FBI Staff Data Exposed After Jobs Portal Went Unpatched for Months in ShinyHunters-Linked Hack

Reuters verified portions of data allegedly stolen from FBI personnel, while the bureau has not confirmed which vulnerability attackers used or the full scale of the breach

FBI
FBI headquarters amid scrutiny over the ShinyHunters data breach FBI - This file was derived from: Seal of the Federal Bureau of Investigation.svg by Clindberg / Wikimedia Commons

Sensitive personal information linked to thousands of FBI employees was exposed after a contractor failed to implement a security patch on a third-party-managed platform involved in the breach, according to the bureau.

Reuters reported that the exposed material included details of some employees' intelligence assignments, home addresses and medical or psychiatric records.

FBI Cyber Division Assistant Director Brett Leatherman said the bureau's review found that the incident resulted from a security failure involving a platform managed by a third-party organisation after a contractor failed to implement a patch issued to secure it. The FBI did not publicly identify the platform, the organisation managing it or the vulnerability involved.

Two sources familiar with the matter told Reuters that the platform was Oracle PeopleSoft and that the third-party organisation was Accenture. ShinyHunters has claimed responsibility for the September intrusion into FBIJobs.gov and told Reuters that a PeopleSoft vulnerability facilitated the attack. That claim does not establish which vulnerability was used.

FBI Says Contractor Failed to Install Patch

Leatherman told Reuters that the FBI's review found a contractor had failed to implement a security patch specifically issued to protect the affected platform.

The bureau did not identify the contractor, platform or third-party organisation. Reuters' two sources identified the system as Oracle PeopleSoft and the organisation managing it as Accenture. Reuters said it could not identify the individual contractor or determine their employment status.

The FBI said it had removed the contractor and taken steps to mitigate further risk and protect its workforce. Accenture told Reuters that it was 'proud to support the mission of the FBI and will continue to do so'. The company did not answer questions about the contractor or the reported patching failure.

The FBI's finding confirms that a security patch issued to protect the platform was not implemented. It does not publicly establish that CVE-2026-35273, or any other specific disclosed PeopleSoft vulnerability, was the route used to compromise FBIJobs.gov.

Oracle Issued Critical PeopleSoft Alert in June

Oracle issued an out-of-band security alert on 10 June for CVE-2026-35273, a critical vulnerability affecting PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. Oracle assigned it a CVSS score of 9.8 and said it could be exploited remotely without authentication, potentially allowing remote code execution.

Mandiant and Google's Threat Intelligence Group said UNC6240, which they track as ShinyHunters, exploited CVE-2026-35273 as a zero-day between 27 May and 9 June. Oracle disclosed the vulnerability on 10 June and urged customers to take immediate action.

On 25 September, Mandiant reported renewed mass exploitation of the same flaw. Researchers said the attackers had modified their technique by URL-encoding a character in the vulnerable request path, allowing them to bypass some web application firewall rules. Mandiant said web shells had been deployed on dozens of systems worldwide across sectors including government, healthcare, technology, transport and higher education. It warned that firewall rules were not a substitute for installing Oracle's patch.

The timing makes CVE-2026-35273 relevant to the FBI investigation, but neither the FBI nor Oracle has publicly confirmed that it was used in the FBIJobs.gov breach. Reuters also said it could not determine whether or when those responsible for securing the jobs site followed Oracle's earlier recommendations.

Reuters Verified Parts of Purported FBI Data

Reuters reported that material attributed to the breach contained detailed descriptions of some FBI employees' assignments, including work involving counterintelligence, surveillance and human intelligence.

A roughly 5,000-line spreadsheet reviewed by Reuters contained names, addresses, telephone numbers, dates of birth, Social Security numbers, emergency contacts and assignment information. Reuters said it could not authenticate the entire spreadsheet, but independently verified details relating to more than 22 people by comparing the material with credit records, previous data leaks and other sources.

In separate reporting, Reuters examined about half a dozen purported medical and psychiatric files and partially authenticated some of them through credit data, professional records and other checks. Reuters said the small number of medical documents it reviewed was insufficient to establish whether they were representative of the wider dataset ShinyHunters claimed to possess.

The hacking group has made broader claims about information allegedly taken from current and former FBI personnel and applicants. The FBI has not publicly confirmed the full size or contents of the dataset claimed by the group.

FBI Investigation Remains Active

Reuters reported that suspected ShinyHunters member Saif al-Din Khader was detained by Jordanian authorities, citing three people familiar with the matter. Two sources said Khader was cooperating with the FBI and other law-enforcement agencies and helping investigators locate other suspected members of the group.

The FBI declined to confirm a specific overseas detention. It said it continued to investigate the cyber incident and pursue those responsible.

The bureau's review establishes that a contractor failed to implement a security patch on a third-party-managed platform involved in the incident. But significant questions remain, including which vulnerability attackers used, how much information was obtained and the precise sequence of failures that allowed the FBIJobs.gov environment to be compromised.