BoletimSecSeptember 24, 2026🇵🇹Translated from Portuguese

ShinyHunters Claims Breach of FBI Recruitment Portal and Demands Eight-Figure Ransom

The hacker collective ShinyHunters has announced that it successfully breached the FBI's recruitment website and obtained sensitive records covering nearly all agency personnel along with data from external job applicants.

According to statements released by the group, the intrusion reached several internal FBI systems, including criminal justice databases, human resources platforms, and Medlink. No independent confirmation of these claims has been obtained so far.

The FBI issued a limited acknowledgment, stating that it is aware of allegations concerning unauthorized activity on FBIjobs.gov and that an investigation is underway. The agency did not confirm any data exfiltration or the extent of access achieved by the intruders.

Regarding the attack method, a spokesperson for ShinyHunters claimed the group exploited a previously unknown zero-day vulnerability in Oracle PeopleSoft to gain remote code execution. The attackers then defaced the careers portal with a fabricated law-enforcement seizure message before issuing their extortion demand.

The group is seeking an eight-figure ransom payment, which it provocatively described as only a small portion of its own assets, and warned that the deadline is approaching. The operation is presented as direct retaliation for an FBI public notice released in May that highlighted ShinyHunters activities.

Until official confirmation emerges, the true scope of the incident remains uncertain. Security researchers emphasize that extortion-focused groups have a clear incentive to overstate the sensitivity and volume of data they claim to possess.

Related articles

BoletimSecRansomware & Extortion

PAYLOAD Ransomware Seizes Active Directory GPO to Disrupt Entire Windows Domain Without Encryption

Researchers at Kaspersky have documented an attack by the PAYLOAD ransomware that paralyzes an entire Windows domain without encrypting a single file. Instead of encryption, the operators leverage native Windows policy mechanisms to enforce disruption across the environment. The core of the attack is a malicious Group Policy Object named PAYLOAD linked directly to the root of the Active Directory domain. This placement allows the policy to reach virtually every connected device, turning it into a corporate-wide disruption tool. Through the GPO, the group distributes ransom notes from SYSVOL, replaces wallpapers and lock screens with extortion images displaying the message Welcome to Payload, and disables local administrator accounts on affected machines. A second policy object named win Firewall Off disables the Windows firewall across the entire fleet, increasing exposure during the operation. Initial access occurred in April 2026 via a compromised legitimate domain account on a FortiGate SSL VPN, with possible entry vectors including phishing, password spraying, and credential stuffing. The victim is a manufacturing company in the Middle East. The extortion model combines data theft with operational shutdown, delivering effects similar to traditional ransomware but without any decryption key to negotiate.

AntiMalwareRansomware & Extortion

Ransomware Operators Hijack Active Directory via GPO to Lock Companies Without Encryption

Kaspersky researchers have uncovered a new extortion campaign called Payload that targets manufacturing companies by compromising privileged accounts and seizing control of Active Directory. Instead of deploying traditional ransomware encryptors, the attackers created a Group Policy Object named Payload linked to the domain root. This GPO automatically changed desktop wallpapers and lock screens across all systems, displayed ransom demands, and disabled administrative accounts after policy refresh. The group also exfiltrated valuable corporate data before the lockdown and later published it on the dark web to increase pressure on victims. Because the attack relied entirely on legitimate Windows mechanisms such as VPN access and Group Policy, conventional antivirus solutions proved ineffective. Experts recommend monitoring GPO changes, enforcing phishing-resistant MFA on VPN and admin systems, and applying least-privilege principles to limit the impact of credential compromise.

BoletimSecRansomware & Extortion

SETTRA Ransomware Deploys MeshAgent and gdrv.sys BYOVD Against Windows Systems

Huntress analysts have identified two separate incidents involving the newly observed SETTRA ransomware targeting Windows environments. The attacks combined the legitimate MeshAgent remote management tool with a Bring Your Own Vulnerable Driver technique using gdrv.sys to disable security controls. Victims included a consumer services and retail company hit in July and an industrial organization compromised in September. Initial access occurred through VPN connections or previously stolen credentials, after which operators deployed MeshAgent to maintain persistence and execute commands. Before encryption, the group deleted Windows event logs, disabled system recovery features, removed recovery partitions, and overwrote free disk space. Encrypted files received the .locked or .locked_wip extensions, with the ransomware binary named after the victim domain and ransom notes dropped as RESTORE_FILES.txt.

AntiMalwareRansomware & Extortion

Ukrainian Developer of LockerGoga, MegaCortex and Nefilim Ransomware Sentenced to 12 Years and Nine Months

A 52-year-old Ukrainian national has been sentenced by the Zurich District Court to 12 years and nine months in prison for his role as the lead developer of the LockerGoga, MegaCortex and Nefilim ransomware strains. The court determined that the malware he created was deployed against companies across dozens of countries, causing approximately 100 million Swiss francs in damages in the cases examined. Notable victims included train manufacturer Stadler Rail, which suffered the theft of around 500 GB of confidential data and a $6 million ransom demand in 2020, as well as climate equipment supplier Meier Tobler and banking software developer Crealogix. The defendant claimed he was performing ordinary cybersecurity consulting and was unaware of the intended use of his code, but investigators found ransom demand templates alongside the source code, undermining his defense. He has been in custody since October 2021 as part of a wider international investigation into attacks affecting more than 1,800 individuals and organizations in 71 countries. Upon release he will be banned from entering Switzerland for ten years, although the verdict remains subject to appeal.