What happened
The FBI's online portals for job applicants and special agent applicants remain offline after what appears to be a successful compromise by the ShinyHunters extortion group. The Bureau confirmed last week that it was investigating the group's claim to have taken personal information belonging to FBI employees.
ShinyHunters told The Register it used an unspecified and unconfirmed Oracle PeopleSoft zero-day to reach the portals, and claims it also breached FBI managed servers on AWS GovCloud, taking personnel files of current, former and aspiring employees. According to the BBC, the group says it reached platforms handling background checks, medical records and investigative information. Reuters matched the career details of eight people to public sources, while noting it could not verify all the job assignments were authentic or current.
The group says it is not after money. It wants the FBI to retract a public service announcement from its IC3 unit advising victims not to pay ransom, and it threatened to release what it holds if the Bureau does not comply.
The more instructive part is the technical account published by Google Cloud and Mandiant. ShinyHunters is exploiting Oracle PeopleSoft vulnerability CVE-2026-35273, the same flaw it used as a zero-day in May and June 2026 against mostly academic institutions. Oracle advised an emergency patch, and where that was not possible, mitigations such as restricting network access to PeopleSoft application and web servers to trusted internal networks. Mandiant warned then that relying solely on web application firewall body inspection rules was insufficient, because those controls can be bypassed.
That warning proved correct. The group modified the original exploit to get past WAF rules blocking the vulnerable Environment Management Hub endpoint, URL-encoding a single character so that a request for /PSEMHUB/ arrived as /%50SEMHUB/. That was enough to reach the endpoint on systems whose operators believed their WAF rules had mitigated it. Mandiant says the campaign also widened targeting to higher education, technology, IT services, healthcare, agriculture, transportation and government. After gaining access the group deploys web shells, a legitimate remote monitoring and management tool called MeshAgent, and fileless command execution.
Why this is a GRC story
A compensating control is not a substitute for a patch. WAF rules bought time, which is what they are for. The failure was treating string matching as a permanent fix rather than a stopgap with an expiry date.
Risk acceptance decisions need a review date. Somewhere, teams decided not to patch and to rely on the edge instead. That was reasonable in the moment and should have been tracked, dated and reopened when the threat actor adapted.
Internet exposed vendor applications are the estate you forget. Recruitment, HR and back office platforms are often owned by a business function rather than security, and they hold personal data. That combination is what got compromised here.
What to watch
Watch whether the FBI confirms the categories of data involved, because that determines who must be notified and under which regime. Also watch whether the group publishes anything if the deadline passes. Claims of this size are sometimes inflated.
Practical work for this week: pull the list of internet facing PeopleSoft and similar enterprise applications, confirm which are actually patched, and ask which rely on a rule that matches a string rather than a fix.
Attribution: Analysis based on Help Net Security's reporting and related public reporting. This article is original commentary, not a repost of the source material.
