Breach tracker

Breach report

FBI investigates ShinyHunters' claim to have stolen staff data through its jobs portal; portals still offline

ClaimedDisclosed Report published United StatesGovernmentBy Vivek Kumar
Records UnknownCause VulnerabilityAttributed / claimed ShinyHunters (claimed)
Editorial illustration of an offline job-application form behind a padlock and caution tape, with the headline FBI Jobs Portal: Hack Claim.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The FBI says it is aware of a criminal group claiming to have compromised FBIJobs.gov and is investigating. ShinyHunters claims it used an Oracle PeopleSoft flaw to take terabytes of staff data. The scope is unconfirmed.

What happened

The FBI said it is aware of a cyber-criminal group claiming to have compromised its FBIJobs.gov recruitment portal and that the point of compromise was still undetermined, according to the Associated Press. The extortion group ShinyHunters claims it exploited an Oracle PeopleSoft vulnerability to reach the jobs portal and other internal systems, and says it took 2 to 3 terabytes of data.

Help Net Security reported on 28 September that the FBI's job portals remained offline. TechCrunch, citing MS Now, reported an internal FBI notice declaring a cyber security incident and telling staff that personal details including Social Security numbers were exposed. We have not seen that notice.

Confirmed vs. claimed

Confirmed: the FBI is investigating the claim, and its jobs portals are offline. Claimed: the amount of data, the systems reached and the PeopleSoft route (ShinyHunters). Reported second-hand: the internal staff notice. This is separate from the FBI surveillance-network incident already on our tracker.

Who is affected

If the claims are accurate, FBI job applicants and staff. There is no indication that members of the public who never applied are affected.

What to do

  • US applicants and staff should expect targeted phishing that uses application details, and consider a credit freeze.
  • Organisations running Oracle PeopleSoft should apply Oracle's latest security fixes, limit internet exposure of PeopleSoft portals and check for unknown web shells or remote access tools.
  • Background on this group: ShinyHunters profile.

Sources

More breaches in United States