Back Cbc.Ca ShinyHunters hackers say they breached FBI, stole employee data
The digital extortion group known as ShinyHunters says it has breached the Federal Bureau of Investigation and claims to have stolen data on thousands of FBI employees.
Later, the FBI said in a statement that the agency "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
ShinyHunters said in a statement posted to its dark-web site and during an online chat with Reuters that it targeted the FBI in response to a May 2026 agency announcement that detailed the group's methods and advised targets not to pay. It said it had stolen data "on almost ALL FBI agents, and individuals who filed an application with the FBI for a job."
It shared what it said was a screenshot of a vandalized FBI job site and what the group said was information on roughly 5,000 agents. It said it was a sample of the overall stolen data set.
Reuters could not verify the authenticity of the screenshot, but a message posted to the FBI job site on Tuesday said that the site and the FBI "Special Agent Applicant Portal" were both "currently unavailable."
Data appeared to contain names and addresses
The data sample appeared to contain information FBI agents' names, addresses, Social Security numbers, their assignments and, in at least some cases, the names of their family members.
Reuters was able to partially verify the authenticity of some of the allegedly stolen FBI personnel information by running the names and postal address details against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs.
A cyberattack hit universities worldwide, including top Canadian schools. Here's what we know
A cyberattack hit universities worldwide, including top Canadian schools. Here's what we know
Telus probes cybersecurity incident that 'ShinyHunters' group claims responsibility for
Telus probes cybersecurity incident that 'ShinyHunters' group claims responsibility for
In at least 10 instances — including in the case of FBI Director Kash Patel — Reuters found details that appeared to match. A person familiar with the matter said that the job descriptions in the data also matched in at least some cases.
However, the news agency could not establish where the data came from, or whether it had been stolen from the FBI's internal systems as the hackers claimed. Attempts to reach the people whose details were in the sample data were unsuccessful.
Cynthia Kaiser, a former FBI official, said breaches like the one claimed by ShinyHunters were "incredibly harmful" because they could be used by criminals to expose and put pressure on the people investigating them.
Kaiser, now senior vice-president at cybersecurity firm Halcyon, noted that an old leak dating back to 2016 is still occasionally used today to harass FBI agents.
"Once that information is stolen, it is used forever," she said.
Same group was behind Canvas hack
ShinyHunters is one of the world's most notorious and attention-seeking hacking crews.
Its recent break-ins include the purported theft of millions of business records from video game developer Rockstar Games, the maker of Grand Theft Auto , and a May intrusion centered on education tool Canvas that caused widespread disruption across schools around the world, including several Canadian universities. Earlier this month, AI company Anthropic said it had caught ShinyHunters-linked hackers trying to use its tools.
On Sunday, the group told Reuters it had gone to war against another notorious cybercrime group, cl0p, in a rare bout of public score-settling.
With files from CBC News
Chinese hackers disrupted U.S. Justice Department, NASA, Federal Reserve, U.S. says
Canadian investigation launched into data breach that exposed millions of IDs
Communauto says it was hit by data breach initiated by its own employee
Unusual log-in activity prompted investigation into Eastlink breach: CEO
York police arrest 5, dismantle alleged criminal drug network operating through dark web
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
