🗂️ CASE FILE — September 30, 2026
Lead story: The FBI is now publicly addressing the ShinyHunters breach of its FBIJobs.gov recruitment portal — a cybersecurity incident the bureau says it will pursue the hackers over. The group claims 2–3 TB of data on nearly all ~38,000 agents and job applicants (names, home addresses, SSNs, duty assignments, even family details), stolen via an Oracle PeopleSoft flaw, and demanded the FBI retract a May 2026 advisory by a Monday deadline. FBIJobs.gov remains offline.
Also covered: Zscaler ThreatLabz 2026 Ransomware Report — data theft up 275%+ year-over-year (896.2 TB), $328M in payments, 62% of attacks hitting manager-level targets and above, Microsoft Teams abused for exfiltration · Bitget details how attackers used a zero-day in third-party security products to steal $387.5M from hot/warm wallets in a ~3-hour window · Citrix NetScaler zero-day (CVE-2026-88772) exploited for 3+ weeks against government, finance, education, and telecom orgs across North America and Europe · Prisoner medical records at two Suffolk County, MA jails hit in an EHR-platform incident at vendor Computer Systems Integrated Inc. · Ransomware claims: LegalWise (South Africa, 350K+ members), Tekko Enterprises (interlock, U.S. defense contracts data), Polikem (emperador, Colombia).
Sources: 6 linked at the end of this brief.
Today's top stories
The ShinyHunters–FBI standoff dominates today's wire: the bureau is now on the record addressing the FBIJobs.gov breach, vowing to pursue the hackers, while the group's one-week deadline for retracting the FBI's May advisory has come and gone with no confirmed mass publication of the stolen data. Alongside it, hard numbers from Zscaler's new ransomware report confirm 2026 as the year extortion went full data-theft-first (+275% exfiltration), and Bitget finally explained how its wallets were drained — a zero-day in third-party security products, the supply-chain attack pattern that keeps working. The NetScaler exploitation saga and a prison-health EHR incident round out a day heavy on infrastructure and health-sector targeting.
FBI confirms cybersecurity incident after ShinyHunters breaches FBIJobs.gov; hackers vow to pursue retraction deadline
The FBI has publicly confirmed it is addressing a massive data breach, with NPR reporting on September 30 that the bureau is vowing to go after the hackers it believes responsible. The breach centers on FBIJobs.gov, the bureau's primary recruitment portal since 2017, which has been offline since it was defaced around September 21–22 — first with a Pokémon mascot and a "This site has been seized by ShinyHunters" banner, then replaced by a maintenance message.
ShinyHunters claims to have exploited a vulnerability in Oracle PeopleSoft — a flaw family tracked as CVE-2026-35273, which the group has been linked to since June — to steal 2–3 terabytes of data described as "very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." The group shared a sample of roughly 5,000 records with journalists including 404 Media and Reuters: names, home addresses, phone numbers, Social Security numbers, duty assignments, job classifications (special agents, intelligence analysts, attorneys, student trainees), and in some cases names of spouses, siblings, and other family members. Reuters partially verified the sample against credit-bureau records — at least 10 matches, including the FBI director — though it could not confirm the data came from FBI systems. ShinyHunters names the affected systems as Criminal Justice (CJ), HR, MedLink, PEGA, PHIRE, and FBIJobs.
The motive is political, not financial: ShinyHunters says it wants the FBI to retract or amend its Private Industry/Public Service Announcement PSA260515 (May 2026), which described the group's harassment, swatting threats, and exaggerated-access extortion tactics and linked its activity to attacks on the Canvas LMS — allegations the group calls disinformation. The deadline reported was one week from the incident (Monday, September 28). One report on September 30 claimed the group says it will not publish the stolen FBI data — "to make a point and dispute the allegations" rather than to extort — though that cannot be independently verified.
Separately, the saga keeps intersecting with the Dutch ShinyHunters arrest: Pepijn van der Stap appeared before the Rotterdam District Court on September 29; the group denies any connection to him, and police have not confirmed membership.
🔍 Investigation notes — defender takeaway (click to expand)
Take the retaliation framing seriously: extortion groups breaching a federal law-enforcement agency over a written advisory is an escalation in adversary posture, not just another breach. Defenders should note: (1) PeopleSoft is everywhere in government, higher education, and large enterprise — if your organization runs it, treat CVE-2026-35273 remediation and PeopleSoft attack-surface review as urgent, not routine; (2) family-member and home-address exposure is a targeting gold mine for foreign actors and a physical-safety risk — former FBI cyber official Cynthia Kaiser flagged both the counterintelligence and short-term safety angles; (3) watch whether the post-deadline posture holds — no confirmed mass leak as of September 30, but groups like this often escalate in stages. The bureau vowing to pursue the hackers publicly adds a manhunt dynamic to a story that was already a counterintelligence event.
Zscaler ThreatLabz 2026 Ransomware Report: data theft up 275%+, 896 TB stolen, $328M paid
Zscaler released its ThreatLabz 2026 Ransomware Report on September 30 with headline numbers that confirm ransomware's pivot to data-theft-first extortion. Key findings:
- Ransomware data theft increased more than 275% year over year, reaching 896.2 terabytes of exfiltrated data — roughly 90 times the Library of Congress's print collection.
- Blockchain transactions associated with ransomware payments reached $328 million; the average ransom payment rose 5.3% YoY to $431,995.
- 62% of attacks targeted manager-level titles and above — employees with privileged roles and business influence.
- Threat actors are increasingly using trusted workplace tools, including Microsoft Teams, to enable data theft and lateral movement.
- GenAI is accelerating operations — from reconnaissance to negotiation, AI-assisted attackers are moving faster at every stage.
🔍 Investigation notes — defender takeaway (click to expand)
The 275% exfiltration jump is the number that reframes every IR plan: destruction is secondary now — data is the weapon, and backup alone no longer limits blast radius. Two shifts to act on: (1) the targeting of privileged-role employees pairs with AI-accelerated social engineering — executive spear-phishing and deepfake-assisted pretexting need their own detection use cases, not just generic phishing controls; (2) trusted-tool abuse (Teams, etc.) defeats perimeter- and network-centric exfiltration monitoring — data-loss controls need to cover collaboration platforms' file-sharing and API paths, where volume anomalies (896 TB doesn't move quietly) should be detectable if you baseline them.
Bitget reveals attackers used zero-day in third-party security products to steal $387.5M
Bitget has disclosed new technical details on its $387.5 million breach (first reported September 25): attackers used a zero-day in third-party security products to compromise the exchange's wallet infrastructure. According to BleepingComputer and SlowMist on-chain analysis, the earliest theft transfer occurred at 02:31 (UTC+8) and the last at 05:23 — a nearly three-hour window spanning the Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base chains, draining ETH, XRP, BNB, AVAX, USDT, USDC, and other tokens from hot and warm wallets.
CEO Gracy Chen said attackers breached a critical backend system within Bitget's wallet infrastructure that was then used to spoof transaction data, triggering the exchange's authorization process to move funds out of the compromised wallets — effectively turning the wallet's own security tooling into the authorization path for the theft. Chen blamed North Korean hackers, citing IP behavior patterns and on-chain analysis — consistent with the DPRK-linked Bybit heist ($1.5B) earlier this year. Bitget has launched a Recovery Bounty Program offering 5% bounties for help recovering or freezing stolen funds. A Bitget spokesperson did not immediately answer BleepingComputer's questions about the specific zero-day flaw and which third-party products were compromised.
🔍 Investigation notes — defender takeaway (click to expand)
Supply-chain zero-days keep winning because security tooling sits on the trust path: compromising the tool that authorizes transactions turns every downstream control into theater. The three-hour window is the operational lesson — on-chain theft at this scale moves in minutes-per-chain; exchanges and custodians need real-time anomaly triggers on authorization paths, not batch reconciliation. Also note the deliberate opacity around which third-party products were hit: everyone in the wallet-tooling ecosystem should be treating this as their incident until the products are named. North Korean attribution, if it holds, keeps the 2026 crypto-heist tally firmly in DPRK hands.
Citrix NetScaler zero-day CVE-2026-88772 exploited for 3+ weeks across government, finance, education, telecom
A report published September 30 describes exploitation of a critical zero-day in Citrix NetScaler — identified as CVE-2026-88772 — allegedly active for more than three weeks before detection. The reported incidents hit organizations across government, financial services, education, telecommunications, and legal services in North America and Europe. Because NetScaler sits at the network perimeter (remote access, application delivery, connectivity), a successful compromise can open paths to internal systems — and the three-week dwell means stolen access may have been laundered into deeper persistence. The report cautions that the full extent, victim count, attacker identities, and techniques have not been independently established.
This extends a September NetScaler saga this brief has been tracking: earlier this week, separate reporting covered active NetScaler exploitation in the wild and the broader defender response.
🔍 Investigation notes — defender takeaway (click to expand)
Three weeks of undetected perimeter exploitation is the pattern of the month — patch windows for edge appliances keep proving too slow. For defenders: (1) hunt, don't just patch — with that dwell time, unpatched-at-the-time instances must be assumed compromised until forensic evidence says otherwise; check for web shells, persistence, and lateral movement; (2) segment and monitor edge-appliance access paths — a compromised NetScaler is a remote-access goldmine, so treat its logs as primary evidence; (3) the cross-sector spread (government, finance, education, telecom) suggests opportunistic scanning rather than targeted selection — internet-facing inventory hygiene is the control that shrinks the exposure surface fastest.
Prisoner medical records exposed in EHR vendor incident at two Suffolk County, MA jails
DataBreaches reports a "cybersecurity incident" involving the electronic health record system for Suffolk County, Massachusetts's two jails. The provider, Computer Systems Integrated Inc. — which runs the EHRs-C platform holding prisoner health data and medical records — confirmed it is aware of and investigating the incident, per reporting by masslive.com's Hadley Barndollar on September 30. Details on scope, the nature of the unauthorized access, and whether data was exfiltrated have not yet been disclosed.
Health-sector and carceral data is among the most sensitive exposure categories: prisoner medical records combine identity data with protected health information, and the affected population has limited ability to self-protect. Watch for a vendor breach-notification filing and the county's disclosure for scale.
Ransomware leak-site claims roundup
Fresh claims from the last 24 hours. None are independently confirmed; treat each as a threat-actor claim, not a confirmed breach:
- LegalWise listed (discovered September 30). South Africa's leading legal-expenses insurance provider (350,000+ members, 1.1M people covered, 400–800 staff) appeared in ransomware.live tracking with an estimated attack date of September 29. The associated gang listing is The Gentlemen — the same group behind the recent Veradigm patient-data claim. If confirmed, this is a large PII exposure set: insurance member data typically includes IDs, addresses, and legal-case details.
- interlock hits Tekko Enterprises, Inc. (Sept 29). The U.S. company is listed with claims of leaked confidential information including utility system drawings/specifications (fuel and HVAC), crane-related materials, employee personal data, security clearances and ID cards, and sensitive bids and financials tied to multiple U.S. defense and infrastructure contracts. The claim cites alleged security negligence and violations of the False Claims Act, DFARS, FISMA, and the Privacy Act.
- emperador claims Polikem (Sept 29). The Colombian chemical-products manufacturer (industrial and automotive applications) is listed with claimed exposure of financial status, inventory records, and other internal data.
🔍 Investigation notes — defender takeaway (click to expand)
Today's claims skew defense-adjacent: Tekko's alleged exposure of security-clearance ID cards and defense contract bids is the one with national-security-adjacent implications — if any of those contracts are in your supply chain, proactively ask for incident status rather than waiting for disclosure. LegalWise is the volume play — 1.1M covered individuals is a South African-scale exposure. As always: claims precede confirmation, some listings are bluffs or recycled access, and none of these are verdicts.
Incident timeline
| Date | Event | Status |
|---|---|---|
| Sept 21–22 | ShinyHunters defaces FBIJobs.gov ("This site has been seized") via suspected Oracle PeopleSoft flaw; data theft begins (2–3 TB claimed) | Confirmed defacement; data-theft claim partially verified via sample |
| Sept 24 | FBI confirms it is investigating ShinyHunters' claims; FBIJobs.gov stays offline | Confirmed |
| Sept 28 | ShinyHunters' one-week deadline for FBI retraction of May advisory passes; no confirmed mass data publication as of Sept 30 | Claim/deadline; outcome unconfirmed |
| Sept 29 | Pepijn van der Stap appears before Rotterdam court in ShinyHunters-investigation arrest; Tekko Enterprises (interlock) and Polikem (emperador) claims published; LegalWise claim estimated dated | Court: confirmed; claims: unconfirmed |
| Sept 30 | FBI publicly addressing the massive breach, vows to pursue hackers (NPR); Zscaler ThreatLabz 2026 Ransomware Report released (896.2 TB, $328M); Bitget details third-party zero-day behind $387.5M theft; NetScaler zero-day CVE-2026-88772 reported exploited 3+ weeks; Suffolk County jails EHR vendor confirms incident | Confirmed / disclosed |
| Oct 2 | N0n data-release deadline for Precision Facades claim (from yesterday's roundup) | Upcoming |
| Oct 5 | DoomMageddon data-release deadline for Chem Process Systems claim (from yesterday's roundup) | Upcoming |
Sources
- FBI investigating massive data breach of the bureau's job portal — NPR (September 30, 2026)
- New Zscaler Report Reveals AI-Assisted Attackers Move to Massive Data Theft — Zscaler/GlobeNewswire
- Bitget hacked via zero-day in third-party security products — BleepingComputer
- Data breach incident targets prisoner medical records at 2 Mass. jails — DataBreaches via Malware News
- Citrix NetScaler Zero-Day Exploited for More Than Three Weeks — Undercode News
- Ransom! Tekko Enterprises, Inc — HendryAdrian (interlock claim)
This sample preserves the article’s original text and publication date, restyled for Amit’s personal website. Older material may describe historical tools or techniques.
Read the original article on Blogger