On September 22, 2026, ShinyHunters claimed to have breached the FBI's jobs portal and stolen names, home addresses, and phone numbers for thousands of agents and their spouses. 404 Media verified a portion of the sample against public records. The FBI confirmed it was investigating. The jobs site went down. That part got the headlines. What got less attention is how they got in.

The fix was available. Not everyone applied it.
In June 2026, Mandiant reported that ShinyHunters had exploited a critical vulnerability in Oracle PeopleSoft, the HR and payroll platform used by large employers and government agencies worldwide, as a zero-day attack against universities. Oracle released a patch on June 10. Security teams were advised to install it and, where that wasn't immediately possible, to block access to the vulnerable component at the network perimeter using a firewall rule.
Some organizations patched. Others put the firewall rule in place and moved on.
By September, ShinyHunters had found a way through the firewall rule. Mandiant's follow-up report, published September 25, explains how: a single character substitution in the web request was enough to make the firewall rule miss the attack entirely, while the PeopleSoft server processed it normally. Organizations that had installed the patch were protected but the ones that had relied on the firewall rule alone were not.
The FBI's jobs portal runs Oracle PeopleSoft. Based on 404 Media's reporting, the group used the same vulnerability to access the portal, then moved into additional FBI-managed storage hosted on Amazon's government cloud. ShinyHunters claims to have taken between 2 and 3 terabytes of data. Those figures come from the group's own statements; the FBI has confirmed only that it is investigating.
Three months separated the patch from the bypass. That is a short window for an adaptation specifically designed to defeat published guidance.
A different entry point than their past campaigns
In May, I tracked a series of ShinyHunters campaigns where the access path was always identity-based: stolen passwords, a phone call to a helpdesk to reset a second factor, tokens borrowed from a compromised software vendor. In each case, the login succeeds. The system records a legitimate sign-in. Nothing looks wrong.
The April Anodot incident followed the same logic: authentication tokens stolen from a SaaS integration provider were used to reach downstream customer data across more than a dozen environments. The platform named in the headlines, Snowflake, was the last step, not where the access was obtained.
The FBI breach works differently. No password was needed. The attack went directly through a software vulnerability in a publicly accessible web application, established a foothold inside the server, and moved from there.
That distinction matters for how you respond to it. The previous campaigns called for watching what happens after a successful login. This one called for patching a known vulnerability before any login happens. Treating them as the same problem means looking in the wrong place.
Across all documented activity, ShinyHunters now has multiple confirmed methods: stolen credentials, social engineering of helpdesks, borrowed software tokens, and exploitation of unpatched enterprise software.
The demand is new territory
Previous ShinyHunters campaigns ended the same way: a ransom demand, backed by the threat of publishing stolen data. Pay, or it leaks.
The FBI breach is different. The group says the hack is "not financially motivated".
On September 23, they published their own PSA addressed directly to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman.

In it, they dispute three specific claims from the FBI's May 2026 advisory: that they use harassment strategies including threatening text messages and phone calls to victims and their families; that they have conducted swatting attacks; and that they falsely claim to hold compromising photographs or videos of victims. They write, in their own words: "WE ARE NOT SEXTORTIONISTS".
Their demand is the removal of that advisory. They gave the FBI one week from September 23 (a deadline of September 30) to "correct or simply REMOVE" it. As of publication, the advisory is still up.
The document is self-reported, published on their dark web leak site, and should be read as such. It is their account of their own motivations, not an independently verified statement. That said, using stolen government personnel data to pressure a law enforcement agency into retracting its own public documentation is a different kind of leverage than a standard ransom demand.
What to do if you run Oracle PeopleSoft
Install Oracle's patch for CVE-2026-35273, available since June 10. Firewall rules blocking the vulnerable endpoint are not a substitute. Mandiant's full remediation guidance covers what to check for on systems that may already be compromised.
The FBI breach is one incident inside a broader September wave. Mandiant observed compromised PeopleSoft systems across higher education, technology, healthcare, agriculture, transportation, and government organizations globally. The FBI case generated press. The others are being worked through quietly.
Track the behavior, not the brand
Mandiant tracks this activity as UNC6240. ShinyHunters is the name on the leak site and the extortion note. They are not the same designation, and treating them as interchangeable makes it harder to follow which operators are running which campaigns, and when.
Last September, when Scattered Spider, Lapsus$, and ShinyHunters announced they were going dark, the infrastructure and techniques did not go anywhere with them. The operators change; the access methods persist.
The May analysis still stands for the credential and token-based campaigns. The FBI breach adds a confirmed case where the entry point was unpatched software, not a compromised identity.
If you're wondering which gap to prioritize: the Mind Your Attack Gaps ebook covers what visibility looks like before the data platform named in the headline.
