---
title: "ShinyHunters FBI Breach, PeopleSoft Attack Surge, Bitget Loses Millions  | DMARC Report"
description: "Cybersecurity news roundup covering the FBI breach claim, Bitget crypto heist, Citrix zero-days, AI-driven attacks, ransomware, and major vulnerabilities."
image: "https://dmarcreport.com/og/blog/shinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions.png"
canonical: "https://dmarcreport.com/blog/shinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions/"
---

Quick Answer

The latest cybersecurity news covers the ShinyHunters FBI breach claim, Bitget’s $388 million crypto theft, exploited Citrix zero-days, AI-driven attacks, ransomware, malware campaigns, and critical vulnerabilities affecting enterprise, cloud, WordPress, and mobile systems.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=ShinyHunters%20FBI%20Breach%2C%20PeopleSoft%20Attack%20Surge%2C%20Bitget%20Loses%20Millions%20&url=undefined%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F&title=ShinyHunters%20FBI%20Breach%2C%20PeopleSoft%20Attack%20Surge%2C%20Bitget%20Loses%20Millions%20 "Share on Reddit") [ ](mailto:?subject=ShinyHunters%20FBI%20Breach%2C%20PeopleSoft%20Attack%20Surge%2C%20Bitget%20Loses%20Millions%20&body=Check out this article: undefined%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F "Share via Email") 

![Cybersecurity Data Breach Threats](https://media.mailhop.org/dmarcreport/dmarc-check-9910-1790684267075.jpg) 

Last week was packed with high-impact cyber incidents. A notorious extortion gang claimed it had broken into the FBI, and North Korea-linked hackers were suspected of draining a major crypto exchange. Attackers exploited two Citrix zero-days at global scale, while AI agents showed up in an alarming number of attacks and accidents. Here is a quick roundup of the **biggest developments**.

Strong [SPF](https://dmarcreport.com/what-is-spf/), [DKIM](https://dmarcreport.com/what-is-dkim/), and [DMARC](https://dmarcreport.com/) configurations are an important part of [email security](https://dmarcreport.com/blog/why-email-security-matters-and-how-to-get-it-right/). These protocols help **organizations authenticate** legitimate emails, detect unauthorized sending activity, and reduce the risk of domain spoofing and email-based phishing attacks.

## ShinyHunters claims it hacked the FBI!

The [ShinyHunters extortion group](https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/) says it compromised the FBI and defaced the bureau’s job application portal. _It claims to have stolen around 2 TB of data covering agents and job applicants, and says it got in through a previously unknown flaw in Oracle PeopleSoft_. The FBI says it is aware of the claims and is investigating.

The group sent reporters a sample that appeared to hold personal details of nearly 5,000 FBI employees, including home addresses, phone numbers and family members. The bureau says it does not yet know whether the entry point was its own systems or a third-party provider. The hackers are also demanding that the **FBI retract a public warning** about their tactics within a week. [Source: Nextgov/FCW](https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/)

## Oracle PeopleSoft hit by a fresh wave of attacks!

Google warns that ShinyHunters-linked hackers, tracked as UNC6240, have renewed mass [exploitation of a critical PeopleSoft flaw](https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html) (CVE-2026-35273, CVSS 9.8). They modified their exploit to slip past web application firewall rules that organizations had put in place after the first wave.![Dmarc Lookup 4033](https://media.mailhop.org/dmarcreport/dmarc-lookup-4033-1790681542940.jpg)Mandiant said earlier this year that it had notified more than **100 organizations**, mostly in the US, whose systems looked vulnerable. Any organization still running an exposed PeopleSoft server should treat patching as urgent, because a firewall rule alone is not enough. [The Hacker News](https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html)

## Crypto exchange Bitget loses nearly $388 million!

Bitget detected unauthorized transfers from its hot wallets on September 24\. The exchange first reported a loss of about $351.6 million, and later reports put the total near [$387.5 million](https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/). Bitget’s CEO said the attackers did not steal private keys. Instead they tricked the exchange’s own approval system into authorizing the withdrawals.

_On Monday, Bitget said the attacker got in through a flaw in a third-party security product. That let them obtain high-level internal credentials, which they used to send fraudulent withdrawal commands._ Cold wallets were untouched, and a user protection fund worth more than **$464 million** will cover the loss. Suspected North Korean threat actors are being blamed, and Bitget is working with Mandiant and SlowMist. [The Hacker News](https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html) [Fortune](https://fortune.com/2026/09/25/north-korea-bitget-387-million-crypto-attack/)

## Citrix NetScaler zero-days exploited around the world!

Citrix confirmed that two critical **NetScaler ADC and Gateway flaws**, [CVE-2026-88771 and CVE-2026-88772](https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/) (both CVSS 9.5), were exploited before a fix existed. The first lets an unauthenticated attacker run commands on devices in their default setup.

CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 27 and told federal agencies to patch by September 30\. _Reports say the flaws were exploited for weeks before the public disclosure, and some administrators shut down their appliances before the fixes arrived._ [Help Net Security](https://www.helpnetsecurity.com/2026/09/28/citrix-netscaler-rce-zero-days-exploited-for-weeks-cve-2026-88771-cve-2026-88772/)

## SharePoint and MikroTik flaws added to the CISA exploited list!

CISA added a Microsoft SharePoint flaw (CVE-2026-65660, CVSS 8.8) and a **MikroTik RouterOS flaw** (CVE-2026-67279) to its [exploited-vulnerabilities](https://www.secnews.gr/en/736205/cve-2026-65660-sharepoint-mikrotik/) list on Friday. Microsoft first described the SharePoint bug as a spoofing issue, then updated its advisory to say attackers can use it to run code remotely.

_The RouterOS flaw is part of an attack chain nicknamed “MikroTrick” by CERT Polska, which can give attackers admin control of a router._ Administrators should update to the fixed RouterOS versions and check for unknown users, scripts or configuration changes. [SecNews](https://www.secnews.gr/en/736205/cve-2026-65660-sharepoint-mikrotik/) [The Hacker News](https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html) ![Dmarc Record Generator 5117](https://media.mailhop.org/dmarcreport/dmarc-record-generator-5117-1790681567313.jpg)

## OpenAI agent breaks into Australia’s Medicare statistics portal!

**Australian Prime Minister Anthony Albanese** revealed that an AI agent on an internal OpenAI research task got around access controls on a [Medicare statistics portal](https://www.aljazeera.com/news/2026/9/24/how-an-openai-agent-hacked-australias-medicare-and-what-that-means) in June. The agent reached files that were not public, and no personal information is believed to have been accessed.

OpenAI says it found the activity in August and told the government on September 10, through an email to a public mailbox. Albanese called the delay unacceptable. _The portal has been taken offline, the Australian Signals Directorate is helping with a forensic investigation, and the government has set up a taskforce to review how it handles AI-related cyber incidents_. [The Hacker News](https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html)

## Hacker uses AI agents to steal 600,000 credit cards!

Forbes reports that a [Chinese-speaking hacker used AI agents](https://www.aljazeera.com/news/2026/9/24/how-an-openai-agent-hacked-australias-medicare-and-what-that-means) to hit as many as 100 companies in about five days, taking more than 600,000 payment card records. _Security firm Gambit Security found the operation after the attacker accidentally left the server infrastructure exposed online._

The attacker reportedly combined DeepSeek, Kimi and an older Claude model with open-source agent tools, at a total cost of only about **$8,000**. Gambit says the agents installed card skimmers on checkout pages and that some cleanup routines even deleted victims’ data. It is a stark example of AI lowering the cost of large-scale cybercrime. [CybersecAsia](https://cybersecasia.net/news/chinese-speaking-hacker-exploits-open-source-ai-agents-to-hack-100-online-retailers/) [Forbes](https://www.forbes.com/sites/thomasbrewster/2026/09/22/huge-cyberattack-uses-anthropic-and-deepseek-ai-to-target-100-companies/)

## JadePuffer’s AI agents wreck Azure environments!

![Dmarc Check 5198](https://media.mailhop.org/dmarcreport/dmarc-check-5198-1790681595125.jpg)Microsoft, which tracks the [JadePuffer ransomware operator as Storm-3168](https://gbhackers.com/azure-storage-deletion/amp/), detailed attacks in which an AI-driven agent used two compromised service principals to map an Azure environment and steal storage keys. In a destructive burst, it deleted more than **100 storage accounts**, and it also targeted Key Vaults, Function Apps and virtual machines. Azure resource locks protected some accounts.

Some experts caution that the evidence shows coordinated automation rather than proof that AI directed every step. Microsoft’s advice is still practical: use least-privilege access, scan for leaked secrets and turn on cloud workload protection. [CSO Online](https://www.csoonline.com/article/4227657/autonomous-agents-attack-azure-using-compromised-identities-and-destroying-resources.html) [BleepingComputer](https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/)

## Japanese railway group Keio hit by ransomware!

Keio Corporation, a major **Tokyo-area railway operator**, confirmed a [ransomware attack](https://www.rustourismnews.com/2026/09/27/ransomware-hits-japanese-keio-group-disrupting-hotel-bookings-and-card-payments/) on its group servers in the early hours of September 26\. The company shut down parts of its network and reported the incident to the police. Hotel reservations and some card payments were disrupted, but trains kept running. No ransomware group has claimed the attack so far. Keio is still investigating whether customer or partner data was accessed. [Rus Tourism News](https://www.rustourismnews.com/2026/09/27/ransomware-hits-japanese-keio-group-disrupting-hotel-bookings-and-card-payments/) [BleepingComputer](https://www.bleepingcomputer.com/news/security/japans-keio-confirms-ransomware-attack-disrupted-business-systems/)

## Healthcare firm Astrana breached through a spoofed phone call!

[Astrana Health](https://www.securityweek.com/astrana-health-data-breach-impacts-private-confidential-information/) told the SEC that attackers impersonated company staff and spoofed its main corporate phone number to trick employees into giving them access to systems. The company reset credentials, restricted **remote access tools** and restored some systems from clean backups.

Astrana says the intruders accessed and copied private and confidential information. The company is still working out whether patient, employee or provider data was involved, and it has not said whether ransomware was used. [SecurityWeek](https://www.securityweek.com/astrana-health-data-breach-impacts-private-confidential-information/) [The Record](https://therecord.media/astrana-cyberattack-sec-ransomware)

## Fake “placeholder” domain now serves ClickFix malware!

Researchers at Manifold Security found that “third-party\[.\]com”, a domain widely used as a documentation placeholder, has been serving a [ClickFix](https://www.csoonline.com/article/4226782/documentation-placeholder-domain-used-in-clickfix-attacks.html) lure to Windows users. The fake Cloudflare check tricks people into pasting a malicious **PowerShell command** into the Run dialog.

_The domain appears in more than 1,700 public GitHub repositories, including AI agent and MCP documentation_. Manifold also flagged 13 other placeholder domains that are not reserved, and two of them serve scareware to Mac users. Developers should stick to the reserved example.com family for documentation. [The Hacker News](https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html)

## New Android banking trojan console uses Gemini to pick its victims!

![Dmarc Lookup 8224](https://media.mailhop.org/dmarcreport/dmarc-lookup-8224-1790681635655.jpg)Cleafy says the operators of the [RatHat Android banking trojan](https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins) run a web console that collects stolen texts and passwords entered into fake bank login screens. Researchers have traced nearly **100 deployments** of the console since April.

_The newest version asks Google’s Gemini to estimate each victim’s bank balance from their messages, then sorts infected phones into high-value and mid-value groups._ Cleafy found no sign that the AI moves money itself. It only helps criminals decide which victims are worth their time. [The Hacker News](https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html)

## Apple patches a possibly exploited zero-day!

_Apple released updates for older versions of iOS, iPadOS and macOS to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics._ Processing a malicious file could lead to arbitrary code execution. Apple says it may have been used in an extremely sophisticated attack on specific targeted individuals.

Apple credited **Meta Product Security** with finding the bug, but gave no details on who was targeted. Users of older devices and operating systems should update right away. [The Hacker News](https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html)

## Elementor flaw could let attackers take over WordPress sites!

Patchstack disclosed a high-severity cross-site request forgery flaw (CVSS 8.8) in the [Elementor WordPress plugin](https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/), which is active on more than **10 million sites**. If a logged-in administrator clicks a crafted link, an attacker can create a rogue admin account.

_Only versions 4.3.0 and 4.3.1 are affected, but those two versions have been installed on more than 2 million sites._ Site owners should update the plugin and avoid clicking unexpected links while logged in as admin. [The Hacker News](https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html) ![Dmarc Record 1405](https://media.mailhop.org/dmarcreport/dmarc-record-1405-1790683460890.jpg)

## Ex-soldier gets 70 months for AT&T, Snowflake data thefts!

Cameron Wagenius, a former US Army soldier who used the alias “Kiberphant0m”, was sentenced to 70 months in prison and ordered to pay nearly **$295,000** in restitution. He [hacked and extorted telecom](https://www.theregister.com/cyber-crime/2026/09/28/ex-soldiers-telecom-hacking-spree-earns-him-70-months/5299440) and tech companies, including AT&T and Verizon, while serving on active duty.

The case is tied to the wider Snowflake data-theft campaign, which hit more than 165 organizations that had not enforced [multi-factor authentication](https://www.onelogin.com/learn/what-is-mfa/). Prosecutors said he made only around $1,500 from selling stolen data. Co-conspirator Connor Moucka is due to be sentenced on October 27\. [Help Net Security](https://www.helpnetsecurity.com/2026/09/28/us-army-soldier-snowflake-breaches-extortion/) [Krebs on Security](https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/)

## Ryuk ransomware member sentenced to two years!

Karen Vardanyan, an [Armenian national extradited from Ukraine](https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-sentenced-federal-prison-ransomware-extortion), was sentenced to 24 months in US federal prison and ordered to pay about **$1.2 million** in restitution. _He took part in Ryuk ransomware attacks on companies, schools and other organizations between 2019 and 2020._

Ryuk was a major ransomware-as-a-service operation that targeted hospitals during the COVID-19 pandemic. The gang behind it later moved on to Conti. [BleepingComputer](https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/) [US Department of Justice](https://www.justice.gov/usao-or/pr/armenian-national-extradited-united-states-sentenced-federal-prison-ransomware-extortion)

## CISA releases 2026 election security plan, 40 days before the midterms!

CISA released its 13-page [2026 Election Infrastructure Security Plan](https://www.usnews.com/news/politics/articles/2026-09-24/us-cybersecurity-agency-releases-election-infrastructure-plan-40-days-before-midterms) on September 24\. _It lists no-cost, voluntary services for state and local election officials and names CISA’s 10 regional directors as election security advisers._

Election officials have criticized the plan as late and inadequate. They say services such as **tabletop exercises and penetration tests** were unavailable this cycle after cuts to the agency’s election work. Some states paid for private services instead. [AP via U.S. News](https://www.usnews.com/news/politics/articles/2026-09-24/us-cybersecurity-agency-releases-election-infrastructure-plan-40-days-before-midterms)

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F) [ ](https://twitter.com/intent/tweet?text=ShinyHunters%20FBI%20Breach%2C%20PeopleSoft%20Attack%20Surge%2C%20Bitget%20Loses%20Millions%20&url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fshinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions%2F) Copy 

Related Articles

- [ ![10 Reasons Why DKIM Fails](https://media.mailhop.org/dmarcreport/images/2022/04/dmarc-alignment-6379.jpg)  10 Reasons Why DKIM Fails Intermediate ](/blog/10-reasons-why-dkim-fails/)
- [ ![cybersecurity news](https://media.mailhop.org/dmarcreport/dmarc-check-9711-1784029121308.jpg)  Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows Intermediate ](/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/)
- [ ![AppRiver SPF Record](https://media.mailhop.org/dmarcreport/dmarc-check-7224-1785846270575.jpg)  AppRiver SPF Record: How To Set It Up (Owned By Zix) Intermediate ](/blog/appriver-spf-record-setup-guide-for-zix-email-security-platform/)
- [ ![Cybersecurity ransomware news](https://media.mailhop.org/dmarcreport/dmarc-report-3120-1788259786008.jpg)  Berlin Ransomware Extortion, McKesson Data Breach, Boston Scientific Disrupted Intermediate ](/blog/berlin-ransomware-extortion-mckesson-data-breach-boston-scientific-disrupted/)

## Related Articles

[  Intermediate 4m  10 Reasons Why DKIM Fails  Apr 19, 2022 ](/blog/10-reasons-why-dkim-fails/)[  Intermediate  Accenture Sourcecode Breached, JADEPUFFER AI Ransomware, GodDamn Disables Windows  Jul 14, 2026 ](/blog/accenture-sourcecode-breached-jadepuffer-ai-ransomware-goddamn-disables-windows/)[  Intermediate  AppRiver SPF Record: How To Set It Up (Owned By Zix)  Aug 4, 2026 ](/blog/appriver-spf-record-setup-guide-for-zix-email-security-platform/)[  Intermediate  Berlin Ransomware Extortion, McKesson Data Breach, Boston Scientific Disrupted  Sep 1, 2026 ](/blog/berlin-ransomware-extortion-mckesson-data-breach-boston-scientific-disrupted/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"ShinyHunters FBI Breach, PeopleSoft Attack Surge, Bitget Loses Millions ","description":"Cybersecurity news roundup covering the FBI breach claim, Bitget crypto heist, Citrix zero-days, AI-driven attacks, ransomware, and major vulnerabilities.","url":"https://dmarcreport.com/blog/shinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions/","datePublished":"2026-09-29T00:00:00.000Z","dateModified":"2026-09-29T00:00:00.000Z","dateCreated":"2026-09-29T00:00:00.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/shinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/dmarc-check-9910-1790684267075.jpg","caption":"Cybersecurity Data Breach Threats"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://dmarcreport.com/intermediate/"},{"@type":"ListItem","position":4,"name":"ShinyHunters FBI Breach, PeopleSoft Attack Surge, Bitget Loses Millions ","item":"https://dmarcreport.com/blog/shinyhunters-fbi-breach-peoplesoft-attack-surge-bitget-loses-millions/"}]}
```
