PŽ
    /
    Zpět na blog
    Security Sunday

    ShinyHunters Hacked the FBI


    ShinyHunters Hacked the FBI

    image

    On Monday night, a banner appeared on the page where you would normally apply for a job at the FBI: “This site has been seized by ShinyHunters.”

    Anyone who has ever seen an FBI seizure banner on a darknet marketplace got the joke.

    A few hours later, journalists at 404 Media, Reuters and Nextgov received a file containing 5,000 names, home addresses, phone numbers and names of family members. According to the hackers, it’s just a sample — they claim to have data on every FBI employee and applicant, up to 3 TB in total.

    They don’t want money for it. They want the FBI to retract a document in which it described them as people who threaten victims’ families.

    What’s confirmed, and what’s just talk? Let’s take a look together.

    Who are ShinyHunters?

    Let’s start with who ShinyHunters are. The group has been active since 2019, and its name is a Pokémon reference: “shiny hunters” are players who hunt for rare, shiny variants of Pokémon. This crew hunts for rare data.

    Their attack vectors are fairly broad: misconfigured cloud environments, OAuth token theft via integrators, supply-chain attacks, zero-day exploits and, above all, social engineering. The group typically relies on vishing — they call an employee, pose as IT support and talk them out of their login credentials.

    They then exfiltrate the data and demand a ransom. If they don’t get paid, they sell or leak the data.

    Interestingly, it’s probably not a single, fixed group. In January this year, Mandiant described it as “multiple threat clusters under one brand.” Journalist Kim Zetter talks about loosely connected cells of the so-called Com, a large international network of cybercriminals.

    If you haven’t heard of this group before, you’ve almost certainly heard of its victims. The list includes AT&T, Ticketmaster, the European Commission and the education platform Canvas.

    And according to the FBI, ShinyHunters also ran BreachForums — the largest marketplace for stolen data — from June 2023 until it was taken down.

    Why this is probably personal

    On May 15, the FBI issued a public warning in response to the attack on Canvas, a platform used by schools across the United States.

    In that warning, the FBI wrote things ShinyHunters really didn’t like: “The group routinely uses harassment, threatening messages and calls to victims and their families, and in some cases swatting, to apply pressure” (paraphrased). Swatting is a false emergency report made so that an armed tactical team shows up at the victim’s home. The FBI adds that the attackers often claim to have compromising photos or videos that don’t actually exist.

    According to CBS News, the FBI actually issued two warnings in May: a FLASH bulletin on May 8 covering the group’s entire ecosystem, and this public announcement a week later. Both give the same advice: don’t pay.

    ShinyHunters deny all of it. They say they don’t harass or swat anyone, and they also reject the claim that this is financially motivated extortion. They even called the “Com” label security-industry propaganda.

    So what did they do? They hacked the FBI to prove they’re not extortionists. And they gave it an ultimatum: fix this within a week, or else… When BleepingComputer journalists asked what “or else” meant, they replied: “No comment.”

    Timeline

    The hackers claim that on Monday, September 21, they gained access to the Oracle PeopleSoft HR and recruiting system running at apply[.]fbijobs[.]gov. A new zero-day vulnerability they discovered reportedly allowed them to execute code remotely on the servers.

    They then defaced the site, and the page where you would normally apply to the FBI displayed the banner: “This site has been seized by ShinyHunters.”

    They further claim that from that server they moved laterally into FBI infrastructure in AWS GovCloud — Amazon’s government cloud — and exfiltrated up to 3 TB of data on current, former and prospective employees.

    What journalists verified

    Reuters compared names, addresses and Social Security numbers from the sample against credit bureau records and previously leaked data. Some of the data matches. However, Reuters couldn’t determine where the data came from — that is, whether it really originated from internal FBI systems.

    Nextgov received a text file listing nearly five thousand FBI employees, including details about spouses and siblings. For some of the names, it confirmed online that they really do work at the FBI as analysts, lawyers, interns and agents. The full dataset, however, has not been verified.

    The FBI stated officially: “We are aware of a group claiming to have compromised the FBIJobs.gov portal and employee data. We are working with the contractors who operate the portal.”

    According to CBS, FBI documents confirm that the bureau’s recruiting division does use both PeopleSoft and AWS GovCloud. So the scenario is technically plausible. So far, the FBI has confirmed an incident on the recruiting portal. Everything else consists of the attackers’ claims, partly supported by the data sample.

    PeopleSoft is not a new target for ShinyHunters

    Oracle PeopleSoft is not a new target for ShinyHunters. Back in June, Mandiant and Google described a campaign in which the group exploited a zero-day tracked as CVE-2026–35273 — a critical vulnerability with a CVSS score of 9.8 in the Environment Management component that allowed unauthenticated remote code execution. Oracle released a fix on June 10, but attacks had been underway since May 27. Google warned more than a hundred organizations at the time, two-thirds of them universities. We don’t know whether the FBI patched its systems.

    What it means

    If the data is genuine, it’s a gold mine for foreign intelligence services: who works where, who they live with, who is applying and for which position. Dan Calderone of Suzu Labs summed it up: “It’s hard to believe that terabytes of FBI personnel data will just sit on a shelf.” He adds that if the zero-day is real, it may be worth more than the data itself.

    ShinyHunters couldn’t have picked a better time for the attack. This month, the FBI released a new cyber strategy focused on disrupting hacker infrastructure.

    If you run PeopleSoft, you should patch it urgently, scan your servers for web shells and backdoors, and rotate all exposed credentials.

    The ultimatum expires in the next few days. The FBI is unlikely to retract its warning — the question is what the hackers will do next.

    One last request: if samples of the data show up online, don’t share them. They contain real people and their families.

    16-Year-Old Researcher Breaks Into Microsoft’s Internal Analytics Service

    A 16-year-old security researcher going by the handle Faav has disclosed an authentication flaw in Titan, Microsoft’s internal analytics platform built on Apache Superset with ClickHouse databases on the back end. Although Titan’s web interface was accessible only to employees via VPN, its API was publicly reachable through an endpoint hosted in Azure. The flaw allowed anyone on the outside to impersonate a service administrator and run arbitrary SQL queries without any Microsoft credentials. The investigation began on August 25, 2026, when Faav’s personal AI tool, Antares, discovered the service along with publicly accessible Swagger documentation. It listed a /v2/Query endpoint that accepted raw SQL queries.

    The root cause is a textbook JWT mistake. Titan checked what the token claimed (tenant, audience, application ID and user) but never verified the cryptographic signature proving who issued it. Faav ultimately sent a token with the algorithm set to none and an empty signature – and Titan accepted it. The last hurdle was the user field: attempts with email-style identities kept failing until Faav realized the back end treated the upn claim as a plain local username. Setting it to admin mapped the request to local user ID 1 with the Admin role, and the first query, SELECT 1, went through. The AI tool handled roughly ten days of groundwork, but the decisive step came from human intuition.

    Critical WordPress Core Vulnerability CVE-2026–87902 Actively Exploited

    On September 22, 2026, WordPress released version 7.1.2, a security-only update that fixes a single serious vulnerability tracked as CVE-2026–87902. It is a path traversal vulnerability that enables Local File Inclusion (LFI). It is rated 9.2 (critical) under CVSS 4.0.

    The bug is in the get_page_template() function, which WordPress uses to select the theme template for rendering a page. A specially crafted request can trick it into loading a local .php file outside the active theme's directories. All versions from 4.7.0 through 7.1.1 are affected – nearly a decade of WordPress releases – and the attacker needs neither an account nor any user interaction.

    The vulnerability was responsibly disclosed by researcher Robert Ressl.

    Cloudflare Containers: Storage Setup Let Customers Read Other Tenants’ Data

    Cloudflare has fixed a vulnerability in Cloudflare Containers that could have led to cross-tenant data exposure. The flaw also affected Cloudflare Sandboxes, which is built on Containers. According to the researchers, Browser Run was affected as well, because it uses the same disk implementation. The vulnerability was reported on September 4, 2026, by Oren Yomtov of Accomplish through Cloudflare’s bug bounty program on HackerOne. Cloudflare says it has fully remediated the issue across its entire infrastructure and found no evidence of exploitation by attackers. According to the company, customers don’t need to take any action.

    © 2026 Patrik Žák. Všechna práva vyhrazena.