Product1 publisher3 min readPublished
ShinyHunters gives the FBI a week to pull its own advisory on ShinyHunters
The group says it took employee and applicant records out of FBIjobs.gov and wants the bureau's May FLASH report corrected or removed inside a week. Four days earlier it had asked a different victim for money.
The Product Desk · Product desk
What happened
- ShinyHunters claims it holds names, home addresses, phone numbers and spouse details for FBI employees and job applicants, according to multiple reports published Sept. 22.
- In a message to Director Kash Patel and cyber assistant director Brett Leatherman, quoted by PCMag, the group gave the FBI one week to correct or remove what it calls the 2026 Quarter 2 FLASH report.
- The bureau said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," in a statement to PCMag.
- The group told The Register it reached FBI-managed servers on AWS GovCloud and downloaded two to three terabytes, naming human resources, MedLink and Criminal Justice Information Services among affected services.
- On Sept. 18 the same group hijacked the Cl0p ransomware gang's leak website and demanded an eight-figure payment.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- exposure Rejected applicants have no live relationship with the bureau, no notification channel, and no way to change a home address they typed into a form years ago.
- decision The bureau now has to decide whether to edit a published warning under a deadline. That puts its communications team inside the incident response.
- contradiction The same group asked another victim for an eight-figure payment four days earlier, so the retraction demand looks like an added option in the toolkit.
- constraint No component, version or configuration has been named, so a team running PeopleSoft has nothing specific to test or patch this week.
Somebody filled in a form on FBIjobs.gov and never heard back. 404 Media was given a sample that the group says holds personal information on 5,000 FBI employees, including home addresses, phone numbers, dates of birth and, in some cases, details about spouses [4]. Using OSINT Industries, the outlet found that some phone numbers corresponded to the names listed alongside them, and a separate check using Darkside, a tool for searching previously compromised data, linked some numbers to Department of Justice personnel [5].
What the group wants changed is a document. The May 15 advisory went out after an attack on a learning management platform disrupted educational institutions [10]. It warned victims that attackers use "real or exaggerated claims of access to sensitive or personal information" to pressure them into paying [11]. The same advisory said ShinyHunters uses harassment strategies, including threatening calls and messages to victims and their families and, in some cases, swatting [12]. "This is NOT financially motivated," a spokesperson told The Register. "We want the FBI to correct or retract their statements they made, which included substantial false allegations" [7]. In the message to the bureau, the group said its threats and claims were real, not exaggerated and not a bluff, and pointed to that day's PSA as proof of it [14].
The Cl0p leak site takeover came four days before the FBI claims surfaced [22]. Inside that week the group asked one victim for money and the other for an edit, and both pages carried a message mimicking a law enforcement seizure notice [8][20].
For a team running the same HR software, the intrusion account is not yet enough to act on. ShinyHunters told The Register it exploited a zero-day in Oracle PeopleSoft that let it run commands on the servers without logging in first [15]. Cybersecurity firm CyPro, analysing The Register's reporting, wrote that "ShinyHunters did not publicly identify a vulnerability reference, PeopleSoft component, exploit request, affected configuration or product version" [17]. The reporting also did not establish how the attackers moved from the recruitment website into other systems [18]. Google's threat intelligence researchers documented a ShinyHunters campaign exploiting a PeopleSoft vulnerability in June, with educational institutions among its targets [19].
A team that owns a careers portal should be asking how long a record lives past the decision it was collected for. The second question is whether the system holding it has an owner on the product side or arrived as a procured HR module patched on the vendor's schedule. An applicant record supports one decision, hire or do not hire. The recruitment site is where ShinyHunters says it started [15]. Mashable notes that home addresses, phone numbers and family details could give harassers or foreign intelligence services a way to reach not only employees but the people closest to them, and that even applicants who never got the job could be exposed [21].
What to watch
- Whether the FBI amends, removes or stands by the 2026 Quarter 2 FLASH report once the group's one-week deadline passes.
- Whether Oracle publishes a PeopleSoft advisory matching the claimed pre-authentication command execution flaw.
- Whether the FBI's investigation places access beyond FBIjobs.gov, in the HR, MedLink or CJIS systems the group named.