
Two FBI job application portals remain offline after the ShinyHunters extortion group claimed to have compromised them through an Oracle PeopleSoft zero-day vulnerability, exposing personal and medical information tied to current, former, and prospective FBI employees.
Visitors to apply.fbijobs.gov and fbijobs.gov/special-agents continue to find the sites unavailable while investigators work through what the group says is a multi-platform intrusion. The disclosure has already produced verifiable details about sensitive FBI assignments, and it shows how a single unpatched flaw can be turned against both academic and government targets.
What ShinyHunters claims to have taken
According to reporting on the incident, ShinyHunters told a technology outlet they used an unspecified and unconfirmed Oracle PeopleSoft zero-day to reach the FBI’s online portals, and also breached FBI managed servers hosted on AWS GovCloud.
The group says the stolen files cover personnel records of current, former, and aspiring FBI employees, and that the haul includes the personal information of tens of thousands of FBI agents and applicants, plus medical records belonging to former agents.
Reporting cited multiple FBI systems in the claimed compromise:
- FBIJobs, the public-facing job application portals
- FBI BEAST, which handles background checks on employees and applicants
- FBI MedLink, which stores medical records
- FBI BICS, which contains investigative information
Among the documents the group has begun to release is material describing the roles of FBI staff in little-known or sensitive units. Reporting on the leaked files noted it was able to match career details or titles for eight people to information in court filings, news articles, or public profiles, though not every assignment could be confirmed as authentic or current.
Why the group says it carried out the attack
ShinyHunters has stated the intrusion is not financially motivated. The group says the breach and its very public disclosure are a response to a recent public service announcement that advised victim organizations not to pay ransoms, which ShinyHunters characterizes as false allegations. The threat attached to the disclosure is that the stolen information will be released further unless the FBI retracts those statements.
How the exploit works: renewed use of CVE-2026-35273
Analysts published a technical rundown on Friday describing how ShinyHunters have resumed exploiting an Oracle PeopleSoft vulnerability tracked as CVE-2026-35273. The same flaw was first used as a zero-day in May and June 2026, when it was aimed mostly at academic institutions. Oracle advised organizations at the time to install the emergency patch, or, where patching was not yet possible, to restrict network access to PeopleSoft application and web servers to trusted internal networks and to block external access to the vulnerable endpoints at the firewall.
The analysts warned that relying only on web application firewall body-inspection rules is insufficient, because those controls can be bypassed. That warning has now been borne out. The group recently modified its original exploit to slip past WAF rules protecting the vulnerable Environment Management Hub (PSEMHUB) endpoint by URL-encoding a single character in the request path, requesting /%50SEMHUB/ instead of /PSEMHUB/. The result is that the request reaches the endpoint on systems whose operators believed their WAF rules had already closed the exposure.
The current campaign shows that the group adapted to published defensive guidance and is now targeting organizations that implemented WAF rules but did not apply the underlying patch. Sectors in the expanded target set include higher education, technology, IT services, healthcare, agriculture, transportation, and government. After gaining access, the extortion group deploys web shells, a legitimate remote management tool called MeshAgent, and runs fileless command execution.
What defenders should take away from the FBI breach
The FBI portal outage is a working example of three recurring problems in enterprise patching. First, a WAF rule is not a substitute for a vendor patch; string-matching controls can be sidestepped with a single URL-encoded character. Second, public technical writeups teach both defenders and attackers, so any defensive guidance that depends on obscurity has a short shelf life. Third, government and education institutions that delayed the Oracle emergency patch earlier in 2026 are now squarely inside the expanded target set.
For organizations running PeopleSoft, the practical path is to apply the Oracle patch for CVE-2026-35273 if it has not already been applied, restrict external network access to the PSEMHUB endpoint, and treat existing WAF rules for PSEMHUB as already bypassed rather than as a working control.
FAQ
Which FBI portals are affected by the ShinyHunters breach?
The FBI job applicant portal at apply.fbijobs.gov and the special agent applicant portal at fbijobs.gov/special-agents were taken offline following the claimed compromise and remained unavailable at the time of the most recent reporting.
What vulnerability did ShinyHunters use to breach the FBI portals?
ShinyHunters said they used an unspecified and unconfirmed Oracle PeopleSoft zero-day. Analysts have tied the activity to renewed exploitation of CVE-2026-35273, an Oracle PeopleSoft flaw the group first exploited in May and June 2026.
What data does ShinyHunters claim to have stolen from the FBI?
The group claims to have personnel files of current, former, and aspiring FBI employees, including personal information for tens of thousands of agents and applicants and medical records for former agents, drawn from FBIJobs, FBI BEAST, FBI MedLink, and FBI BICS.
This article summarizes reporting from helpnetsecurity.com.
