs were exposed; outlets confirmed stolen medical records.
  • 3The group says it will not publish the data, but experts warn of phishing, social engineering and counterintelligence risks.

The news

The FBI breach claimed by hacking group ShinyHunters on September 22 has grown more serious. MS Now reported on September 26, and TechCrunch on September 28, that the bureau had declared a cyber security incident in an internal notice telling employees their names, addresses, job titles and Social Security numbers were exposed. TechCrunch called it the bureau's first acknowledgment that agents' personal data was taken. Several outlets, including Reuters, have also confirmed that the stolen files included medical records of FBI staff.

ShinyHunters first posted the claim on its dark web leak site, saying it held sensitive data on almost all FBI agents and on people who had applied for FBI jobs, according to TechCrunch. A sample shared by the group contained names, home addresses and phone numbers of agents and their spouses. The group also reportedly defaced the FBIJobs.gov recruiting portal, which went offline.

According to reporting by TechCrunch, Nextgov and Help Net Security, the attackers exploited a flaw in an Oracle PeopleSoft server that stores human resources and applicant data, then moved into FBI systems hosted in Amazon Web Services' GovCloud, a cloud region for U.S. government workloads. The Register reported the group described the PeopleSoft bug as a pre-authentication zero-day that was still unpatched as of September 25.

The group's claims have expanded since. The Register reported that ShinyHunters said the data included Social Security numbers, job titles, field office assignments and emergency contacts. Help Net Security reported claimed access to systems handling background checks, medical records and investigative information. Nextgov reported the group claimed to hold records identifying staff working on operations involving Russia, China, Hezbollah and cartels. The FBI has not publicly confirmed the scope of the breach or these wider claims, though its internal notice reportedly told staff that Social Security numbers and job titles were among the data exposed.

An FBI spokesperson told TechCrunch on September 22 that the bureau was aware of claims about unauthorized activity affecting FBIjobs.gov and was investigating. The Register reported the FBI later said the point of breach was still undetermined and that it was investigating aggressively. ShinyHunters has said it is not seeking a ransom and wants the FBI to correct a May 2026 advisory about the group; it told Nextgov it would never publish the data.

BleepingComputer reported that Dutch police confirmed arresting a 24-year-old Amsterdam man in September as part of an investigation into ShinyHunters. The group denied any connection to him.

The numbers

Date ShinyHunters claimed the breach
September 22, 2026
Date MS Now reported the FBI's internal incident declaration
September 26, 2026
Volume of data claimed
Terabytes (per ShinyHunters, unverified)
Age of suspect arrested by Dutch police
24

Why CEOs should care

For CISOs, the attack path is familiar and uncomfortable. The entry point was reportedly an HR and recruiting system, not a mission system, yet the attackers claim it gave them a path into connected systems holding medical files and background-check material. Security leaders should confirm where their own HR, applicant tracking and benefits platforms sit, whether they are reachable from the internet, and whether they connect to cloud storage holding far more sensitive records. Companies running Oracle PeopleSoft should check exposure and apply Oracle's guidance; Help Net Security reported that Google's Mandiant found a web application firewall alone was not enough to stop related attacks.

For boards and general counsels, the incident is a reminder that employee and candidate data is a security asset, not just a compliance record. Ask how long applicant data is retained, who can reach medical or screening information, and whether it is separated from general HR records. Deleting data the company no longer needs is one of the few controls that shrinks the damage of any future breach.

For executives personally, the lesson is about targeting. Experts quoted by TechCrunch and Nextgov warned that stolen personnel data enables profiling, phishing, social engineering and approaches by foreign intelligence services. Leaders whose home addresses and family details sit in HR systems should expect more convincing lures and should route unusual requests through verified channels.

The bigger picture

The FBI case is not the only ShinyHunters campaign involving Oracle PeopleSoft. Help Net Security reported the group first exploited a PeopleSoft flaw against academic institutions in May and June 2026, and Google's Mandiant has since warned of fresh attacks that slip past firewall rules. One weakness in a widely used HR platform can reach an organization's most sensitive personnel data.

TechCrunch reported it was unclear whether the FBI had notified congressional oversight committees, as federal law may require for major incidents.

What’s next

Watch for an official FBI statement on the scope of the breach, any notification to current and former employees and applicants, and congressional inquiries. Also watch Oracle for patches or updated guidance on PeopleSoft, and the Rotterdam court proceedings in the Dutch ShinyHunters investigation.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

FBIShinyHuntersOracle PeopleSoftData breach

Earlier coverage of Oracle

All Oracle coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.