The FBI is investigating a claimed cyberattack involving its jobs portal after ShinyHunters said it had obtained sensitive data. The bureau said it was working with third-party providers while determining whether the point of compromise was a supplier or the FBI environment.

What is confirmed and what is claimed

The FBI confirmed awareness of the claim and an investigation; the group alleged it obtained extensive employee and applicant data and said it used an Oracle PeopleSoft human-resources vulnerability. The precise initial access path and scope remain unconfirmed, so those claims should be treated as allegations pending the investigation.

Broader lesson

The event highlights the risk concentration around third-party employment and human-resources systems. Organizations should maintain clear ownership for supplier incident response, restrict access to sensitive HR data, and test procedures for taking public-facing portals offline while preserving evidence.

Source: Cybersecurity Dive: FBI jobs portal investigation, including the FBI statement and reporting on the claim.

By Allan