Nadia Dubois
September 26, 2026
10 min read
Three days after the extortion group ShinyHunters first claimed it had breached Federal Bureau of Investigation systems, the story has shifted from a raw numbers game (how many terabytes, how many agents) to something more pointed: motive. According to The Register, the group says the intrusion was retaliation against the Bureau, not a money grab. That reframing, combined with a Reuters-sourced report that psychiatric and medical evaluation records were part of the haul, has turned a data-theft story into a national security story.
The FBI confirmed on September 23 that it is investigating the claim, and as of September 26 the Bureau still has not verified the full scope of what ShinyHunters says it took What has changed since the story first broke is the technical picture of how the attackers got in, and why they say they did it at all
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What ShinyHunters Actually Claims Happened
ShinyHunters, an extortion collective with roots tracing back to French-speaking hacking forums, went public with the claim on its data-leak site earlier in the week, describing what it called “very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.” The group says the stolen material totals somewhere between 2 terabytes and 3 terabytes, though that figure has not been independently confirmed by any government agency, per TechCrunch.
A roughly 5,000-line spreadsheet reviewed by security researchers and journalists reportedly contains names, home addresses, phone numbers, dates of birth, Social Security numbers and emergency-contact details, according to reporting cited by multiple outlets. The BBC said it had reviewed a small portion of the data and that it appeared genuine. Some records reportedly describe officials’ job assignments, including work tied to counterintelligence operations against Chinese and Russian intelligence services and investigations into drug cartels, according to Reuters.
The newest wrinkle, reported September 25 by U.S. News & World Report citing Reuters, is that the stolen files include psychiatric and medical evaluation records tied to FBI personnel screening. That category of data raises the stakes considerably: medical and mental-health history is exactly the kind of leverage that foreign intelligence services or criminal actors could use to pressure or blackmail cleared law enforcement personnel, a risk flagged directly by Lawfare, which described the incident as a counterintelligence problem rather than a garden-variety privacy breach.
The Attack Path: A Second Oracle PeopleSoft Zero-Day
The technical detail that separates this incident from the initial burst of headlines is the entry point. ShinyHunters told BleepingComputer it exploited a previously unknown vulnerability in Oracle PeopleSoft, the human-resources and applicant-tracking software that also underpins the FBI’s public jobs portal, apply.fbijobs.gov. According to BleepingComputer, the flaw allows remote code execution, and the group says it used it Monday night to gain an initial foothold before moving laterally into FBI-managed Amazon Web Services GovCloud infrastructure.
A screenshot the group shared with researchers reportedly shows a page under a “/PSEMHUB/” path on the jobs portal displaying Linux system information, which ShinyHunters described as its entry point into the wider FBI environment. From there, the attackers claim to have pivoted into several internal services: FBIJOBS, the recruiting portal itself; a background-check system some reporting refers to as FBI BEAST; FBI MedLink, which stores agent medical records; and an additional system tied to criminal-justice and investigative data. Not every outlet uses identical names for these systems, and none of the internal system names have been confirmed directly by the FBI.
This is notable because it is not the first Oracle PeopleSoft zero-day of 2026. A separate PeopleSoft flaw, tracked as CVE-2026-35273, hit more than 100 schools earlier this year with a CVSS score of 9.8, and ShinyHunters was separately linked to a campaign that compromised more than 100 organizations through a related Oracle weakness. The fact that the same enterprise software category keeps producing exploitable holes across both education and federal law-enforcement customers is becoming its own story, independent of any single breach.
Why ShinyHunters Says It Did This
Unlike most of ShinyHunters’ prior campaigns, which have centered on extortion payments, the group is framing this one differently. “This is NOT financially motivated,” a spokesperson for the group told The Register. The stated grievance traces back to a FLASH advisory the FBI published in May 2026 warning organizations about ShinyHunters’ tactics. The group objects to how it was characterized in that document. “We want the FBI to correct or retract their statements they made, which included substantial false allegations,” the spokesperson said, according to the same Register report.
Separately, according to reporting summarized by ASIS International’s security-management newsroom, the group has also demanded the takedown of a public service announcement it views as inaccurate. Whether that demand is genuine or simply a pretext dressed up to look less mercenary than a typical extortion play is something investigators, and outside researchers, are still weighing. CyberScoop framed the incident as putting ShinyHunters in the most direct conflict yet with the federal agents whose job is to investigate exactly this kind of extortion crime.
Timeline: How the Story Has Moved in Five Days
How This Compares to Past Federal Breaches
Federal law enforcement and personnel data has been a target before, and the closest historical analogue is the 2015 breach of the Office of Personnel Management, which exposed background-investigation files, including fingerprints, for more than 21 million current and former federal employees and contractors. That incident reshaped how Washington thinks about personnel-data security and is frequently cited as the benchmark for measuring counterintelligence damage from a government data breach.
Tech Insider’s own coverage of the IDScan breach and its OPM comparison earlier this year noted that Congress took roughly 14 days to respond publicly to that incident, versus about 12 days after OPM in 2015. If congressional silence follows a similar pattern here, expect the loudest public reaction to come from committees, not the floor, in the days ahead. The FBI incident differs from OPM in one important respect: OPM was a single centralized breach of a government-run system, while the FBI incident, if ShinyHunters’ account holds up, involves a third-party enterprise software flaw that gave attackers a path into a portal before they pivoted into cloud infrastructure the Bureau itself manages.
It also follows a pattern the site has tracked repeatedly this year: ShinyHunters’ repeat breach of Rockstar Games, in which the group leaked 8.1GB of anti-cheat code, shows a group willing to strike the same target more than once and willing to leak data purely to embarrass a victim rather than solely to collect a ransom. The FBI case looks like an escalation of that same playbook, aimed at the one federal agency whose job is to catch groups like ShinyHunters. It also follows the site’s earlier coverage of the initial claim itself, in ShinyHunters Say They Hacked FBI, Hold 2-3TB Data, and an unrelated FBI probe into a separate driver’s-license breach covered in FBI Probes Breach Exposing 153M Driver’s Licenses.
Data Table: What’s Confirmed vs. Still Unverified
The Counterintelligence Angle
What makes this incident different from a typical corporate data breach is who the victims are. If the stolen data really does include home addresses, family details, medical histories and information about agents’ work assignments, that combination looks close to a playbook for coercion. Foreign intelligence services have historically used exactly this kind of personal leverage, financial pressure, medical or psychiatric vulnerabilities, family details, to try to recruit or blackmail people with access to classified information. Lawfare’s analysis of the incident frames it in those terms rather than as a simple privacy violation, arguing the exposure of agents’ assignments against Chinese and Russian intelligence targets could put ongoing operations and the safety of individual officers at risk.
That risk is compounded by uncertainty. Because the FBI has not yet confirmed the scope of the breach, agents and applicants named in the leaked files have no way to know for certain whether their own information is included, which limits their ability to take protective steps like changing addresses tied to sensitive assignments or alerting family members.
Market and Industry Impact
Breaches involving federal law enforcement tend to move two distinct markets. The first is Oracle’s enterprise applications business: a second PeopleSoft zero-day surfacing in the same year that CVE-2026-35273 hit more than 100 schools adds pressure on Oracle to accelerate patch cycles for its HR and applicant-tracking modules, which remain widely deployed across government agencies, universities and large enterprises specifically because migrating off legacy PeopleSoft deployments is slow and expensive.
The second is the identity-protection and breach-response sector. Vendors that specialize in credit monitoring, dark-web scanning and identity-theft insurance for large-scale personnel breaches, the same category of firm that handled aftermath contracts for OPM in 2015, are likely candidates for any federal contract tied to notifying and protecting affected employees here, though no such contract has been announced. Cybersecurity Dive’s framing of this as a breach tied to a third-party jobs portal also puts renewed scrutiny on how federal agencies vet the security posture of vendors that manage recruiting, HR and background-check pipelines, a governance gap that outside contractors, rather than the FBI’s own IT staff, are often responsible for closing.
What Happens Next
The FBI’s public statement so far has focused on determining whether the hackers breached its own systems or a third party, and on working with the outside vendors that support FBIJobs.gov to contain the incident. That distinction, internal system versus third-party vendor, will likely determine how the FBI legally and operationally responds, including whether affected employees are entitled to standard federal data-breach notification and credit-monitoring benefits.
ShinyHunters, for its part, has a well-documented pattern of using data leaks as leverage during negotiations, then partially or fully releasing material regardless of whether demands are met. Whether the group’s stated retaliation motive changes that pattern, or whether this becomes another leak-first, negotiate-later situation, should become clearer in the coming days as more of the alleged dataset either surfaces publicly or is confirmed as fabricated or exaggerated.
Predictions
- The FBI will eventually confirm that at least some employee and applicant data was exposed, even if the final scope turns out to be smaller than the 2TB-3TB ShinyHunters claims.
- Oracle will face renewed pressure to publish a fix and a CVE identifier for the PeopleSoft flaw ShinyHunters says it exploited, given that a separate PeopleSoft zero-day already produced a CVSS 9.8 rating this year.
- Congressional committees overseeing the FBI and federal cybersecurity will request briefings, following a similar delayed-response pattern to the one seen after the IDScan breach.
- Expect follow-on reporting focused specifically on whether any counterintelligence operations were compromised by the exposure of agents’ work assignments, rather than on the raw data volume.
- Identity-protection and credit-monitoring vendors will likely see renewed federal interest in personnel-breach response contracts, mirroring the aftermath of the 2015 OPM breach.
Frequently Asked Questions
Has the FBI confirmed the breach actually happened?
The FBI has confirmed it is investigating the claim but, as of September 26, has not independently verified the full scope of what ShinyHunters says it stole
Who is ShinyHunters?
ShinyHunters is an extortion group tied to French-speaking hacking communities that has claimed responsibility for a long list of high-profile breaches in 2026, including a repeat attack on Rockstar Games and a disruptive breach of the education platform Canvas.
How did the attackers reportedly get in?
ShinyHunters told BleepingComputer it used a previously unknown Oracle PeopleSoft vulnerability affecting the FBI’s job-application portal, then moved laterally into FBI-managed AWS GovCloud infrastructure.
What kind of data is allegedly involved?
Reported categories include names, addresses, phone numbers, dates of birth, Social Security numbers, emergency contacts, job assignment details, and, according to a Reuters-sourced report, psychiatric and medical evaluation records.
Why does ShinyHunters say it targeted the FBI?
The group told The Register the attack was retaliation over an FBI advisory published in May 2026 that it says contained false allegations, and that it wants the advisory corrected or retracted.
Is this the same as the Oracle PeopleSoft flaw that hit schools earlier in 2026?
No. That earlier flaw, tracked as CVE-2026-35273, is a separate, already-disclosed vulnerability. The flaw ShinyHunters says it used against the FBI is described as a new, previously unreported zero-day.
How does this compare to the 2015 OPM breach?
The 2015 Office of Personnel Management breach exposed background-investigation files for more than 21 million current and former federal employees and remains the standard comparison point for federal personnel-data breaches, though the attack vector and scale of this incident have not yet been fully confirmed.
What should affected FBI employees or applicants do right now?
Security experts generally recommend monitoring credit reports, watching for phishing attempts referencing personal details, and following any official notification from the FBI once the investigation concludes, rather than reacting to unverified samples posted by the hackers themselves.
