Photo by Vitaly Gariev on Unsplash. Source: https://unsplash.com/photos/woman-working-on-computer-at-night-qLypTcjzTmA (Unsplash License). A woman working at a computer at night, illustrating an after-hours security incident response.

Executive Summary

ShinyHunters says it left the FBI with two to three terabytes, including names, home addresses, phone numbers, dates of birth, health records and, for some, spouse details containing Social Security numbers. It says the haul covers almost every agent and everyone who ever applied. The Bureau has confirmed only that it is investigating claims of unauthorized activity affecting fbijobs.gov, so the scale remains the attacker’s account.

If any of it holds, the damage is physical rather than commercial. A former FBI official said the data would let any criminal with a grudge target agents and their families. The technical lesson survives either version. A PeopleSoft zero day cannot be patched before it is disclosed, so no patch decided this outcome. Two things did, what the compromised system could reach and how much data could leave unnoticed.

ShinyHunters told BleepingComputer it took two to three terabytes out of the FBI, and its description of the haul is the part that should stop you. Names, home addresses, phone numbers, dates of birth. For some, spouse details including Social Security numbers. Health information. The group says the records cover almost every agent and everyone who ever applied.

The Bureau has confirmed only that it is investigating claims of unauthorized activity affecting fbijobs.gov, and Reuters could not establish that the data came from internal systems. So treat the scale as a claim. 404 Media received a sample of roughly 5,000 records and checked part of it against public data, which is why this deserves attention rather than dismissal.

The Stakes Here Are Physical, Not Commercial

Cynthia Kaiser, a former FBI official, was blunt. Any criminal with a grudge could use this data to target and physically harm not just the agents who investigated them, but those agents’ families. It is why the Bureau is treating the claim seriously before proof arrives.

A file of names, home addresses and family details is also pressure against people who hold clearances. An agency that suspects its staff can be coerced has a problem no firewall solves.

Which is the point. A job application portal carries the personal details of the people who enforce the law. It should be defended like the most sensitive system in the building. In practice it is the least, because recruitment sits outside the security perimeter in most mental models.

Diagram of the PeopleSoft attack path in four stages with the matching control at each boundary. Stage one is initial access to the internet-facing PeopleSoft web tier through the Environment Management Hub, controlled at the perimeter by blocking the PSEMHUB and PSIGW endpoints. Stage two is lateral movement to internal agency services, controlled by segmentation. Stage three is staging and exfiltration, controlled by egress filtering and outbound SMB monitoring. Stage four is persistence through webshells, controlled by file integrity monitoring. None of the four controls is a vendor patch.
The path the group describes, and the control at each boundary. None of the four is a patch.

A Patch Was Never Going to Stop This

A zero day has no patch when it is used. That is the definition, not a failure of diligence. Oracle needed two weeks to answer this group’s June PeopleSoft flaw, tracked as CVE-2026-35273 and rated 9.8, and the current one is still unpatched. Any advice that reduces to patch faster is empty here.

The June campaign shows what worked, and it was not a patch. Mandiant listed network changes applicable the day the advisory landed. Block external access to the Environment Management Hub and the Integration Broker endpoints. Disable the Environment Management service where nothing needs it. Mandiant notes neither breaks normal browser sessions, and a control that costs nothing is one you can apply during an emergency.

This group is not winning on clever bugs. Mandiant tracks it as UNC6240 and describes a crew that leans on weak authentication and misconfiguration. It needs an exposed system and a slow patch cycle, and enterprise resource planning platforms supply both. That is why Rapid7 published mitigations that need no vendor fix.

The Controls That Shrink the Loss

A recruitment portal should never be a route to payroll, health and criminal justice records. On the attackers’ account it was. Segmentation is what turns a catastrophe into an incident, and it is a design choice rather than a vendor feature. The npm worm that reseeds itself every time you patch makes the same point on a different stack.

Egress is the first place to look. The June method compressed staged data and streamed it to an external mirror. Data leaving in terabyte quantities is not subtle, and egress filtering does not care whether the flaw has a CVE yet. This control decides whether a breach becomes a loss.

File integrity monitoring on the web tier is the second. The June intrusions dropped a Java webshell into the deployment directory and left marker files in the application directories. A new executable where only application files belong is worth alerting on.

Identity is the third. The June playbook sprayed SSH credentials at PeopleSoft nodes using hardcoded usernames such as psoft and oracle. Shared service accounts make lateral movement cheap.

Outbound SMB monitoring is the fourth and most overlooked. The June chain made PeopleSoft servers open outbound SMB connections, which leaks Windows machine account password hashes. An HR platform has no reason to open one.

None of these need Oracle to ship anything. The initial compromise may have been unavoidable. Three terabytes leaving was not, and neither was a portal with that much reach. The same lesson landed on vCenter a year ago, and it keeps landing.

Three questions worth asking about any PeopleSoft deployment you own. Is the Environment Management Hub reachable from the internet right now, and if so why. What can the recruitment and HR tier actually reach internally. And would you notice two terabytes leaving, or learn about it from a leak site.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

One thought on “ShinyHunters Says It Took Home Addresses for Nearly Every FBI Agent. No Patch Would Have Stopped That.”

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.