Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

FBI Job Portal Breach Exposes 5,000 Staff Records After ShinyHunters Exploit Oracle PeopleSoft Flaw

ShinyHunters exploited CVE‑2026‑35273 in Oracle PeopleSoft PeopleTools to breach the FBI’s job‑application portal, stealing SSNs and medical records of about 5,000 employees. The incident underscores the need for continuous third‑party risk monitoring and auditable patch‑management evidence for compliance readiness.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 bitdefender.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
bitdefender.com

FBI Job Portal Breach Exposes 5,000 Staff Records After ShinyHunters Exploit Oracle PeopleSoft Flaw

What Happened — The FBI’s online job‑application portal was compromised after ShinyHunters leveraged a recently‑patched Oracle PeopleSoft PeopleTools vulnerability (CVE‑2026‑35273). The attackers exfiltrated Social Security numbers, personal identifiers and sensitive medical/psychiatric records of roughly 5,000 FBI employees, including staff involved in high‑profile investigations.

Why It Matters for Trust & Control Assurance

  • Demonstrates the risk of relying on un‑verified third‑party software updates; continuous vendor‑risk monitoring is essential to prove due diligence.
  • Highlights the need for auditable patch‑management evidence that can be presented during internal or external compliance reviews.
  • Shows how a single unpatched flaw can cascade into a data‑exposure incident, underscoring the importance of a defensible control‑assurance trail for critical applications.

Who Is Affected

  • Federal law‑enforcement agencies (FBI) and their personnel.
  • Any organization that deploys Oracle PeopleSoft PeopleTools or similar enterprise HR/portal solutions.

Recommended Actions

  • Verify that all Oracle PeopleSoft installations are patched to the latest release that addresses CVE‑2026‑35273.
  • Integrate continuous vulnerability scanning of third‑party components into your security program.
  • Update your third‑party risk register to reflect the new exposure and document remediation evidence for audit purposes.
  • Conduct a focused review of data‑handling controls for personally identifiable information (PII) and protected health information (PHI) stored in HR systems.

Technical Notes

  • Attack vector: Exploitation of a known vulnerability (CVE‑2026‑35273) in Oracle PeopleSoft PeopleTools.
  • Data types stolen: Social Security numbers, personal identifiers, medical and psychiatric records of ~5,000 FBI staff.
  • Related activity: The breach was followed by ShinyHunters’ extortion attempts against the ransomware group Cl0p.

Source: Bitdefender Blog – FBI tells ShinyHunters members to turn themselves in

📰 Original Source
https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-shinyhunters-turn-themselves-in-arrest-leader ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →