Circuit Wire — a daily news update from the Circuit.

The FBI is investigating claims by the ShinyHunters extortion group that it broke into bureau systems on Monday night, September 21, defaced the FBI jobs website and stole data on current and former employees and job applicants. The group told BleepingComputer it got in through a new, unpatched flaw in Oracle PeopleSoft.

The bureau said it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." It has not confirmed that its systems were breached or that any data was taken. An alert on the jobs site says apply.fbijobs.gov and the Special Agent Application Portal are unavailable, CyberScoop reported.

ShinyHunters claims it took between 2TB and 3TB of data. The group says it moved from the PeopleSoft foothold into FBI-managed AWS GovCloud infrastructure and also reached the bureau's Criminal Justice, HR and Medlink services. None of those claims has been independently verified. The group also says it is now using the same flaw against other organizations, including Fortune 500 companies. BleepingComputer has asked Oracle and Google's Mandiant whether they know of the alleged vulnerability.

The group shared a screenshot showing apply.fbijobs.gov defaced with its logo and a message claiming that personal and health information on FBI staff and applicants had been compromised. It says the FBI spotted the intrusion quickly and took affected systems offline. 404 Media, which first reported the breach, received a sample of about 5,000 purported FBI employee records and said it verified that some of the information was accurate.

ShinyHunters says the attack is not about money. The group wants the FBI to correct or remove a May 2026 public warning about its tactics, which the bureau issued after the group's attack on Instructure, the company behind the Canvas learning platform. ShinyHunters disputes that warning's claims about swatting and harassment, and it denies ties to the loose cybercrime network known as The Com. It gave the bureau one week to act and would not say whether it would release the stolen data if the FBI does not comply.

The group has hit a long list of large targets this year, including McKesson and Instructure. Last week it breached and defaced the leak site of the Clop ransomware gang, which we reported on Tuesday. The group has also been linked to an earlier Oracle zero-day, used in Clop's 2025 data theft campaign against Oracle E-Business Suite customers.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.