AI Weekly Malaysia

Back to items Summaries

FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data

ID
29337
Status
summarized
Published
28 Sep 2026, 10:50 PM
Fetched
28 Sep 2026, 11:42 PM
Provider
TechCrunch
Category
technology
Original URL
https://techcrunch.com/2026/09/28/fbi-reportedly-declares-cyber-security-incident-after-hackers-steal-agents-personal-data/
Source URL
https://techcrunch.com/feed/

Summary

Score
4.5
Created
28 Sep 2026, 11:43 PM
Tags
Audience
developersstartup_founders

What happened

TechCrunch reports the FBI sent staff an internal notification declaring a "cyber security incident" after hackers stole personal data — names, addresses, job titles, and Social Security numbers — from the FBIJobs.gov application portal. The ShinyHunters group claims it exploited a vulnerability in an Oracle PeopleSoft server hosting HR data, and outlets have since confirmed stolen medical records including blood and urine samples and psychiatric reports. The group says it is not seeking a financial ransom but is demanding correction of an earlier claim.

Why it matters

Oracle PeopleSoft is common HR/ERP infrastructure, so the concrete lesson here is that an internet-facing HR portal can leak SSNs plus medical and psychiatric records in one hit. If you run or integrate PeopleSoft (or any HR app holding applicant data), the decision to make now is whether that portal needs to be publicly reachable at all, and whether you even need to retain applicant medical data after rejection. Note the ransom posture: this group reportedly skipped a cash demand, so paying-ransom playbooks and 'we'll just restore from backup' assumptions do not map to this incident.

Discussion angle

If the entry point was a vulnerability in an Oracle PeopleSoft server, what does that imply for teams running PeopleSoft or similar HR suites — and does the absence of a ransom demand change how you'd respond compared to a typical ransomware incident?

Top