Alleged ShinyHunters member Saif al-Din Khader, detained in Jordan on Tuesday, is helping the FBI find other members, two sources told Reuters. A new ShinyHunters leak site went up two days later, suggesting other members still run the extortion.
Perspective Coverage
8 publishers
- Builder
- Builder 16%
- Operator
- Operator 71%
- Investor
- Investor 13%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence62
Defense Manpower Data Center is notifying people after intruders read unencrypted files on its server for nine months, exposing 2.76 million living people. Nine months of access means every file that server held over the period should be treated as copied.
Perspective Coverage
9 publishers
- Builder
- Builder 13%
- Operator
- Operator 81%
- Investor
- Investor 6%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence68
Pentagon officials are telling 2.8 million living people that hackers took their personnel records, occupational specialty included. At least 1.5 million of them are not on active duty, so the exposure reaches well beyond the active force a month after a similar FBI breach.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence64
FBI's Brett Leatherman urged ShinyHunters members to surrender after the Dutch arrest of an alleged leader of a group tied to $70 million in extortion. Dutch police have not ruled out more arrests, though the public record so far shows one suspect in custody.
Perspective Coverage
9 publishers
- Builder
- Builder 17%
- Operator
- Operator 68%
- Investor
- Investor 15%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+30
- Incentives60
- Confidence64
FBI says ShinyHunters, which claimed the attack behind a nationwide learning-platform outage, may target students and families with threats and swatting. Its advice is to pay nothing and verify any contact through a channel already known.
Publishers:ic3.gov
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
ShinyHunters claims it holds fitness-for-work medical records, including blood and urine results, on about 60,000 current and former FBI staff. Test results and home addresses cannot be reset like a password, so containment now depends on the files staying unpublished.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives65
- Confidence50
FBI told staff in an internal memo to assume hacking group ShinyHunters stole data on every employee after a claimed 2 to 3 terabyte breach of FBIjobs.gov. Until the bureau confirms the scale, staff and the job applicants the hackers say are also in the files have reason to treat their home addresses as exposed.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence40
Dutch police detained an alleged ShinyHunters leader on September 15, seven days before the group defaced the FBI's jobs website. The FBI says it is still chasing the rest of the group, so the vendor services and web portals it has used to get in remain the exposure to manage.
Perspective Coverage
3 publishers
- Builder
- Builder 13%
- Operator
- Operator 69%
- Investor
- Investor 18%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence58
ShinyHunters claims data on almost every FBI agent, and samples reviewed by researchers show contact information, family details and duty assignments. The FBI has not confirmed what was taken or who took it, and says it is investigating.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence40
ShinyHunters is again mass-exploiting Oracle PeopleSoft flaw CVE-2026-35273, defeating firewall rules by URL-encoding a single character. Anyone who filtered the endpoint instead of applying Oracle's June 10 patch should assume exposure.
Perspective Coverage
8 publishers
- Builder
- Builder 25%
- Operator
- Operator 58%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+8
- Incentives58
- Confidence74
ShinyHunters says it will never publish the 2-3TB of FBI data it took, allegedly through the agency's online jobs board. The agents whose records were taken still have to plan as if the files are loose, because the pledge covers only publication.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives75
- Confidence40
ShinyHunters told 404 Media it will never publish its FBI haul, which it claims is 2 to 3 terabytes covering all employees and applicants. Keeping the files unpublished limits public exposure, but agents' home addresses, spouses' names and medical records are still with the group.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives75
- Confidence45
ShinyHunters says it will never publish or sell the 2TB to 3TB of FBI data it claims to hold and calls its one-week ultimatum a marketing campaign. The pledge leaves standing its unverified claim that an Oracle PeopleSoft zero-day got it in.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+45
- Incentives70
- Confidence40
Mandiant says ShinyHunters has planted web shells on dozens of Oracle PeopleSoft systems by URL-encoding one character to get past firewall rules. Employers that treated June's stopgap as the fix now have to patch and also look for any access the attackers left behind.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+8
- Incentives20
- Confidence70
ShinyHunters is again exploiting Oracle PeopleSoft flaw CVE-2026-35273, getting past WAF rules by URL-encoding one letter of the path, Mandiant reported. The servers now in reach are the ones whose operators filtered the endpoint and never applied Oracle's patch.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives70
- Confidence55
ShinyHunters has shown journalists FBI medical exams that name agents and their addresses, from a set it says covers about 60,000 current and former staff. The FBI has so far confirmed only an incident in FBIJobs-related systems, and the group is threatening to publish within five days.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence45
ShinyHunters says the two to three terabytes it took from the FBI include psychiatric and medical evaluations of bureau staff. Beside a Reuters sample tying named staff to counterintelligence jobs, those files are exposure no password reset can fix.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence40
ShinyHunters is exploiting an unpatched CVSS 9.8 pre-login flaw in Oracle PeopleSoft, encoding one URL character to slip past WAF rules matching the raw path. Mandiant has confirmed JSP web shells on dozens of systems.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence50
ShinyHunters claims 623GB from a July social-engineering campaign and leaked part of it. Have I Been Pwned confirmed 1.6 million account records. Both the vendor and the crew can be telling the truth.
Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 62%
- Investor
- Investor 16%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives55
- Confidence70
A fulfillment partner exposed names, addresses and phone numbers belonging to hardware wallet buyers, according to The Register. The vendor's boundary was the company's boundary.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 55%
- Investor
- Investor 17%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence68
Earlier coverage
- ShinyHunters routes around PeopleSoft firewall rules to hit systems still missing Oracle's patch
Invest · September 26, 2026 · 1 publisher
- ShinyHunters phished the firm that had just profiled it, and device trust was the only thing that mattered
Security · August 25, 2026 · 5 publishers
- ShinyHunters breached Clop's leak site through an unpatched Grav path traversal flaw
Security · September 26, 2026 · 1 publisher
- McKesson's 8-K locates the stolen data inside third-party applications
Security · August 28, 2026 · 9 publishers
- North Korea's WaterPlum fake-recruiter campaign has stolen $10.7 million from IT workers
Security · September 25, 2026 · 1 publisher
- Trezor says ShipMonk kept 67,000 customer records it had certified as deleted
Security · September 6, 2026 · 3 publishers
- Intruders reached Mathspace's unpatched Metabase four days after the fix shipped
Security · September 7, 2026 · 4 publishers
- Attackers phished Trezor, BitBox and CoinTracking customers through one shared newsletter provider
Security · September 10, 2026 · 4 publishers
- Florida traces the DAVID driver database breach to one Plant City police account
Security · September 11, 2026 · 2 publishers
- Anthropic widened its dual-use biology block on lost certainty about the old threshold
Build · September 10, 2026 · 5 publishers
- Storm-3121 callers demand an urgent passkey update to harvest Microsoft 365 session tokens
Security · September 11, 2026 · 6 publishers
- RubyGems froze new sign-ups after thousands of suspicious uploads researchers link to OpenAI agents
Security · September 11, 2026 · 12 publishers
- ShinyHunters threatens to name companies that paid Clop after defacing its leak site
Security · September 25, 2026 · 1 publisher
- Google's undercover analyst watched TeamPCP poison packages from inside its core chat
Product · September 18, 2026 · 1 publisher
- ShinyHunters says a Grav upload path let it deface Clop's leak site
Build · September 19, 2026 · 2 publishers
- ShinyHunters reportedly pivoted from a recruiting server to FBI agent records
Product · September 22, 2026 · 4 publishers
- ShinyHunters pins its claimed FBI breach on an unpatched PeopleSoft RCE
Security · September 23, 2026 · 14 publishers
- ShinyHunters demands an FBI advisory retraction as the price of not leaking staff data
Product · September 24, 2026 · 1 publisher
- ShinyHunters claims an Oracle PeopleSoft exploit opened the FBI's job application portal
Product · September 23, 2026 · 1 publisher
- ShinyHunters claims 2 to 3 terabytes of FBI personnel data from an Oracle PeopleSoft flaw
Leadership · September 23, 2026 · 3 publishers
- ShinyHunters claims a PeopleSoft zero-day gave it code execution on FBI servers
Product · September 23, 2026 · 1 publisher
- ShinyHunters claims the private keys to Clop's onion address after defacing the leak site
Security · September 19, 2026 · 6 publishers
- Clop asks ShinyHunters to come online from the leak site ShinyHunters defaced
Security · September 22, 2026 · 1 publisher
- ShinyHunters says it controls the private keys to Cl0p's onion address
Product · September 21, 2026 · 1 publisher
- ShinyHunters says a Grav upload flaw got it inside Cl0p's leak site
Product · September 21, 2026 · 1 publisher
- Telus says stolen credentials gave an attacker 16 months inside consumer telecom accounts
Security · September 14, 2026 · 1 publisher
- IBM prices the AI-assisted breach at a million dollars more than the rest
Invest · September 14, 2026 · 1 publisher
- AdaptHealth traces a 4.1 million-record breach to one compromised contractor session
Security · September 12, 2026 · 2 publishers
- San Francisco's city attorney orders Meta to stop allowing AI child abuse ads its review missed
Product · September 12, 2026 · 1 publisher
- Anthropic documents five possible bioweapons cases it cannot confirm were meant to cause harm
Product · September 11, 2026 · 7 publishers
- ShinyHunters affiliates escalated one stolen token to full cloud admin in about three hours
Product · September 10, 2026 · 1 publisher
- Fake IT callers register their own MFA method under the Microsoft 365 identities they phish
Security · September 10, 2026 · 1 publisher
- ShinyHunters claims it scraped 200,000 driver records out of Florida's DAVID lookup portal
Security · September 8, 2026 · 1 publisher
- TeamPCP poisoned more than 1,000 packages with tactics anyone can copy
Security · August 28, 2026 · 1 publisher
- Jack Henry stakes a public refusal on an exposure it counts in institutions
Invest · September 2, 2026 · 1 publisher
- Log4j maintainers call this week's critical RCE reports a known security non-finding
Security · August 28, 2026 · 1 publisher
- ShinyHunters dumps 12.9 million Carhartt records after a refused $3.3 million ransom
Security · August 27, 2026 · 1 publisher
- Take-Two's GTA 6 leak subpoena turns Discord and Microsoft logs into a device-level ID list
Security · August 25, 2026 · 1 publisher
- A DMCA notice over one GitHub repo now asks Microsoft for MachineGuids from three Discord servers
Build · August 22, 2026 · 1 publisher
- The extortion call now comes from your help desk, and the fix is a procedure you own
Leadership · August 19, 2026 · 1 publisher