Six days after the extortion group ShinyHunters claimed it broke into the FBI’s recruiting infrastructure, the bureau’s job-applicant portals are still dark. As of September 28, 2026, both apply.fbijobs.gov and the special-agent applicant portal at fbijobs.gov/special-agents remain unavailable, leaving prospective hires and current staff locked out of a system the FBI uses to manage employment records. The story has moved past the initial “hack claim” news cycle into a harder question: how did an alleged zero-day in decades-old Oracle PeopleSoft software reportedly punch through federal defenses, and why does this keep happening to the same enterprise platform.

This piece digs into the technical chain behind the claim, the PeopleSoft flaw ShinyHunters says it used, the earlier zero-day Mandiant tied to the same group months before the FBI incident, and what the pattern means for every government agency and enterprise still running PeopleSoft in production.

What’s confirmed as of September 28, 2026

Start with what multiple named outlets have independently verified, because the ShinyHunters story has generated plenty of noise that reporters have not been able to confirm. The FBI’s applicant portals went offline around September 22, 2026, and stayed that way through the following weekend. The bureau has publicly acknowledged the incident, telling Reuters: “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” In a more detailed statement carried by ABC News, the FBI said it was working with outside vendors to contain the fallout: “The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information, and we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

Notice the careful phrasing: the FBI has not said whether the breach originated inside its own network or at a third-party contractor that hosts pieces of the applicant pipeline. That distinction matters enormously for liability and for figuring out which systems need patching. As of this writing, the bureau has not named the specific vulnerability, and no independent security firm has confirmed the exact flaw ShinyHunters used against the FBI’s environment specifically.

The PeopleSoft zero-day claim, explained

ShinyHunters told reporters at BleepingComputer exactly which Oracle product it says it broke into: “The Oracle product we exploited the 0day in is PeopleSoft.” The Register’s coverage adds detail on the mechanism, reporting that, according to a spokesperson for the group, the alleged vulnerability enabled remote code execution on the servers. Remote code execution is about as bad as a web-facing vulnerability gets. It means an attacker doesn’t need valid credentials or a phishing victim to get a foothold; a crafted request against an exposed PeopleSoft component is enough to run arbitrary commands.

What makes the claim more alarming is a follow-up statement BleepingComputer quoted from the group: “We found another one yesterday and immediately exploited it on the FBI.” Read literally, that’s a claim of near-real-time zero-day discovery and weaponization against a live federal target, not a patched, months-old bug someone forgot to close. Whether that specific claim holds up under forensic review is unconfirmed. ShinyHunters has an incentive to inflate its own capabilities for extortion leverage, and neither the FBI nor Oracle has validated the “found it yesterday” detail.

CVE-2026-35273 and the May-June precedent

The FBI incident didn’t happen in a vacuum. Google Cloud’s Mandiant threat-intelligence team had already flagged a PeopleSoft vulnerability tracked as CVE-2026-35273, reporting that ShinyHunters exploited it as a zero-day back in May and June of 2026, three to four months before the FBI portal claim surfaced. The FBI’s own public statements have not confirmed that CVE-2026-35273 is the same flaw used against its systems, and no outlet has independently verified that link either. But the timeline is suggestive: a threat group with documented PeopleSoft zero-day capability earlier in the year, followed by a claimed second PeopleSoft intrusion against a federal target in September, is the kind of pattern that keeps enterprise security teams up at night even without a confirmed technical link between the two incidents.

For readers tracking the broader breach timeline, our earlier coverage detailed the moment the FBI first declared the cyber incident and ShinyHunters set its extortion deadline, and the follow-up once the bureau confirmed the breach probe with FBIJobs.gov down for five days. This piece picks up where those left off, on the software-vulnerability side of the story.

Why PeopleSoft keeps showing up in breach reports

Oracle’s PeopleSoft suite runs HR, payroll, procurement, and applicant-tracking workloads for a huge slice of government and higher-education institutions in the US. It’s also old. The core architecture dates to the 1990s, predating modern secure-by-design web frameworks, and many deployments carry years of customization that makes patching slower and riskier than a typical SaaS update. Agencies don’t rip out PeopleSoft because migrating HR and payroll systems is expensive and disruptive, so the software lingers in production long after its architecture has fallen behind current threat models.

That combination, internet-facing, business-critical, and hard to patch quickly, makes PeopleSoft a repeat target rather than a one-off. It sits in the same category as other legacy enterprise software that keeps generating high-severity CVEs years after release: SharePoint’s CVE-2026-65660 landed on CISA’s Known Exploited Vulnerabilities list at CVSS 8.8 earlier this year, and Roundcube’s CVE-2026-48842 SQL injection flaw hit CVSS 8.1 with no authentication required. Old, widely deployed, business-critical software is where attackers put their research budget, because one working exploit chain can be reused against dozens of organizations running the same stack.

Timeline of the FBI PeopleSoft incident

DateEventSource
May–June 2026Mandiant reports ShinyHunters exploiting Oracle PeopleSoft CVE-2026-35273 as a zero-dayGoogle Cloud / Mandiant analysis
September 22, 2026ShinyHunters claims breach of FBI applicant infrastructure; apply.fbijobs.gov and the special-agent portal go offlineReuters, BleepingComputer
September 22, 2026FBI confirms it is investigating claims of unauthorized activity affecting FBIJobs.govReuters
Following daysFBI states point of breach (agency network vs. third-party provider) remains undeterminedABC News
September 28, 2026Both applicant portals remain unavailable; no CVE has been publicly confirmed for the FBI incident specificallyShattered.io reporting

What’s still unconfirmed, and why it matters

Some of the loudest numbers attached to this story have not been verified by the FBI or by independent forensic analysis. Claims that ShinyHunters exfiltrated two to three terabytes of data are unconfirmed. Claims that the haul covers records on nearly all FBI agents, or hundreds of millions of pages of documents, are similarly unverified and should be treated as extortion-group marketing until an independent party checks them. Our earlier report on the FBI hack claim covering 60,000 staff medical files walked through how those disputed figures have shifted as the story developed, a pattern typical of extortion campaigns, where the attacker has every incentive to inflate scope to pressure a victim into paying.

ShinyHunters has also pushed a specific framing of motive. The group told reporters, per The Register’s summary of its statement: “This is NOT financially motivated.” That claim deserves the same skepticism as the data-volume figures. Groups in the ShinyHunters orbit have historically monetized stolen data through leak-site extortion, private sales, or public pressure campaigns, so a stated non-financial motive doesn’t rule out a payment demand arriving separately, nor does it change the operational reality that federal employee data may be circulating outside the FBI’s control.

Market and vendor impact: the third-party question

The detail that should worry federal contractors more than any single-agency breach is the FBI’s own admission that it doesn’t yet know if the intrusion point sits inside its enterprise network or with an outside vendor supporting FBIJobs.gov. Federal HR and applicant-tracking systems are rarely built entirely in-house; agencies lean on systems integrators and cloud hosting partners to run PeopleSoft instances, apply patches, and manage identity federation. If the breach traces to a shared services provider rather than the FBI’s own infrastructure, the exposure could extend to every other agency that provider supports, turning a single-agency headline into a supply-chain story overnight.

That’s the same structural risk that has shown up repeatedly this year when a single compromised vendor rippled across dozens of downstream customers. Enterprise software buyers, especially in government, have been slow to demand the kind of vendor security attestations that would catch this earlier, largely because switching costs on systems like PeopleSoft are so high that agencies tolerate risk they’d reject in a greenfield deployment. The Nexus breach’s exposure of 153 million IDs earlier this year followed a similar shape: a single identity-verification vendor’s failure cascading across every organization that relied on it.

How this compares to other 2026 zero-day incidents

Set against the year’s other major enterprise-software zero-days, the alleged FBI PeopleSoft flaw fits a recognizable shape: old platform, internet-facing component, RCE-class impact, and a threat actor moving faster than the patch cycle.

IncidentVendor/ProductReported severityAttacker capability claimed
FBI applicant portal (Sept. 2026)Oracle PeopleSoftNot publicly assigned a CVE for this specific incidentRemote code execution, per ShinyHunters
CVE-2026-35273 (May–June 2026)Oracle PeopleSoftExploited as zero-day, per MandiantPredates the FBI claim by roughly three to four months
CVE-2026-65660Microsoft SharePointCVSS 8.8, added to CISA KEVExploited in the wild
CVE-2026-48842Roundcube webmailCVSS 8.1Unauthenticated SQL injection
CVE-2026-63077JetBrains TeamCityCVSS 9.8Tied to ransomware deployment against roughly 160 servers

The pattern across this table is not that any single product is uniquely broken. It’s that internet-facing enterprise software with long deployment lifespans keeps producing high-severity, sometimes unauthenticated bugs faster than organizations can patch them. Security teams that treat each disclosure as an isolated event miss the structural trend: legacy platforms are the soft underbelly of otherwise well-defended networks.

Who is ShinyHunters

ShinyHunters is a data-extortion collective that security researchers have tracked since around 2020, generally associated with large-scale data theft and public leak-site pressure campaigns rather than ransomware encryption. The group’s tactics in this incident follow a familiar playbook: claim a technical exploit, assert a large data haul, publicly frame the breach as non-financial to generate press coverage, and let media attention itself become part of the extortion leverage. BleepingComputer’s coverage noted a defacement-style banner reportedly left at the point of compromise: “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.” That kind of theatrical messaging is standard for extortion groups seeking maximum visibility rather than quiet, ransomware-style monetization.

The federal patch problem

Patching a zero-day in a business-critical HR system is not the same as patching a browser. PeopleSoft deployments at large organizations typically run heavily customized modules, integrations with payroll and benefits providers, and identity systems tied to badge access and security clearances. Emergency patches risk breaking those integrations, so security teams face a real trade-off between shipping a fix fast and validating it doesn’t take down applicant processing entirely, which, ironically, is exactly what happened here anyway, just via the attack instead of the patch.

For a sense of how incident responders typically triage this kind of exposure once a vendor zero-day is suspected, the checklist below reflects standard practice rather than any FBI-specific detail, since the bureau has not published its own response playbook.

1. Isolate internet-facing PeopleSoft components from the rest of the network
2. Pull vendor and CDN logs for the affected applicant-portal domains
3. Rotate credentials for service accounts tied to the HR/applicant pipeline
4. Cross-reference outbound traffic against known ShinyHunters infrastructure
5. Notify affected employees and applicants per breach-notification statutes
6. Coordinate with third-party hosting/support providers named in the FBI statement
7. Hold a joint post-incident review with the vendor before restoring service

Historical context: legacy ERP as a recurring target

Enterprise resource planning suites like PeopleSoft, along with adjacent HR and procurement platforms, have been targeted repeatedly over the years precisely because they sit at the intersection of impossible to take offline and expensive to modernize. Government agencies in particular tend to run these platforms well past their originally intended service life, since replacing a payroll or applicant-tracking system touches thousands of employees and years of historical records. That inertia is exactly what makes a confirmed zero-day exploitation chain, like the one Mandiant flagged for CVE-2026-35273 months before the FBI claim, so consequential: once a working exploit exists against a widely deployed legacy platform, it can be reused against any organization running a similar configuration, not just the first victim.

Predictions: what happens next

  • Oracle will face pressure to confirm or deny the PeopleSoft zero-day publicly. Until Oracle issues a security alert naming a specific CVE tied to the FBI incident, other PeopleSoft customers can’t confirm their own exposure.
  • Other federal agencies running PeopleSoft will quietly audit their exposure. Expect internal advisories at agencies with similar HR/applicant infrastructure even without public disclosure.
  • The “point of breach” question will become the central dispute. Whether the intrusion traces to FBI infrastructure or a third-party provider will shape any congressional inquiry and determine which contracts face scrutiny.
  • ShinyHunters’ unverified data-volume claims will shrink under scrutiny. Extortion groups routinely inflate figures before negotiation; expect the eventual confirmed scope, if disclosed, to be narrower than the 2-3 terabyte claim.
  • Expect a CISA advisory referencing PeopleSoft hardening guidance. Given the CVE-2026-35273 precedent and this new claim, a joint advisory covering PeopleSoft internet-facing components would fit the agency’s recent pattern of responding to actively exploited legacy-software chains.

What organizations running PeopleSoft should do now

Regardless of whether the FBI incident traces back to CVE-2026-35273 or a separate flaw, any organization running internet-facing PeopleSoft components should treat this as a prompt to check exposure now rather than wait for an official CVE tied to this specific incident. That means confirming which PeopleSoft modules are reachable from the open internet, verifying patch levels against Oracle’s published Critical Patch Update advisories, and reviewing third-party hosting contracts for who owns incident-response responsibility if something goes wrong. The gap between patched against known CVEs and safe from zero-days is exactly where incidents like this one live, and no amount of compliance paperwork closes that gap on its own.

Security teams should also revisit their assumptions about applicant-tracking and HR systems specifically. These platforms often hold less glamorous data than customer databases, but they contain exactly the kind of personally identifiable information, background-check material, and employment history that make for high-value extortion leverage, especially against a law-enforcement agency where staff identities carry operational sensitivity. Threat-intelligence teams such as Mandiant and Google Cloud’s security research group have both published guidance this year on tracking zero-day exploitation patterns across exactly this class of enterprise software.

Frequently asked questions

Is the FBI jobs portal still down?

Yes. As of September 28, 2026, both apply.fbijobs.gov and the special-agent applicant portal at fbijobs.gov/special-agents remain unavailable.

What vulnerability did ShinyHunters claim to use against the FBI?

ShinyHunters told reporters it used an alleged zero-day in Oracle PeopleSoft, describing it as capable of remote code execution. The specific vulnerability has not been publicly identified or independently confirmed.

Is this the same vulnerability as CVE-2026-35273?

Unconfirmed. CVE-2026-35273 is a separate Oracle PeopleSoft flaw that Mandiant said ShinyHunters exploited as a zero-day in May and June of 2026, months before the FBI claim. The FBI’s public statements have not confirmed that this is the same vulnerability used in the September incident.

Has the FBI confirmed how much data was stolen?

No. Claims that ShinyHunters stole two to three terabytes of data, or data covering nearly all FBI agents, are unconfirmed and have not been independently verified.

Did the breach happen on FBI systems or at a third-party vendor?

The FBI has said this point remains undetermined. The bureau stated it is working with third-party providers that support FBIJobs.gov while it investigates whether the point of breach was its own enterprise network or an outside vendor.

Is ShinyHunters demanding a ransom from the FBI?

The group told reporters its actions were “not financially motivated,” per The Register. That claim has not been independently verified, and extortion groups have historically monetized stolen data through other channels even when publicly framing an attack as non-financial.

What is Oracle PeopleSoft and why is it a target?

PeopleSoft is an enterprise resource planning suite Oracle acquired in 2005, widely used by government agencies and universities to run HR, payroll, and applicant-tracking systems. Its age, heavy customization, and internet-facing components make it a recurring target for vulnerability research and exploitation.

What should other organizations running PeopleSoft do?

Confirm which PeopleSoft components are reachable from the public internet, check patch levels against Oracle’s Critical Patch Update releases, and review which party (internal team or hosting vendor) owns incident response for those systems, since the FBI’s own uncertainty about its breach point shows how murky that responsibility can get.