Hackers Claim They Breached the FBI — Here’s What Las Vegas Businesses Should Take From It
The extortion group ShinyHunters says it stole 2–3 TB of FBI personnel data through an unpatched vendor system. The FBI hasn’t confirmed it — but the attack path it describes is one small businesses face every day.
Published by CMIT Solutions of Las Vegas · Cybersecurity · 7 min read
As of this writing, neither the FBI nor Oracle has confirmed the specific vulnerability or the full scope of stolen data. This article reflects what the hacking group has claimed publicly and what independent outlets have been able to partially verify. We will update this post as confirmed details emerge.
On September 22, 2026, the data-extortion group known as ShinyHunters — the same group linked to breaches at Salesforce-connected apps, Carnival, Charter Communications, and the Canvas learning platform — claimed it had broken into multiple FBI systems and stolen sensitive data on nearly every current and former FBI employee and job applicant. The FBI has confirmed it is investigating “unauthorized activity affecting FBIJobs.gov,” and the job-application portal was still offline as of the following afternoon.
How the Attackers Say They Got In
According to the hackers themselves — not an FBI advisory or a published security bulletin — the entry point was a previously unknown (“zero-day”) vulnerability in Oracle PeopleSoft, the same enterprise software category tied to the FBI’s recruitment site, FBIJobs.gov. ShinyHunters told researchers the flaw allowed remote code execution without needing valid login credentials, and that they used it Monday night to get into FBI-managed systems before moving laterally into FBI-hosted AWS GovCloud infrastructure.
- No CVE number published. Neither Oracle nor the FBI has confirmed which PeopleSoft vulnerability, if any, was used, or which product versions are affected.
- Different from the June 2026 PeopleSoft zero-day. Oracle PeopleSoft was previously hit by a separate, confirmed vulnerability (CVE-2026-35273) that ShinyHunters exploited against 100+ organizations earlier this year. It is not yet clear whether this is the same flaw left unpatched somewhere, or a second, distinct zero-day.
- Claimed lateral movement into cloud infrastructure. The group says the initial foothold on a public-facing recruitment system allowed it to reach further into FBI-managed AWS GovCloud environments — a pattern that mirrors how many small-business breaches unfold, just at government scale.
What They Claim to Have Taken
ShinyHunters says it exfiltrated 2–3 terabytes of data from three internal FBI systems it named as “Criminal Justice (CJ),” “Human Resources (HR),” and “Medlink,” including names, home addresses, phone numbers, dates of birth, and details on employees’ spouses. The group released a 5,000-record sample; 404 Media and Reuters each independently matched a portion of it against public records and credit-bureau data — meaning parts of the claim appear credible, even though the full scope remains unverified.
Is It Still Active?
FBIJobs.gov was reportedly defaced by the attackers and remained offline more than a day after the claim surfaced. No patch or advisory has been published for the vulnerability described, which means that if the claim is accurate, the underlying flaw may still be exploitable elsewhere. ShinyHunters says the motive isn’t financial — it’s demanding the FBI retract a threat-intelligence report the group says makes false claims about it, with a one-week deadline. Security researchers are treating the technical details as an unverified threat-actor claim until Oracle or the FBI confirms them.
This would be the second confirmed-or-claimed breach of an FBI system in 2026, following an earlier, separate intrusion into a system used to manage wiretap and foreign-intelligence surveillance warrants.
What This Means If You Run a Business in Las Vegas
It’s tempting to read this as a story about the federal government and move on. It shouldn’t be. The attack path described — an unpatched, internet-facing vendor application, used as a stepping-stone into more sensitive systems — is the exact pattern behind most of the breaches we’ve covered this year, from Veradigm to the Salesforce-Gainsight incident. If it can happen to an agency with a dedicated cybersecurity budget in the billions, it can happen to a 20-person Las Vegas firm running the same category of off-the-shelf enterprise software.
• Third-Party Software Is Your Attack Surface
The GapMost businesses track patching on their own laptops and servers, but not on the vendor platforms (HR systems, recruiting portals, CRM add-ons) that hold their most sensitive data.
The FixMaintain a full inventory of every third-party application that touches employee or customer data, and confirm someone — you or your IT provider — is actually watching for vendor security advisories, not just internal ones.
• A Zero-Day Doesn’t Mean You’re Helpless
The GapBy definition, no patch exists yet for a true zero-day — but most breaches attributed to one turn out to involve older, already-patched flaws left unaddressed.
The FixNetwork segmentation and monitoring limit how far an attacker can move even after getting in — the FBI’s own claimed weak point was lateral movement from a public recruiting site into internal systems, not the initial entry alone.
• Employee PII Is a Target, Not Just Customer Data
The GapBusinesses often lock down customer and financial records while leaving HR files — names, addresses, dates of birth, family details — on far less protected systems.
The FixApply the same access controls, encryption, and vendor vetting to HR and payroll systems that you apply to customer data — a breach of employee records carries its own legal and trust costs.
Not Sure What Vendor Software Is Touching Your Sensitive Data?
Get a free IT assessment and find out before an attacker does.
This story is still developing, and the responsible read is skepticism paired with preparation: treat ShinyHunters’ claims as unconfirmed until the FBI or Oracle says otherwise, but treat the attack pattern itself as proven — because we’ve already covered a half-dozen real breaches this year that started exactly this way. CMIT Solutions of Las Vegas helps Clark County businesses inventory their vendor software, patch on a real schedule, and build the network segmentation that limits the damage when — not if — something gets through.
Don’t Wait for a Headline to Find Your Weak Point
CMIT Solutions of Las Vegas helps local businesses find and fix the vendor and third-party risks attackers look for first.
Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com