Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

ShinyHunters Claims FBI Job Portals Breached via PeopleSoft Zero‑Day (CVE‑2026‑35273)

ShinyHunters says it used an unpatched Oracle PeopleSoft zero‑day (CVE‑2026‑35273) to breach the FBI’s job‑application portals and steal personnel and medical records. The incident highlights the importance of continuous patch‑management and evidence‑driven control assurance for audit readiness.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
Medium
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
helpnetsecurity.com

ShinyHunters Claims FBI Job Portals Breached via PeopleSoft Zero‑Day (CVE‑2026‑35273)

What Happened — The extortion group ShinyHunters says it exploited an unpatched Oracle PeopleSoft vulnerability (CVE‑2026‑35273) to gain access to the FBI’s job‑application portals on apply.fbijobs.gov and fbijobs.gov/special‑agents. The attackers allege they stole personnel files, medical records, and assignment data for thousands of current, former, and prospective FBI employees and have kept the sites offline.

Why It Matters for Trust & Control Assurance

  • Unpatched critical ERP vulnerabilities illustrate the need for continuous control‑assurance programs that monitor patch status and enforce network‑segmentation controls.
  • Demonstrable evidence of timely vulnerability remediation and restricted access to sensitive HR systems is a core control objective that satisfies multiple frameworks (e.g., NIST CSF 2.0, ISO 27001).
  • Verisq’s Control Mapping capability can help organizations map patch‑management, network‑segmentation, and logging controls to a unified evidence repository for audit readiness.

Who Is Affected

  • Federal law‑enforcement personnel and applicants.
  • Any organization that runs Oracle PeopleSoft or similar HR/ERP platforms.

Recommended Actions

  • Apply Oracle’s emergency patch for CVE‑2026‑35273 immediately; if patching is delayed, enforce strict network‑level restrictions to the PeopleSoft web tier.
  • Review and tighten access controls around HR/ personnel data, ensuring least‑privilege and multi‑factor authentication.
  • Verify that logging and monitoring of privileged actions are enabled and that logs are retained for forensic review.
  • Conduct a rapid incident‑response assessment to confirm whether data was exfiltrated and to contain any further activity.

Technical Notes – The attack leveraged a zero‑day PeopleSoft flaw first observed in May 2026. Oracle’s advisory recommends emergency patching and, as a temporary mitigation, blocking external traffic to PeopleSoft application servers at the perimeter firewall. ShinyHunters also claims to have accessed FBI‑managed servers in AWS GovCloud, potentially expanding the breach surface. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/09/28/fbi-job-portals-offline-shinyhunters-breach/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →