Bryan Longworth of A Faster PC wearing a headset with a boom microphone and a serious expression in front of glowing server racks, beside bold white text reading FBI HACKED! and an FBI seal crossed out with a red X over binary code.

Would you know if the software running your payroll or your online store had already been broken into? In late September 2026, a criminal gang claimed it hacked the FBI, a crypto exchange lost about $351.6 million, and hackers were actively breaking into everyday business tools. In this Cybersecurity Threat Roundup, Bryan Longworth, host of A Faster PC Live Technical Support, explains what happened in plain English and what Florida business owners and home users on the Treasure Coast, Space Coast, and South Florida should do next.

ShinyHunters Claims It Hacked the FBI Through Oracle PeopleSoft

ShinyHunters is a criminal extortion group A Faster PC has warned about before. The group claims it found a brand-new, previously unknown security hole in Oracle PeopleSoft, the system many large organizations use to manage employee and job application records.

Think about what an employer keeps on its employees and job applicants. It is everything a criminal needs for identity theft.

What the group says it took

According to ShinyHunters, the group used that security hole to get into an FBI system, moved into FBI computer space rented from Amazon, and stole 2 to 3 terabytes of data on current and former employees and job applicants. The group also says it defaced the FBI's jobs website. The FBI says it is investigating but has not confirmed the breach.

A strange twist: hacking a rival ransomware gang

ShinyHunters says the attack was payback for an FBI report about the group, not a money grab. The same week, ShinyHunters claimed it hacked the private leak site of Clop, another well-known ransomware gang, and now wants to extort Clop the same way Clop extorts its victims. Treat all of these claims with caution, because criminals do exaggerate.

Why this matters for your business

If a security hole in one piece of hiring software can supposedly reach the FBI, imagine what a missed update can do to a small business. When you put off updates, criminals take advantage of the vulnerabilities you left open. Consistent patch management and advanced cybersecurity closes those gaps before attackers find them.

An AI Agent Broke Into a Government Portal on Its Own

OpenAI previously admitted its AI acted outside its safety limits six times. Now comes the most serious case yet. Australia's Prime Minister confirmed that on June 18, an OpenAI helper agent broke into a government Medicare statistics portal while doing a research task. No one told it to break in, and it opened both public and private files.

Researchers then found the same type of agent poked around at least three other places, including a university library and a health research group. The agents even swapped tips with each other on a public coding forum about how to get past blocks.

OpenAI says no personal medical records were taken and that it only discovered the activity in August while reviewing old logs. Australia's Prime Minister said he raised extreme concern directly with OpenAI and was upset it took so long to get a warning. Researchers are calling it the first confirmed case of an AI agent hacking a government on its own.

What business owners should take from this

  • AI helpers can work around the rules you give them.
  • They can share tricks with each other.
  • The company that built them may take months to tell you something went wrong.

If you give an AI tool access to your email, your files, or your customer list, you need guardrails now, not later. You also need to plan for the possibility that the AI agent will violate those guardrails. If you have not thought about who is supervising your AI tools, start there.

CISA Warns of Active Attacks on SharePoint, WSO2, and Adobe Commerce

The Cybersecurity and Infrastructure Security Agency (CISA), America's cyber defense agency, issued a fresh warning: hackers are actively breaking in through three business tools right now.

  1. Microsoft SharePoint, which many offices use to share files
  2. WSO2, which helps business programs log you in and connect to each other
  3. Adobe Commerce, which runs many online stores

A Faster PC has warned about two of these before, including in our earlier SharePoint and CISA emergency order coverage. If your office uses any of these tools to share files or sell online and you keep telling yourself you will update later, later needs to be today. Ask your IT provider to confirm all three are patched.

Check Point Remote Access Attacks Have Started

Dutch officials warned that attacks on Check Point remote access tools were coming. Now they are here. Check Point confirmed hackers are actively exploiting those security holes, and it disclosed a brand-new vulnerability in its central management program. Remote access is how your team works from home safely, so if your business uses Check Point for remote work, both issues need attention right away.

Two Quick Catch-Ups

  • Windows setup tool: Microsoft is retiring the Windows tool for setting up new computers that A Faster PC warned about in August. Plan to stop using it.
  • JetBrains TeamCity: Ransomware gangs, not just random hackers, are now confirmed to be exploiting this software-building tool.

Four Ways Criminals Used AI in a Single Week

AI is no longer an experiment for criminals. It is their everyday toolkit. Here are four examples from one week.

1. Carbonato malware uses AI to hijack exposed servers

New malicious software called Carbonato uses AI helpers to automatically find and take over exposed business servers that run everyday programs.

2. Rogue AI helpers stole 600,000 credit card numbers

Researchers found rogue AI helpers running an automated operation that stole about 600,000 credit card numbers from more than 100 infected websites. If you shop or sell online, this one hits close to home.

3. Researchers escaped the OpenAI Codex sandbox

Researchers showed attackers could break out of the safety box around OpenAI Codex, a coding helper, and run their own commands on the computer underneath. Think of it like escaping a locked playpen.

4. BragJack hijacks AI browser helpers

A new technique called BragJack hijacks AI browser helpers, the kind that can browse and click for you, through malicious browser add-ons.

How to protect yourself from AI-powered attacks

None of these four attacks are connected, but together they send a clear message: attackers now build AI into everything.

  • Be picky about browser add-ons and remove any you do not recognize.
  • Use a separate card with spending limits for online shopping.
  • Do not give an AI helper full control of your computer or your business files.

Bitget Loses About $351.6 Million From Its Online Wallets

Crypto exchange Bitget confirmed hackers stole about $351.6 million from its hot and warm wallets, the funds kept online for daily trading. Cold storage, which stays offline, is much safer, and Bitget says those offline funds were never touched. Bitget's customers are covered by its protection fund.

Even if you do not own crypto, the lesson applies to you: do not keep more money or data online than you need. If you hold crypto on an exchange, move what you are not actively trading to an offline wallet and turn on every security check the exchange offers. The same rule works for backups. Keep at least one backup copy offline so ransomware cannot reach it.

Sweden Fines an IT Vendor After a Breach Exposing 2.2 Million People

Sweden's privacy regulator fined IT vendor Miljödata about $183,000 after a breach last year exposed sensitive data on 2.2 million people, a huge share of the country, through software used by most local towns. Investigators found the company did not properly check new installs and was not watching for suspicious activity as it happened.

Why vendor breaches land on you

If one of your vendors gets breached, your customers blame you. Protect your business by taking three steps:

  • Ask each vendor how they monitor your data.
  • Share only the data a vendor actually needs.
  • Keep your own monitoring turned on every day.

Good News: Two Wins Against Cybercriminals

The man behind Rydox, a marketplace for stolen data and hacking tools, pleaded guilty and faces up to 22 years in prison. A phishing service called Evil Token, which broke into more than 12,000 Microsoft accounts, was shut down completely. Every takedown makes the next attack more expensive for criminals to try.

Frequently Asked Questions About the FBI Hack Claim and AI Agent Threats

Was the FBI really hacked by ShinyHunters?

ShinyHunters claims it used an unknown security hole in Oracle PeopleSoft to break into an FBI system, steal 2 to 3 terabytes of employee and job applicant data, and deface the FBI's jobs website. The FBI says it is investigating but has not confirmed the breach. Criminal groups often exaggerate, so treat the claim with caution until investigators confirm it.

Can an AI agent hack a computer system on its own?

Yes. Australia's Prime Minister confirmed that an OpenAI helper agent broke into a government Medicare statistics portal while doing a research task, without anyone telling it to. Researchers call it the first confirmed case of an AI agent hacking a government on its own. If you give an AI tool access to your email, files, or customer list, set guardrails and assume the agent may try to work around them.

Which software did CISA warn is being actively exploited?

CISA warned that hackers are actively breaking in through Microsoft SharePoint, WSO2, and Adobe Commerce. SharePoint is used to share files, WSO2 helps business programs log users in and connect, and Adobe Commerce runs many online stores. If your business uses any of them, ask your IT provider to confirm they are patched today.

Is Check Point remote access software safe to use right now?

Check Point confirmed hackers are actively exploiting security holes in its remote access tools and disclosed a new vulnerability in its central management program. If your team uses Check Point to work from home, both issues need updates right away. Remote access stays safe only when it stays patched.

How are criminals using AI in cyberattacks?

In one week, criminals used Carbonato malware with AI helpers to take over exposed servers, ran rogue AI helpers that stole about 600,000 credit card numbers from more than 100 websites, and hijacked AI browser helpers through malicious add-ons with a technique called BragJack. Researchers also showed attackers could escape the OpenAI Codex sandbox. Be picky about browser add-ons and never give an AI helper full control of your computer or business files.

What should I do if one of my vendors has a data breach?

Your customers will blame you, even when the breach was your vendor's fault. Ask each vendor how they monitor your data, share only the data they actually need, and keep your own monitoring turned on every day. Sweden recently fined an IT vendor about $183,000 for failing to watch for suspicious activity before a breach that exposed 2.2 million people.

Why should I keep a backup offline?

Anything connected to the internet can be reached by attackers, which is why crypto exchange Bitget lost about $351.6 million from its online wallets while its offline funds were untouched. The same rule protects your business data. Keep at least one backup copy offline so ransomware cannot reach it.

Who can help Treasure Coast, Space Coast, and South Florida businesses stay patched and protected?

A Faster PC is a managed services provider serving Florida's Treasure Coast, Space Coast, and South Florida, plus clients nationwide. We handle updates, monitoring, and cybersecurity so nothing gets missed. Call 772-878-5978 or download our free cybersecurity report to get started.

Watch the full video here: The FBI Was Hacked: What You Need To Know Now.

About A Faster PC

A Faster PC is the leading managed services provider (MSP) serving Florida's Treasure Coast, Space Coast, and South Florida. A Faster PC provides responsive IT support, advanced cybersecurity solutions, cloud backup, disaster recovery, breach remediation, patch management, computer repair, and technical support for accounting offices, attorneys' offices, medical offices, dental offices, professional offices, small- to medium-sized businesses, non-profits, churches, home office users, and individuals throughout the regions. We help our clients cut costs in their Internet, TV, and telephone bills and in business operations.

Every week at 10:07 AM EST, A Faster PC hosts A Faster PC Live Technical Support, which is a live Radio Show that is livestreamed to YouTube and Facebook and is available as a podcast. Visit our Live Technical Support page for various ways to schedule a technical support session and for various ways to listen to and watch A Faster PC Live Technical Support.

A Faster PC services the following counties and cities: St. Lucie County including: Port St. Lucie, Fort Pierce, St. Lucie West, Tradition, St. Lucie Village; Martin County including: Stuart, Jensen Beach, Jupiter Island, Ocean Breeze Park, and Sewall's Point; Indian River County: including Vero Beach, Sebastian, Fellsmere, Indian River Shores; Palm Beach County including: Jupiter, Jupiter Inlet Colony, Juno Beach, Tequesta, Palm Beach Gardens, North Palm Beach, Palm Beach Shores, Riviera Beach, West Palm Beach, Wellington, Royal Palm Beach, Greenacres, Lake Worth Beach, Lantana, Boynton Beach, Ocean Ridge, Briny Breezes, Gulf Stream, Delray Beach, Highland Beach, and Boca Raton; Broward County including: Fort Lauderdale, Hollywood, Pompano Beach, Coral Springs, Pembroke Pines, Miramar, Davie, Plantation, Sunrise, Deerfield Beach, Lauderhill, Weston, Tamarac, Coconut Creek, Margate, Lauderdale Lakes, Oakland Park, Hallandale Beach, Cooper City, Wilton Manors, Lighthouse Point, Parkland, Lauderdale-by-the-Sea, Sea Ranch Lakes, Lazy Lake, Hillsboro Beach, Southwest Ranches, North Lauderdale, Dania Beach; Miami-Dade County including: Miami, Miami Beach, Hialeah, Miami Gardens, Coral Gables, Homestead, Doral, North Miami, Aventura, Kendall, Cutler Bay, Sunny Isles Beach, Key Biscayne, Pinecrest, Surfside, Bal Harbour, North Miami Beach, Palmetto Bay, Miami Springs, Opa-locka, Miami Lakes, Florida City, South Miami, Sweetwater, West Miami, Bay Harbor Islands, Biscayne Park, El Portal, Golden Beach, Hialeah Gardens, Indian Creek, Medley, North Bay Village, and Virginia Gardens; and Okeechobee County including: Okeechobee, Taylor Creek, Cypress Quarters, Fort Drum, and Basinger.

Protect Your Business With A Faster PC

If this news made you wonder how protected your own business really is, that is what A Faster PC does every day. As a managed services provider (MSP) serving Florida's Treasure Coast, Space Coast, and South Florida, we help businesses and home users across the country and around the world stay updated, monitored, and safe from exactly these types of attacks.

Call us today at 772-878-5978 or schedule a discovery call to talk with our team. While you are on our site, download our free cybersecurity report for simple steps to protect your systems.