Skip to content
ShinyHunters claims FBI breach and data theft

ShinyHunters claims FBI breach and data theft

Computing • September 23, 2026

Cybercrime group ShinyHunters claims to have breached FBI systems, stolen personal data belonging to employees and job applicants, and defaced the bureau's recruitment website – but it is not, for once, seeking a payout.

The group says it obtained between 2TB and 3TB of data covering current and former FBI employees and applicants. It claims the information includes names, addresses, phone numbers, dates of birth and, in some cases, details of spouses and family members.

The FBI says it is investigating the claims.

404 Media says ShinyHunters supplied a sample dataset covering 5,000 alleged FBI employees, at least some of which appeared to be genuine following checks against public records.

The hackers also briefly replaced content on the FBI's jobs website with a message stating that the site had been "seized by ShinyHunters." Computing has been unable to access the site to verify this, although The Register says the site displayed a maintenance notice when it attempted to connect.

Claim centres on Oracle PeopleSoft

ShinyHunters says it gained access through a previously unknown vulnerability in Oracle PeopleSoft, which is widely used for HR and recruitment. The group claims the flaw allowed remote code execution against systems supporting the FBI's recruitment platform before it moved laterally into other environments hosted on AWS GovCloud.

Neither Oracle, AWS nor the FBI have commented on the allegations at the time of going to press. The bureau's response has so far been limited to a statement that it is "aware of claims regarding unauthorised activity affecting FBIjobs.gov and is currently investigating."

If ShinyHunters’ claims are accurate, the data breach raises serious counterintelligence and security concerns. Information government employees and their families can be valuable to organised crime groups, hostile states and anyone seeking to identify, or pressure officials.

Not a typical extortion attempt

As well as the target, the group's stated motive makes the attack unusual.

ShinyHunters has built its reputation on data theft and extortion campaigns targeting large organisations like EY , Rockstar Games and Kodak .

This time, however, the gang says it is not seeking a ransom payment.

"This is NOT financially motivated," a spokesperson told The Register . Instead, the group wants the FBI to amend or retract statements made in a public advisory issued in May.

The advisory followed attacks linked to ShinyHunters . It warned that the group uses harassment techniques, including threatening messages to victims and family members, and may exaggerate the extent of stolen data to increase pressure during extortion attempts.

ShinyHunters says those allegations are false. The group has reportedly demanded that the FBI remove or correct the statements and has framed the attack as retaliation rather than a money-making operation.

Another escalation from a prolific group

Whether ShinyHunters’ actually stole data or not from the FBI is still unconfirmed. While portions of the sample data appear authentic, there is no independent verification of the group's broader claims.

Still, the incident fits a pattern of increasingly bold behaviour. ShinyHunters has repeatedly targeted high-profile organisations and government institutions, seeking publicity as well as financial gain. Earlier this week it claimed responsibility for breaching infrastructure belonging to rival ransomware operation Clop, turning its attention on another criminal group rather than a traditional victim.

Whether or not the group actually stole FBI data or not, it has already accomplished one of its major goals: keeping ShinyHunters in the news.

Extracted Entities

Attack Types (1)

Industries (1)

Platforms (1)

Ransomware Groups (1)