The FBI Jobs Breach, ShinyHunters, and What It Means for San Joaquin County
The FBI Jobs Breach, ShinyHunters, and What It Means for San Joaquin County
LodiEye — October 2026
Summary
In late September 2026, a hacking and extortion group called ShinyHunters said it had broken into FBIJobs.gov, the FBI’s recruiting website, altered the site and stolen sensitive records on FBI employees and job applicants. The FBI first said it was investigating claims of unauthorized activity. It later called the matter a cyber incident and said it was contacting people who may be affected. Internal notices reported by news organizations told employees that names, home addresses, job titles and Social Security numbers were exposed.[7][11]
Journalists who examined samples of the stolen data reported records tied to real FBI or Justice Department personnel, including family contact information and medical or psychiatric material. That supports the conclusion that a serious theft occurred. It does not prove every claim the hackers have made. Their statements that they took records on nearly all FBI personnel, a large number of applicants, and 2 to 3 terabytes of data in total have not been confirmed in full.[10][12]
The hackers say they got in through Oracle PeopleSoft, a widely used software package for payroll, human resources and finance, and then moved into other FBI-managed systems. The FBI has not confirmed that account. The claim came during a documented ShinyHunters campaign against a serious PeopleSoft security flaw, one that lets an attacker into a system over the internet without a password. Oracle released a fix on June 10. Google’s Mandiant security unit later documented attackers getting past temporary network blocks at organizations that had not installed the fix.[3][6]
Two developments followed in the last days of September. Dutch police and the FBI announced that a 24-year-old Amsterdam man, described by the FBI as one of the group’s alleged leaders, had been arrested on September 15, about a week before the FBI breach became public. Separately, ShinyHunters told several news outlets it does not plan to publish or sell the FBI data and called the episode a “marketing campaign.” That statement cannot be verified, and the data remains in the group’s hands. On October 1 the group’s leak site was back online, listing two new corporate targets.[9][22][25][26]
For San Joaquin County, the incident is a reason to check local systems. It is not evidence of a local breach. County documents show the county uses PeopleSoft for human resources and has been working on an upgrade, and older materials describe PeopleSoft-based employee self-service, finance and payroll functions. The county’s current software version, whether the system can be reached from the internet, and whether the June fix is installed are not public.[14]
Status as of October 2
A serious theft of FBI personnel data is supported by internal notices and by samples that journalists checked independently. The specific PeopleSoft entry path, the claimed 2-to-3-terabyte volume and the final number of affected people remain unconfirmed. ShinyHunters says it will not publish the FBI data, a statement that rests on the group’s word alone. One alleged leader is in custody in the Netherlands, and the group remains active. No publicly disclosed compromise of San Joaquin County systems through this PeopleSoft flaw was identified.
The FBIJobs incident
The public evidence comes with different levels of certainty. This section separates what the FBI has acknowledged, what its internal communications reportedly say, what journalists checked independently, and what ShinyHunters alone claims.
Confirmed or corroborated
- The FBI acknowledged a cyber incident involving FBIJobs.gov and said it had not yet determined whether the point of entry was an FBI system or a supporting third party.
- The application portals were taken offline after the public claim and were still unavailable on September 28.[27]
- The bureau sent organization-wide communications and advised employees to take added security precautions.
- News organizations authenticated portions of sample data against public records or sources familiar with FBI personnel. One outlet reported receiving a sample covering roughly 5,000 employees.[7][10][27]
- In a September 29 statement, the FBI said it was working around the clock on the incident and was in regular communication with anyone who may be affected.[24]
Still alleged
- That a previously unknown PeopleSoft flaw provided the initial access.
- That the attackers moved from the recruiting environment into AWS GovCloud or other FBI-managed systems, including systems the group says hold background-check, medical and investigative information.[27]
- That the group removed 2 to 3 terabytes and obtained records covering nearly all FBI employees and many applicants.
- That every sampled record originated in an FBI-managed system and not in a connected or third-party environment.
- That the group will not publish, sell or otherwise use the data, as it now says.[25]
What the available evidence establishes
| Data category | Evidence available | Assessment |
|---|---|---|
| Names, addresses, job titles and Social Security numbers | Reported from an internal FBI employee notification. | High confidence that some records were exposed; final scope is not public. |
| Family contact details | Samples supplied to journalists; portions checked against public records. | High confidence for sampled records. |
| Medical, laboratory and psychiatric information | Multiple outlets reported reviewing or confirming such records. | High confidence for sampled records; breadth unknown. |
| Sensitive unit or assignment information | Reported in samples reviewed by major outlets. | Moderate to high confidence; extent unknown. |
| Applicant records | Claimed by ShinyHunters; the portal has long handled job applications.[2] | Plausible, but scope is unconfirmed. |
| 2 to 3 terabytes, or nearly all personnel | ShinyHunters claim and a reported FBI worst-case operating assumption. | Not a final forensic count. |
Source: FBI statements and reporting by AP, CBS News, TechCrunch, NPR and Reuters.[7][8][10][12][13]
Timeline
The FBI’s Internet Crime Complaint Center (IC3) warns that ShinyHunters uses large-scale data theft and extortion, following an attack that affected a learning-management system.[1]
Oracle publishes its security alert for the PeopleSoft flaw, catalogued as CVE-2026-35273, and urges customers to install the fix.[3]
Dutch police arrest a 24-year-old Amsterdam man on suspicion of participating in a criminal organization, in an investigation into ShinyHunters. The arrest is not made public until two weeks later.[9][23]
ShinyHunters claims the FBIJobs compromise. The recruiting and special-agent applicant portals become unavailable.
The FBI says it is aggressively investigating and has not determined whether the entry point was an FBI or third-party system.[7]
Mandiant reports renewed mass exploitation of CVE-2026-35273 across government, health care, education, agriculture, transportation and other sectors.[6]
Reporting reveals an internal FBI cyber-incident notification and employee exposure. A reported memo says the bureau is operating under a broad worst-case assumption.[11][12]
ShinyHunters tells news outlets it never intended to publish or sell the FBI data and describes the confrontation as a “marketing campaign.” Dutch police confirm the September 15 arrest.[24][25]
The FBI and Dutch National Police formally announce the arrest. Brett Leatherman, assistant director of the FBI Cyber Division, calls the suspect one of the group’s alleged leaders, says he and others allegedly breached more than 140 organizations and took at least $70 million in extortion payments since last year, and urges remaining members to contact the bureau.[9][22][23]
The ShinyHunters website goes offline after the group’s deadline for the FBI to alter or withdraw its May advisory expires. The cause is not disclosed.[13]
The group’s leak site returns at a new address. ShinyHunters tells Cybernews the outage came from its own upgrades and attacks by rivals, not an FBI takedown. The site lists O’Reilly Automotive and Dexcom as new targets, without sample data, and threatens to publish by the end of Friday, October 2.[26]
Why the breach matters
The material described in the reporting is valuable for more than identity theft. Home addresses and family details can be used for intimidation or physical targeting. Employment, assignment, medical and psychiatric information can support tailored phishing, impersonation, profiling and attempted recruitment by hostile intelligence services. ShinyHunters now says it will not publish or sell the data. Even if that holds, the group still has it, and samples already shared with journalists and other parties cannot be recalled.[25]
- Personal safety: Employees and relatives may face harassment, publication of their home details or threats.
- Counterintelligence: Detailed biographical and medical information can identify pressure points and make deceptive approaches more convincing.
- Operational security: Assignment or unit information can reveal relationships and organizational patterns even without case files.
- Long-term fraud: Social Security numbers, addresses and employment histories keep their value after passwords are changed.
- Institutional trust: Limited or delayed disclosure leaves employees and applicants uncertain about the protective steps they need to take.
The known target was the jobs portal. That is not proof that the attackers reached FBI investigative systems. The exposed personnel information is still unusually useful for targeting people, their families and the people they work with.
Who ShinyHunters is
ShinyHunters is a changing cybercriminal brand or cluster, not a stable organization with fixed membership. The name has been associated with high-volume data theft, leak sites and extortion since at least 2020. Google tracks the cluster involved in the PeopleSoft campaigns as UNC6240 and describes it as financially motivated.[6]
The FBI’s May advisory says the group specializes in large-scale breaches and extortion and may use real or exaggerated access claims to pressure victims. The advisory warns of threatening communications, harassment and, in some cases, swatting, meaning false emergency calls meant to send armed police to a victim’s home. It advises victims not to pay or engage, to preserve evidence and to report activity to IC3 or an FBI field office.[1]
On September 29, the FBI and Dutch National Police announced the arrest of a 24-year-old Amsterdam man whom the FBI described as one of the group’s alleged leaders. Dutch police said he was arrested on September 15 on suspicion of participating in a criminal organization. That places him in custody about a week before the FBI breach was announced, and the FBI has not tied the arrest to that breach. Dutch police also said the arrest was not part of their investigation into the breach of the Dutch telecom company Odido. ShinyHunters has denied any connection to the man. The group’s return on October 1 with new claims against O’Reilly Automotive and Dexcom indicates it is still operating. Neither claim came with sample data, and neither company had responded publicly when Cybernews reported them.[9][22][23][24][26]
Common access paths associated with recent campaigns
| Method | How it works | Defensive implication |
|---|---|---|
| Help-desk or phone phishing | Attackers impersonate support personnel and direct users to fake sign-in pages or persuade them to reset access. | Require identity verification and confirmation through a separate channel for support requests. |
| Malicious connected apps | A user is persuaded to authorize an application that can export cloud data. | Restrict app approvals and monitor unusual data exports from cloud services. |
| Public-site misconfiguration | Anonymous or weakly protected interfaces expose customer or operational data. | Continuously test internet-facing services and minimize anonymous access. |
| Software exploitation | Attackers exploit a vulnerable public component before any login takes place. | Patch promptly. Multifactor authentication does not stop an attack that bypasses the login step. |
The PeopleSoft campaign
Oracle’s June security alert identifies CVE-2026-35273 in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62. PeopleTools is the underlying platform that PeopleSoft applications run on. Oracle rated the flaw 9.8 out of 10 on the standard severity scale and said an attacker with network access, and no login, could compromise PeopleTools. Oracle advised customers to apply the update without delay and warned that blocking network traffic is not a long-term substitute for correcting the flaw. The flaw is also listed in the federal Cybersecurity and Infrastructure Security Agency’s catalog of vulnerabilities known to be exploited in real attacks.[3][4][5]
Mandiant reported that UNC6240 exploited the flaw between May 27 and June 9, before any fix existed, primarily against higher-education institutions. In September, Mandiant found a renewed campaign in which the group disguised one character in the web address of the vulnerable component, known as PSEMHUB, to slip past firewall rules written to block that exact address. The campaign planted web shells, which are hidden programs that give an attacker continued access, on dozens of systems across higher education, technology, IT services, health care, agriculture, transportation and government.[6]
This campaign makes the attackers’ PeopleSoft account plausible. It does not prove that CVE-2026-35273 was the FBI entry point. ShinyHunters has described the FBI exploit as a new flaw, while Mandiant’s September evidence concerns an adapted attack on the flaw already fixed in June. Until the FBI or a forensic investigator publishes technical findings, both possibilities remain unproven.
Immediate checks for PeopleSoft operators
- Determine whether any environment runs affected PeopleTools versions or contains the PSEMHUB application, including test, training, disaster-recovery and forgotten internet-facing instances.
- Apply Oracle’s CVE-2026-35273 update. Do not treat a firewall rule or path block as a replacement for patching.
- Disable the Environment Management Hub in multi-server configurations, or remove PSEMHUB in single-server configurations, when it is not required and Oracle guidance permits it.
- Search WebLogic and PIA logs for
/PSEMHUB/, encoded variants such as/%50SEMHUB/, external POST requests to/hub, and unexpected JSP or JSPX files. - Inspect
PSEMHUB.warandPORTAL.warfor web shells, preserve evidence and rotate credentials accessible from the PeopleSoft tier if compromise is found.[6]
Risk to San Joaquin County
County government
San Joaquin County’s Information Systems Division publicly identified an upgrade of its PeopleSoft Human Capital Management system, the county’s human resources software, and its underlying infrastructure as a budget objective. County benefits materials have also directed employees to PeopleSoft Employee Self-Service. Historical Oracle and vendor materials describe PeopleSoft-based finance, payroll and human-resources functions and remote employee access controls.[14]
Those records establish that the county uses the product. They do not establish that it is vulnerable today. Public materials reviewed for this report do not show the county’s current PeopleTools version, whether PSEMHUB exists or is exposed, whether the June patch was installed, or whether older descriptions of the system remain accurate. The county has also pursued broader work on its business systems, so historical case studies should not be read as a current network diagram.
Local status as of October 2
No publicly disclosed San Joaquin County compromise through CVE-2026-35273 was identified. The absence of a public report is not evidence that every local system is patched or unaffected.
Cities and local agencies
The county’s local governments have prior experience with disruptive cyber incidents. Lodi suffered ransomware attacks in 2018 and 2019 that affected phones, financial services, the city’s core business software and computer-aided dispatch. The city refused a demand of 75 bitcoins, rebuilt its systems and later strengthened backup and recovery capabilities. A vendor case study says dispatch restoration took four days and a failed backup process caused the loss of one week of business-system data. Because that account is marketing material, it is best read alongside independent reporting and the Civil Grand Jury record.[15][19][20][21]
The 2021–22 San Joaquin County Civil Grand Jury found that Lodi met eight of nine cybersecurity expectations and operated a strong awareness program with monthly training and quarterly phishing exercises. The one item not met was a completed, current business-continuity plan. The report also found the county itself met eight expectations but lacked a documented ransomware policy at that time. These are 2022 findings, not current assessments. Agencies may have completed or revised plans since then.[15]
Local cyber incidents and preparedness findings
| Incident or review | Documented finding | Why it matters now |
|---|---|---|
| City of Lodi, 2018–19 | Ransomware disrupted phones, finance, business software and computer-aided dispatch; the city did not pay. | Shows the importance of tested backups, backup monitoring and restoration priorities. |
| Civil Grand Jury, 2022 | Lodi lacked a completed business-continuity plan; the county lacked a documented ransomware policy. | A useful baseline. Current plan status is not in the public record reviewed here. |
| Delta College, May 2026 | Canvas access was disrupted during the national learning-management-system incident near the end of the term. | Shows how one vendor incident can affect local education without compromising a college-managed server. |
| Superior Court, October 2024 | An intruder accessed systems and copied files containing identity, financial and health information; the court disclosed the result in 2025. | Shows the local consequences when sensitive data is concentrated in one place, and how long forensic review can take. |
Source: San Joaquin County Civil Grand Jury, Superior Court, U.S. Department of Education, ABC10, WBUR, Stateline and Rubrik.[15][16][17][18][19][20][21]
Schools and colleges
Schools and colleges are particularly exposed because their learning, identity and administrative systems are closely connected. The U.S. Department of Education reported that the 2026 Canvas incident involved unauthorized access to usernames, email addresses, courses, enrollment information and messages, while Instructure, the company that makes Canvas, said it had no evidence that passwords, birth dates, government identifiers or financial data were exposed. Delta College was among the institutions that experienced disruption.[17][18]
Health care and businesses
Mandiant identified health care, agriculture and transportation among the sectors in the renewed PeopleSoft campaign. All three are important locally. The technical risk depends on a combination of conditions: an affected PeopleTools component, a system reachable from the internet, incomplete patching, and access from the PeopleSoft servers to HR, payroll, student, patient or financial records. Smaller organizations can also be affected through payroll providers, software platforms and other vendors even if they are never targeted by name.[6]
Residents
- Anyone who applied for an FBI job through the affected portal should follow formal FBI instructions, treat unexpected contacts as suspicious and consider freezing credit with all three nationwide credit bureaus.
- People whose court information may have been involved in the 2024 incident should use the court’s official incident page and identity-protection process.[16]
- Customers of O’Reilly Auto Parts and users of Dexcom glucose monitors should watch for official notices from those companies. As of October 1 the breach claims against both were unverified.[26]
- Accurate personal details in a call, text or email do not prove the sender is legitimate. Verify through a known telephone number or official website.
- Use unique passwords and phishing-resistant multifactor authentication where available. Keep in mind that a user’s own login protections do not repair a vulnerable public server.
Actions for local organizations
Within 24 hours
- Inventory every PeopleSoft and PeopleTools instance, including nonproduction and disaster-recovery systems, and record owner, version, internet exposure and patch state.
- Confirm the Oracle June security update is installed and review whether the Environment Management Hub (PSEMHUB) is required.
- Begin targeted log and file-system searches using Mandiant’s published indicators and preserve relevant logs before retention windows expire.
- Notify executive leadership, legal counsel, privacy staff, the cyber insurer and incident-response partners if suspicious activity is found.
Within 30 days
- Map what data each public-facing system can reach and remove unnecessary connections to HR, payroll, medical, financial and law-enforcement records.
- Set alerts for bulk database queries, unusual service-account use and large outbound transfers from administrative systems.
- Require independent verification for help-desk password resets, changes to multifactor authentication, new connected apps and requests made by telephone.
- Review vendor contracts for patch ownership, log access, incident-notification deadlines, evidence preservation and subcontractor responsibilities.
- Verify backups through restoration tests, monitor backup failures and maintain protected recovery copies that production administrators cannot alter.
Questions for governing boards
- What deadline applies when an actively exploited flaw affects an internet-facing government system?
- Who may approve a workaround in place of a vendor patch, and how quickly must that exception expire?
- Which official owns the risk when a department, software vendor, cloud provider and implementation contractor share a system?
- How long are records on unsuccessful applicants, former employees, patients, students and vendors retained, and who approves deletion?
- When were continuity, disaster-recovery and ransomware plans last exercised, as opposed to last updated on paper?
What remains unknown
The FBI investigation and incident response remain active. The points below may change as forensic results, notices to affected people and reports to Congress become public.
- The FBI’s confirmed initial-access method and whether a third-party provider was the entry point.
- Whether CVE-2026-35273, a different PeopleSoft flaw or another weakness was used against FBIJobs.gov.
- The final number of affected employees, former employees and applicants, and the validated volume of data taken.
- The exact systems from which the sampled medical, psychiatric, assignment and family records originated.
- Whether all affected people and Congress have received every legally required notification.
- Why the ShinyHunters site went offline on September 30. The group attributes it to its own upgrades and attacks by rivals; that has not been independently confirmed.
- Whether the group will keep its stated commitment not to publish or sell the FBI data.
- What role, if any, the man arrested in the Netherlands had in the PeopleSoft campaign, and whether further arrests will follow.
- Whether the claims against O’Reilly Automotive and Dexcom are accurate.
- The current PeopleTools versions, exposure and patch status of San Joaquin County and other local PeopleSoft users.
LodiEye is the original civic-reporting and analysis arm of Lodi411.com, a citizen-run civic data and transparency platform serving Lodi, California and San Joaquin County. LodiEye gathers information of public interest, applies editorial judgment to public records, meetings, and data, and publishes original explanatory reporting for its readers — the work of a newsroom, and a representative of the news media as that term is defined under federal law. Our reporting emphasizes primary sources, public data, and full source transparency so readers can check every claim. LodiEye complements, and does not replace, the other outlets covering this region; for additional reporting on Lodi, San Joaquin County, and the broader region, we also encourage readers to consult the Lodi News-Sentinel, Stocktonia, The Sacramento Bee, CalMatters, and other established news organizations. Our full editorial standards and news-media-status statement is published at lodi411.com/editorial-standards.
This LodiEye report was produced using artificial intelligence tools under the direction and review of the founder. Lodi411 uses multiple AI platforms in its research and publication workflow, including Anthropic’s Claude (primarily Opus and Sonnet models) and Perplexity AI across a variety of large language models offered by each. These tools were used in the following capacities:
Source Discovery: AI-assisted search and retrieval identified the public record behind the incident: the FBI/IC3 advisory of May 15, Oracle’s security alert and June patch update, Google Cloud/Mandiant research on the PeopleSoft campaign, reporting by the Associated Press, CBS News, NBC News, TechCrunch, NPR, Reuters and the security trade press, and local records including the county Information Systems Division budget, the 2021–22 Civil Grand Jury cybersecurity report and the Superior Court’s incident notice.
Credibility Validation: Each claim was sorted by who made it and what supports it. Statements by ShinyHunters are treated as allegations unless corroborated by the FBI, a primary technical advisory or independent examination of the data. The Rubrik account of Lodi’s ransomware recovery is identified as a vendor case study and read alongside independent reporting and the Grand Jury record.
Analysis and Synthesis: AI tools helped connect the national incident and the PeopleSoft campaign to documented local use of the same software, and to earlier local incidents, without drawing conclusions about local systems that the public record does not support.
Presentation: AI tools assisted with drafting, the evidence and incident tables, the timeline and the HTML layout of this page.
Final Review: The founder reviewed the report for accuracy, tone and local relevance before publication.
Lodi411 describes its methods so readers can judge the work for themselves. Corrections and clarifications are welcome at editor@lodi411.com.
References
- Primary FBI/IC3 — “Cyber Criminal Group Attacks Learning Management System,” May 15, 2026.
- Primary FBIJobs — Applicant Portal FAQ.
- Primary Oracle — Security Alert risk matrix for CVE-2026-35273.
- Primary Oracle — June 2026 Critical Security Patch Update.
- Primary CISA — Known Exploited Vulnerabilities Catalog.
- Technical research Google Cloud/Mandiant — “ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft,” Sept. 25, 2026.
- News / FBI statement Associated Press/PBS — FBI investigates hackers’ claim, Sept. 22, 2026.
- News CBS News — Group claims theft of FBI personnel and applicant data, Sept. 23, 2026.
- News CBS News — Dutch arrest and FBI incident update, Sept. 29, 2026.
- News / sample review TechCrunch — Initial FBIJobs claim and sample verification, Sept. 22, 2026.
- News / internal notice TechCrunch — FBI internal cyber-incident notification, Sept. 28, 2026.
- News NPR — FBI response and personnel concerns, Sept. 29–30, 2026.
- News Reuters — ShinyHunters site goes offline after deadline, Sept. 30, 2026.
- Primary local San Joaquin County Information Systems Division — Budget objectives, including the PeopleSoft HCM upgrade.
- Primary local San Joaquin County Civil Grand Jury — “Cybersecurity: Local Defense Against a Global Threat,” 2021–22.
- Primary local San Joaquin County Superior Court — Cybersecurity incident notice.
- Primary U.S. Department of Education — Canvas cybersecurity incident alert, updated May 29, 2026.
- Local news ABC10 — Canvas disruption at San Joaquin Delta College, May 6, 2026.
- News WBUR/Here & Now — Lodi ransomware response, Aug. 29, 2019.
- News Stateline — Lodi response, ransom refusal and recovery costs, Feb. 4, 2020.
- Vendor case study Rubrik — City of Lodi recovery case study.
- News CyberScoop — Alleged ShinyHunters leader arrested in the Netherlands, Sept. 2026.
- News BleepingComputer — FBI tells ShinyHunters members to turn themselves in after recent arrest, Sept. 2026.
- News / FBI statement NBC News — FBI sends warning to cybercrime group after Dutch arrest, Sept. 2026.
- News Nextgov/FCW — ShinyHunters says it won’t publish FBI data, Sept. 2026.
- News Cybernews — ShinyHunters claims O’Reilly Automotive and Dexcom breaches, Oct. 1, 2026.
- News Help Net Security — FBI job portals remain offline after ShinyHunters claims breach, Sept. 28, 2026.