Skip to content
Cyber Extortion Group Claims: 'We Have Compromised the FBI'

Cyber Extortion Group Claims: 'We Have Compromised the FBI'

Govinfosecurity • September 23, 2026

The cyber extortion group ShinyHunters claims to have breached FBI systems and stolen personal data pertaining to employees and job applicants. The group said the hack was in retaliation for the bureau disseminating incorrect information its cybercrime activities and tactics.

See Also: A Darkening Landscape: AI, Friend and Foe of Cyber Resilience

"We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency," reads a "public service announcement" posted to ShinyHunters' data-leak site Tuesday and updated Wednesday.

"The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink and more," the data-leak post reads.

The bureau said in a statement that it's probing the alleged breach. "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," it said.

ShinyHunters told multiple media outlets that the stolen information encompasses personal data pertaining to FBI agents, including their name, address, phone number and details pertaining to their spouse. After being given a sample of 5,000 individuals' allegedly stolen details by the group, 404 Media reported that it appears to be legitimate.

ShinyHunters told news outlets it stole the data after using a zero-day exploit against the FBI's Oracle PeopleSoft software, then pivoting to its Amazon Web Services GovCloud environment and stealing over two terabytes of data.

An individual with knowledge of the breach described it to Politico as being "really bad," not least given the personal and national security safety risks tied to information on agents and their families being in the hands of, or shared with, other criminals or unfriendly nation states.

The prolific cyber extortion group regularly steals large amounts of corporate data, sometimes by tricking victims into giving it direct access to their cloud environments, and then holding it to ransom (see: Wave of ShinyHunters Extortion Drives Surge in Data Leaks ).

In recent months, the group has also held to ransom the Florida Highway Safety and Motor Vehicles agency , 100 universities and colleges that use Oracle PeopleSoft, and Amazon's One Medical primary care division.

Shaking down the FBI may be designed primarily to be a brand-building exercise. "ShinyHunters isn't expecting a ransom from the FBI. It's defending its brand. By publicly taking on the agency, ShinyHunters is trying to rebuild its credibility and push future victims back toward the negotiating table," said threat intelligence firm Flashpoint.

"Since the FBI will likely not engage with ShinyHunters, we expect the group to follow the same playbook it uses against corporate victims and leak the stolen data," it said.

The first public signs that a security incident might be unfolding at the FBI appeared Monday, when its online jobs portal, apply.fbijobs.gov , was defaced with ShinyHunters ASCII art and cyber extortion messaging.

"All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI employees and all applicant information. We have a lot more than what we claim here. Thank you for your attention to this matter," read a message posted to the site.

The FBI quickly took the site offline. The landing page now resolves to a "system unavailable" message.

In the data-leak site message first posted Tuesday, ShinyHunters issued an extortion demand to FBI Director Kash Patel and Brett Leatherman , assistant director of the FBI's Cyber Division.

The group has promised to delete the stolen data if, within one week, the FBI deletes or updates a May 15 security alert it issued ShinyHunters' breach of the Canvas e-learning platform, to correct what the criminals described as factual inaccuracies, including claims that the group directly threatens or harasses victims or family members, sometimes using compromising photos or videos, or engages in swatting.

"This is not a ransom, coercion or extortion," the group's note claims.

Cybersecurity experts and law enforcement agencies have long warned organizations that promises by criminals to delete stolen data rarely get honored, and are impossible to verify.

ShinyHunters said it took umbrage with the FBI stating that its members "often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims."

ShinyHunters said in its extortion note: "We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that."

Whether the group has a genuine beef with the FBI, or if it's trolling - at least in part - the law enforcement agency isn't clear.

Group Dismisses Ties to the Com

Multiple security researchers, as well as the FBI in its May security alert, have lumped ShinyHunters into the broader cybercrime community known as The Com. Experts said it's largely compromised of Western adolescents, and comprises numerous sub-groups that have resulted in such spinoffs as the cybercrime group Scattered Spider as well as the nihilistic violent extremism group called 764, which often preys on children (see: Police Target Violent Online Predators Incubated by the Com ).

The ShinyHunters note to the FBI said it has never had anything to do with The Com, never uses harassment strategies or threatening messages to employees or family members, has never conducting swatting attacks - which refer to tricking emergency services into believing a crime is occurring at a target's residence - and never traffics in embarrassing photos or videos. "We are not sextortionists," the group said in its message.

This isn't the first time ShinyHunters has taken pains to differentiate itself from The Com. "We deny any and all association, affiliation or links to 'The Com,'" the group said in an unsolicited message to ISMG in May, prompted by a news report based in part on the FBI's alert on The Com.

The spokesperson added: "Just because our tactics may overlap or be extremely similar to those who do vishing (e.g. Scattered Spider who is actually associated with 'The Com') doesn't mean we are also directly associated, affiliated or linked to 'The Com,'" which they also likened to being "a culture and ecosystem," rather than the FBI's assessment that it was anything more formal (see: What's in a Name? The Quest to Understand Scattered Spider ).

Targeting a Western law enforcement agency directly stands as a serious escalation by any cybercrime group.

For ShinyHunters, it's not the only bravado and braggadocio displayed in recent days. On Friday, the group defaced the data-leak site for its Russian-speaking rival Clop, aka Cl0p. ShinyHunters claimed to have stolen extensive amounts of code and data from the group, and demanded a large ransom, tied to Clop's theft of data beginning in mid-2025 from a number of large organizations that use Oracle E-Business Suite. In another claim that couldn't be verified, ShinyHunters accused Clop of having stolen its EBS exploits (see: Cyber Extortion War: ShinyHunters Holds Rival Clop to Ransom ).

After posting the FBI on its data-leak site Tuesday, ShinyHunters on Wednesday added the name of another claimed victim: Fresenius Medical Care.

The German healthcare company, which provides kidney dialysis products and services used by 4.5 million patients worldwide, confirmed Tuesday that it's "investigating a cybersecurity incident involving unauthorized access to a limited number of internal systems."

The company said "the incident has not impacted our medical devices, patient care, manufacturing operations or business continuity," and noted that it's working with digital forensic experts and law enforcement agencies to investigate the intrusion.

Fraud Management & Cybercrime

Executive Editor, DataBreachToday & Europe, ISMG

Schwartz is an award-winning journalist with two decades of experience in magazines, newspapers and electronic media. He has covered the information security and privacy sector throughout his career. Before joining Information Security Media Group in 2014, where he now serves as the executive editor, DataBreachToday and for European news coverage, Schwartz was the information security beat reporter for InformationWeek and a frequent contributor to DarkReading, among other publications. He lives in Scotland.