In short: On September 22, 2026 it became public that the ShinyHunters extortion group had defaced the FBI's jobs site. The group claimed it stole 2 to 3 terabytes of employee and applicant data through an unpatched flaw in Oracle PeopleSoft. The FBI says it is investigating. It has not said how the attackers got in or what was taken, and it says the point of breach is "still undetermined," whether at a third-party provider or at the FBI itself. What is confirmed is the pattern behind the claim: in May and June the same group exploited a PeopleSoft flaw in a campaign that led Mandiant to warn more than 100 organizations with exposed systems, and that flaw is on CISA's exploited list. If your company runs any hiring, HR or payroll system that faces the internet, this is your week to find out who patches it.
You may not run PeopleSoft. Many North Carolina manufacturers and distributors do run something in the same position: a careers page that feeds an applicant system, a payroll or benefits portal, an ERP web screen for remote staff. These systems face the internet on purpose. And they hold the most sensitive records a small company keeps: Social Security numbers, dates of birth, home addresses, sometimes spouses and dependents.
Key takeaway: The FBI story is still a claim. The lesson does not depend on it. Your hiring and HR systems are internet-facing by design and hold your most sensitive employee data. This group has now gone after PeopleSoft twice in four months: once confirmed by Mandiant in June, once claimed against the FBI this week.
Want someone to find every HR, payroll and ERP system you have facing the internet, and who patches each one? Preferred Data Corporation has done this work for Piedmont Triad companies out of High Point since 1987. Call (336) 886-3282 or contact us.
What happened at the FBI, and what is actually confirmed?
As of September 23, 2026, one thing is confirmed from the FBI's side: it is investigating, and it has not yet determined whether the breach happened at a third-party provider or inside the FBI. Journalists have partly verified a sample of stolen records. Everything else, including the zero-day, the cloud pivot and the data volume, comes from the attackers.
Here is where each piece stands, source by source:
| Claim | Who says so | Status as of Sept 23 |
|---|---|---|
| FBIjobs.gov was defaced with a "seized by ShinyHunters" banner | The Register, CyberScoop | Widely reported. The FBI statement refers to "unauthorized activity affecting FBIjobs.gov" |
| The FBI is investigating | FBI statements quoted by Nextgov/FCW and Cybersecurity Dive | Confirmed. The FBI has not said how attackers got in or what was taken, and says the point of breach is undetermined |
| Names, home addresses and phone numbers of agents and spouses were taken | Sample given to 404 Media, per TechCrunch | Partly verified: 404 Media checked a portion against public records |
| Entry was a new, unpatched Oracle PeopleSoft flaw | The attackers, per BleepingComputer | Unverified. No CVE. Oracle did not respond to Cybersecurity Dive |
| They moved into FBI servers in AWS GovCloud and took 2 to 3 TB | The attackers, per CyberInsider | Unverified |
| Motive is retaliation for the FBI's May 15 warning about the group | The attackers' own statement | Their stated reason. They demand the warning be withdrawn within a week |
The FBI first said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." On September 23 it went further, telling Cybersecurity Dive that "the point of breach is still undetermined," whether at a third party or inside the FBI, and that it is working with "those third-party providers that support FBIJobs.gov." At least one outlet has attributed the zero-day and GovCloud details to an FBI spokesperson. That does not match either FBI statement, so we are treating those details as the attackers' claims until the FBI or Oracle says otherwise.
Why would a hacking group go after a hiring portal?
Because an applicant portal has to accept connections from strangers, and it stores exactly what extortion crews sell. Its whole job is to let people you have never met upload personal details. That makes it one of the few internal systems a company deliberately puts on the open internet.
The June campaign shows the pattern is not new. Google's Mandiant team reported on June 11, 2026 that ShinyHunters exploited a PeopleSoft flaw as a zero-day from May 27 to June 9. Mandiant notified more than 100 organizations whose exposed systems matched, 68 percent of them in higher education and most in the United States. Data taken in that campaign was posted to the group's leak site on June 9.
The FBI claim names the same doorway. A screenshot the group shared with CyberInsider appears to show a /PSEMHUB/ page on the FBI applications site. That is the same PeopleSoft component, Environment Management Hub, that the June flaw lived in.
Is this the same PeopleSoft flaw Oracle fixed in June?
Nobody outside the FBI and the attackers knows yet. The group says it is new. It could also be the June flaw on a server that was never patched. For a business owner the action is the same either way: find the system, patch it, and take the management piece off the internet.
The June flaw is CVE-2026-35273. It scores 9.8 out of 10: an outsider can reach the /PSEMHUB/hub endpoint without logging in, and that can lead to running code on the server. It affects PeopleSoft PeopleTools 8.61 and 8.62. Oracle issued an emergency Security Alert on June 10. Rapid7 reports that it came with an out-of-band patch, while early coverage said only mitigations were available, and CISA added it to the Known Exploited Vulnerabilities catalog on June 12. At the time, Oracle called its recommended mitigations "a high-priority risk reduction measure," SecurityWeek reported.
That is three and a half months ago. If the FBI claim turns out to be the old flaw, the lesson is patch ownership. If it turns out to be a new one, the lesson is exposure: a management component that no outsider needs should not answer outsiders at all. Mandiant's first recommendation covers both. Disable the Environment Management Hub, or block outside access to /PSEMHUB/* and /PSIGW/HttpListeningConnector at the firewall. Mandiant adds that web-application-firewall rules on their own "can be bypassed."
We do not run PeopleSoft. Does this still apply?
Skip the patch. Keep the inventory question. Plenty of companies without PeopleSoft still have hiring, HR, payroll or ERP systems that someone opened to the internet, sometimes years ago, without anyone clearly owning the patching.
Send your IT provider three questions in writing, with a reply-by date:
- Which of our systems that hold employee or applicant data can be reached from the internet, and who hosts each one?
- For each one, who applies security updates, and when was the last one applied?
- Do any of them run Oracle PeopleSoft, and if so, is Oracle's June 10 Security Alert guidance applied and is the management hub blocked from outside?
You do not need to follow the technical detail to grade the answers. A good answer names things. A brush-off does not.
| What you asked | An answer that means something | An answer that means nothing |
|---|---|---|
| What faces the internet | Names each system, whether it is hosted by a vendor or by you, and how staff reach it | "It is all in the cloud" |
| Who patches it | A name or a vendor for each system, plus a date | "We keep everything up to date" |
| PeopleSoft | "None here," or a version, a patch date and a firewall rule | "We would have to check" |
A "we would have to check" is not proof anything is wrong. Usually it means nobody has asked in years. For a system that holds Social Security numbers, it is still worth fixing this month.
If you would rather hand those three questions to someone who knows what a good answer looks like, Preferred Data Corporation's cybersecurity team is in High Point at (336) 886-3282.
What should a PeopleSoft shop check this week?
Patch, then block, then look for signs someone was already inside. A patch closes the door. It does not tell you whether someone already came through it.
We covered the June flaw in detail when it broke, in our Oracle PeopleSoft CVE-2026-35273 defense guide. Hand that guide and Mandiant's June hunting guidance to your IT team. The short version:
- [ ] Confirm Oracle's current fix or mitigations from the June 10, 2026 Security Alert are applied
- [ ] Disable the Environment Management Hub, or block outside access to
/PSEMHUB/*and/PSIGW/HttpListeningConnectorat the firewall - [ ] Hunt for signs of the June campaign on those servers since late May, using Mandiant's indicators
What is new this week: if the FBI claim holds, blocking the management hub from the internet matters even more, because a patch cannot protect against a flaw Oracle has not fixed yet. When Oracle or the FBI says whether the September flaw is new, we will update this post.
What happens to your employees' families if HR data leaks?
This group does not stop at the company. The FBI's May 15 warning, public service announcement I-051526-PSA, says ShinyHunters actors send "threatening text messages and phone calls to victims and their family members, and in some cases, swatting." That warning is the one the group now wants withdrawn.
For a small employer, that changes what a breach means. Stolen HR records give an extortion crew a home address and a spouse's phone number, not just an email login. If your HR or applicant data is ever exposed, brief your people before the calls start. Use the FBI's own advice:
- Verify any urgent or unusual request through a different channel before acting on it
- Do not pay and do not engage with the demand
- Report it to IC3, 1-800-CALL-FBI, or the FBI Charlotte field office, which covers North Carolina. Save every phone number, username, message and screenshot
There is also a legal clock. North Carolina's breach statute, G.S. 75-65, puts the duty to notify on the business that owns or licenses the personal information. That is you, even when the system belongs to a vendor. If the incident meets the statute's definition of a breach in G.S. 75-61, notice goes to affected North Carolina residents "without unreasonable delay" and to the Attorney General's Consumer Protection Division. If more than 1,000 people are notified at once, the nationwide consumer reporting agencies must be notified too.
How much applicant data should we be keeping at all?
Keep only what you are required to keep. Records you have deleted cannot be stolen. Federal rules under 29 CFR 1602.14 generally require employers to keep applications and hiring records for one year from the date the record was made or the hiring decision, whichever is later. Larger federal contractors must keep them for two years under 41 CFR 60-1.12, and anything tied to a pending charge or lawsuit must be kept until it is resolved. Many applicant systems keep everything forever unless someone changes the setting.
Ask your HR lead and your counsel how long you actually need to keep applicant files, including any litigation holds. Then ask your IT provider whether the system is set to purge on that schedule. Also ask whether you collect Social Security numbers at the application stage at all, or only after an offer.
Key takeaway: The cheapest breach to clean up is the one where the old records were already gone.
What should we do this week?
Four steps, in order. None of them depend on how the FBI story turns out.
- Inventory. List every system holding employee or applicant data that can be reached from the internet, and who hosts it.
- Assign patching. Put one owner and a last-patched date against each one. Send the three questions above if you cannot fill that in.
- Close what outsiders do not need. Admin panels and management hubs should never answer the public internet. Network segmentation and firewall rules do this cheaply.
- Shrink and prepare. Set a retention schedule for applicant data, and write a one-page note telling staff what to do if an extortion call reaches their home.
Our managed IT team can walk you through steps one through three. Call (336) 886-3282.
Frequently Asked Questions
Did ShinyHunters really hack the FBI?
The FBI has confirmed an investigation into unauthorized activity affecting FBIjobs.gov. It has not said how the attackers got in or what was taken, and says the point of breach is still undetermined. The jobs site was defaced and 404 Media partly verified a sample of stolen records. As of September 23, 2026, the zero-day, the cloud pivot and the 2 to 3 TB figure are the attackers' claims.
Is there a patch for the PeopleSoft flaw used against the FBI?
Not that anyone has announced. There is no CVE or Oracle statement for the flaw the group claims to have used. The earlier flaw from the June campaign, CVE-2026-35273, has been covered by an Oracle Security Alert since June 10, 2026. Blocking outside access to the PeopleSoft management hub is the step most likely to help against both.
We use a hosted applicant tracking system. Is this our problem or the vendor's?
The patching is the vendor's. Under North Carolina law, notifying your applicants is yours. Ask the vendor in writing how quickly it would tell you about a breach, and whether it keeps your data after you delete it.
What should an employee do if someone calls their home claiming to have company data?
Hang up, do not pay, and call a known number at the company to report it. Write down the number, time and what was said. The company should report it to IC3 or the FBI Charlotte field office, following the FBI's own guidance in PSA I-051526-PSA.
Should we pull our careers page offline until this is resolved?
Usually not. A careers page that only links to a hosted applicant system carries little risk by itself. The risk sits in the system that stores the applications. Check that system's owner and patch status instead.
Why does the FBI's May warning matter to a manufacturer?
It describes how this group applies pressure once it has data: contacting victims and their family members directly. For an employer, those victims are your employees. That is a people problem as much as an IT one. It belongs in your incident plan next to the technical steps.
Where we are: Preferred Data Corporation has worked on North Carolina back-office and plant-floor systems out of High Point since 1987. We go on site within 200 miles, including Greensboro, Winston-Salem, Charlotte and Raleigh. Call (336) 886-3282, email [email protected], or visit us at 1208 Eastchester Drive, Suite 131, High Point, NC 27265.
Related Resources
- Mandiant: ShinyHunters targets education sector with Oracle PeopleSoft exploit (June 11, 2026)
- CISA: CVE-2026-35273 added to the Known Exploited Vulnerabilities catalog, June 12, 2026
- FBI PSA I-051526-PSA: ShinyHunters: Cyber Criminal Group Attacks Learning Management System (May 15, 2026)
- North Carolina G.S. 75-65: protection from security breaches
- Preferred Data Cybersecurity Services
- Preferred Data Managed IT Services
- Preferred Data Network Infrastructure
- Preferred Data Manufacturing IT
- Oracle PeopleSoft CVE-2026-35273: the June zero-day and how to respond
- ShinyHunters at Abbott: vishing, single sign-on and SaaS data theft
- The Cushman and Wakefield vishing breach and your Salesforce data
- The BOD 26-04 patch clock and what it means for NC small business