FBI Job Portal Hacked, ShinyHunters Claim They Took Data on Nearly Every Agent
On September 22, 2026, the FBI confirmed it was investigating unauthorized activity on FBIjobs.gov after its Special Agent Applicant Portal went offline. The group behind the claim calls itself ShinyHunters, a data-extortion collective active since 2019, known for breaching Salesforce, Snowflake, and SaaS platforms at scale.
This one is different. Every major ShinyHunters campaign this year followed the same script: steal data, demand payment, leak it if the victim refuses. This time, the group told 404 Media the hack wasn’t financial. It wanted a May 2026 FBI advisory describing its own tactics taken down, and called its goal “maybe coercion” instead of ransom.
The mechanism explains the anger. That advisory, an IC3 public service announcement, laid out ShinyHunters’ playbook in detail: vishing calls, MFA bypass, extortion pressure tactics. Getting profiled by the agency you’re extorting is a credibility problem for a group that runs on fear. The FBI breach, which started Monday night per the group’s own account, is the only 2026 campaign in this pattern that isn’t holding data hostage for money. Every other one is.
The past and future of ShinyHunters
ShinyHunters built its 2025-2026 run on one core weakness: exposed identity, not broken software. The group’s Salesforce campaign used device code phishing and stolen OAuth tokens to compromise more than 1,000 organizations, claiming 1.5 billion records taken. Named victims from that run include Qantas, Harvard, and SoundCloud, spanning airlines, universities, and consumer platforms with no single industry pattern beyond who had exposed guest access or unmonitored SaaS integrations.
Healthcare became a distinct focus starting mid-2026. Health-ISAC issued an urgent alert warning that ShinyHunters was registering medical-themed impersonation domains and calling employees directly on personal devices, bypassing MFA to pivot from single sign-on into connected SaaS platforms. The largest confirmed hit was McKesson, one of the largest US pharmaceutical distributors. ShinyHunters claimed 284 million patient records after an intrusion detected August 25, 2026, and demanded $55,236,150 with a 72-hour deadline. McKesson did not respond, and the group published the data anyway.
The pattern across both runs holds regardless of industry: attackers rarely broke through a firewall. They authenticated as someone they weren’t, through a system nobody was watching closely enough.
The future looks broader, not narrower. ShinyHunters told BleepingComputer it’s now exploiting an alleged Oracle PeopleSoft zero-day against Fortune 500 companies, using the same access method it claims worked on the FBI. Oracle disclosed a critical, unauthenticated PeopleSoft vulnerability (CVE-2026-35273) in June 2026, though Oracle’s advisory hasn’t confirmed a link to the FBI incident specifically. Organizations running PeopleSoft or similar HR and recruitment systems should treat that patch as urgent, not routine. Vishing training belongs on every team’s calendar this quarter, not just IT’s, since the entry point in nearly every ShinyHunters campaign has been a person, not a server.
The mechanism of the exploit
A) The FBI breach. ShinyHunters told BleepingComputer it entered through a zero-day flaw in Oracle PeopleSoft, the HR and recruitment system the FBI uses for job applications, exploiting a remote code execution bug to run its own commands on the server. From that single system, the group claims it moved laterally into AWS GovCloud, the cloud environment storing actual agent and applicant records. The claimed haul runs between 2 and 3 terabytes, covering current and former employees, applicants, and other internal service data. None of this has been independently confirmed; the FBI has acknowledged only that it’s investigating activity on FBIjobs.gov, and Oracle’s own advisory doesn’t tie the disclosed CVE to this specific claim.
B) The Salesforce campaign. This one ran on a different flaw entirely: not a server vulnerability, but a misconfigured permission. ShinyHunters scanned publicly accessible Salesforce Experience Cloud sites for guest user profiles left with excessive access, then used a weaponized version of a legitimate Salesforce debugging tool to query CRM data through exposed API endpoints without ever authenticating as a real user. A parallel track used device code phishing: victims were walked through an OAuth device authorization flow via vishing calls, tricked into approving an attacker-controlled app that requested full API access and refresh tokens. Two different techniques, one shared outcome: the attacker ends up holding a permission the organization never meant to grant.
C) The healthcare vishing pattern. No software flaw at all here, just a phone call. Employees at targeted health organizations received calls or voicemails from numbers spoofed to look internal, guided to a fake login page mimicking their company’s real portal, per Health-ISAC’s technical breakdown. Reverse-proxy phishing kits captured credentials in real time and relayed them to the legitimate login page, prompting the victim to approve the MFA push themselves. The attacker walks away holding a live, authenticated session, granted willingly by the person being deceived.
Three different entry points. Same finish line every time: an identity or a permission the system trusted, used by someone who shouldn’t have had it.
If that finish line sounds familiar in your own estate, a useful next read is how teams keep a current picture of what holds trust and what depends on it: Trusted Runtime Truth.
The guidance, so you don’t get hunted by ShinyHunters
Patch aggressively, and patch the boring systems too. HR platforms, recruitment portals, and vendor integrations rarely sit on a CISO’s priority list, yet they were the entry point in the FBI incident and the wider Oracle PeopleSoft campaign. A patch cadence that treats every internet-facing system as equally urgent closes the gap ShinyHunters has repeatedly used.
Move off SMS and voice MFA for anyone with elevated access. Reverse-proxy phishing kits exist specifically to defeat push-based approval, and they’ve worked. Phishing-resistant methods, FIDO2 security keys or passkeys, remove the human approval step attackers depend on.
Audit guest and third-party access on every SaaS platform, not once, but on a recurring schedule. The Salesforce campaign succeeded because permissions granted years earlier were never revisited. A permission that made sense in 2023 is not automatically safe in 2026.
Train every team on vishing, not just IT and helpdesk staff. The healthcare campaigns worked because employees trusted a familiar-sounding voice on the phone. That trust is the actual vulnerability, and it sits with whoever answers the call, in any department.
Know what’s connected to what, before an attacker finds out first. Every mechanism above, the FBI’s PeopleSoft-to-GovCloud pivot, Salesforce’s guest-access sprawl, healthcare’s SSO-to-SaaS chain, succeeded because the organization didn’t have a current, accurate map of its own dependencies. The attacker’s map was better than the defender’s.
That last point is where ground truth about a system’s actual, current state, not what a spreadsheet says it should be, starts to matter operationally. An accurate, frequently updated picture of what’s running, what it’s connected to, and who or what holds permission to reach it turns a PeopleSoft-to-GovCloud pivot from a silent lateral move into a visible, flagged deviation. Not a product decision. An operational baseline every organization on this list was missing at the moment it mattered most.
Teams that want a clearer baseline for that last control often start with dependency and inventory visibility, then decide what else they need. A short walkthrough is enough for most: request a demo.






