# ShinyHunters claims FBI jobs site breach via PeopleSoft flaw; bureau probes ‘unauthorized activity’

*Wednesday, September 23, 2026 at 6:21 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-23T06:21:38.666Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18624.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: The hacking group ShinyHunters says it broke into an FBI system linked to FBIJobs.gov and stole data on agents and job applicants, allegedly using an undisclosed PeopleSoft vulnerability. The FBI says it’s investigating unauthorized activity affecting the jobs site.

ShinyHunters, a hacking group known for large data thefts, now claims it has compromised an FBI recruitment system.

According to reports summarised by security outlets, the group says it breached an FBI system associated with FBIJobs.gov and obtained information on both current agents and job applicants. ShinyHunters claims it used a previously unknown vulnerability in PeopleSoft, an enterprise software platform widely used for human‑resources and finance functions. No technical proof of the exploit has been made public, and independent forensic details are not yet available.

The FBI has acknowledged that something may be wrong. In a short statement, the bureau said it is investigating claims of "unauthorized activity" affecting FBIJobs.gov. It did not say when the alleged intrusion occurred, what systems were accessed or what types of data might be involved, and it has not publicly attributed the activity to any specific group.

If ShinyHunters’ account is accurate, the breach could expose personally identifiable information on people who work for, or have applied to work for, one of the United States’ main domestic and counter‑intelligence agencies. Recruitment and HR systems typically hold names, contact details, work and education histories and other screening information. Even partial data can be combined with records from other breaches to build detailed profiles.

ShinyHunters has previously targeted major companies, stealing and sometimes selling large databases. An FBI‑related breach, if confirmed, would be symbolically significant even if it involved a peripheral system rather than classified networks, and an undisclosed PeopleSoft flaw would have implications well beyond the bureau given the software’s widespread use.

The incident underlines a broader vulnerability: support systems such as recruitment portals and HR platforms sit close enough to sensitive organisations to hold valuable information, but they often don’t receive the same level of protection as core classified systems.

Key points to watch now are whether ShinyHunters releases sample data to back its claim, whether the FBI or other U.S. agencies publish technical advisories about a PeopleSoft issue, and whether the software’s developer issues patches or guidance tied to this case. Any notifications to affected applicants or staff would clarify the scale of the exposure.
