← Back to Intelligence Library

Threat Intelligence • Developing Threat Actor Profile

ShinyHunters: Claims, Evidence, and the FBIJobs.gov Investigation

A September 25, 2026 assessment of the FBIJobs.gov incident, separating the reported investigation from unverified data-volume and intrusion-method claims.

ShinyHuntersFBIJobs.govData TheftDeveloping Assessment

Last Updated: September 28, 2026

Assessment boundary

This article summarizes the ShinyHunters profile updated September 25, 2026. It preserves that evidence cutoff and should not be read as a live incident update. At that point, the source described the investigation as developing, with the extent and origin of any access unresolved.

Claims and the reported response

According to the profile, actors using the ShinyHunters name claimed on September 22 to possess FBI employee and applicant information. The profile cites a September 23 FBI statement acknowledging an investigation concerning FBIJobs.gov, including work with third-party providers.

The profile distinguishes that response from the actors' assertions. A claimed 2?3 terabytes of data and a claimed Oracle PeopleSoft entry point were not established findings. Reports of apparently genuine personnel information in samples did not establish where the records originated.

Actor context is not incident proof

The profile describes ShinyHunters as a name associated with data theft and extortion, with changing partnerships and possible impersonation complicating attribution. Historical activity can guide questions, but cannot establish the method used in a new incident.

It separately cites Google and Mandiant reporting on a May?June 2026 PeopleSoft campaign associated with UNC6240 and CVE-2026-35273. The source explicitly does not establish that this vulnerability or attack path was used against FBIJobs.gov.

Why the gaps matter

The profile does not assign a detailed ATT&CK chain to the FBIJobs.gov incident because public evidence did not establish initial access, persistence, movement, or exfiltration methods. Its reference to T1190 concerns the separate PeopleSoft campaign only.

Potential personnel-data exposure could enable tailored phishing or impersonation. Those are assessed downstream risks, not confirmed outcomes reported by this profile.

Defensive priorities and collection needs

For recruiting systems, the profile recommends mapping provider responsibilities and data flows, limiting access to applicant records, logging bulk access, and preserving evidence across organizational boundaries. These are general priorities, not findings that a particular FBI control failed.

Future updates should look for confirmed initial access, affected environments, record categories and counts, formal notifications, and technical findings. Those details would support a firmer assessment of scope and a defensible mapping of techniques.

Source research

Adapted from Threat Actor Profile: ShinyHunters. Consult the original note for its references, evidence, and full analysis.

The profile cites the September 23 FBI statement and distinguishes the separate Google and Mandiant PeopleSoft campaign report.

Millie's Perspective

Attribution and incident scope need their own evidence. A recognizable actor name or apparently genuine sample does not establish the entry point, the full volume of data, or access to a wider enterprise.

Key Takeaways

  • This article reflects the source profile's September 25, 2026 evidence cutoff.
  • The reported investigation does not establish the full scope of a compromise.
  • The claimed data volume and PeopleSoft entry point remain unverified in the source.
  • The separate PeopleSoft campaign must not be treated as proof of the FBIJobs.gov attack path.

Project Repository

Interested in the complete project, lab documentation, or research notes? Explore the full repository on GitHub.

View on GitHub →

Related Reading