Skip to content
ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'

ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'

Theregister • September 25, 2026

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script now

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script

Crooks use fake desktop apps to fool HR staff into giving them remote access 1 hour ago

Crooks use fake desktop apps to fool HR staff into giving them remote access

Bitget blames North Korea for $387.5M crypto wallet raid 2 hours ago

Bitget blames North Korea for $387.5M crypto wallet raid

Which copy of that file is the real one? Dinner, off the record, in Midtown 4 hours ago

Which copy of that file is the real one? Dinner, off the record, in Midtown

Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs 19 hours ago

Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs

ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients , university and K-12 students , and Carnival cruisers , wanted to preserve their reputation and keep their “business” afloat. So it hacked the FBI to make a statement, the group told The Register .

“It’s a game and it’s the world we live in,” a ShinyHunters spokesperson told us. “We are just protecting our business as any other business would do. It’s who does their job better.”

On Friday, the FBI confirmed the breach to The Register , after earlier in the week saying the bureau was investigating ShinyHunters’ claims.

"The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” an FBI spokesperson told The Register . "While the point of breach is still undetermined - whether a third-party or the FBI’s enterprise - we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk."

On Tuesday, the criminals told us that they broke into the bureau via yet another Oracle PeopleSoft zero-day flaw in the FBIJobs.gov portal, which remains down as of Friday. Then, they breached the FBI’s managed servers on AWS GovCloud and swiped thousands of personnel files belonging to current, former, and prospective FBI employees.

“We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” the group claimed in a message posted online and addressed to FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI’s Cyber Division.

Sample files reviewed by journalists and security researchers appear to contain agents’ addresses, phone numbers, email addresses, Social Security numbers, job titles, assigned field office, and emergency information.

'We refuted the misinformation disseminated by the FBI'

According to a spokesperson for ShinyHunters, the FBI hack isn’t the money, and the crew did not demand a multimillion-dollar extortion payment to not leak the agents’ personal details.

“Our breach of the FBI was executed specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report,” a spokesperson told The Register .

The FBI bulletin, published soon after the group breached ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff, said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”

The criminals, it continued, “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

ShinyHunters contends this is all false. By hacking the FBI and releasing its statement the hack, “we demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers,” the spokesperson told us in an interview.

“This was fundamentally a public relations and marketing initiative for our business,” they said.

'Results-driven professionals' or criminals?

ShinyHunters said it believes that “future corporate partners we engage with for payment will review this documentation, reinforcing our reputation as serious, results-driven professionals focused solely on transaction and resolution.”

Most people call these "future corporate partners" victim organizations, breached by the digital thieves, and threatened with data leaks unless they pay an extortion demand.

The FBI intrusion “establishes our credibility, technical superiority and excellence, and capability with future corporate stakeholders, positioning us as a professional and predictable entity focused on concluding negotiations efficiently,” the spokesperson said.

It also puts a huge target on the crew, and we’d bet that the FBI, already gunning to arrest ShinyHunters members, is now doubling down on those efforts.

The spokesperson said they and others in the crew started off as GnosticPlayers before rebranding as ShinyHunters in 2020, and that they have since seen the “majority” of GnosticPlayers members arrested.

This business, however, is a criminal operation. We asked them why they believe people will trust the words of criminals over those of law enforcement.

They said it’s due to ShinyHunters’ “unique and exceptional reputation along with over five years of history in the space…We are in a unique position and due to our vast capabilities and resources, victims are more likely to resolve the situation quickly and cheaper with us instead of going down the full disclosure route.”

Think of the children

We also questioned how they justify doing what they do in this “business” - breaking into IT systems, stealing data, extorting victims - considering the personal toll it takes on people, especially when the stolen files contain sensitive information children as they did in the Canvas intrusion.

ShinyHunters claims that they “don't attack human beings. We attack the corporate structure. The Business. Not human beings. The money comes out of insurance pocket. Not people’s or businesses' own. Full coverage by insurance. No personal harm is being done, only business harm that they recover from within a quarter considering the type of attack.”

Ransomware and other disruptive attacks are “substantially worse and costly,” they said.

“There are times in the work we do sometimes we have to push the corporate to the absolute limit to get them on the table,” they continued, noting that there was an “initial issue” with the Canvas intrusion “that we cannot on, but it highly relates to the misinformation we are combating. It takes a lot of convincing to bring a corporate to the table to negotiate if they think you are not trustworthy and bluffing/exaggerating what you have.”

While we don’t know for sure what this issue was, ShinyHunters switched to school-by-school extortion after compromising Instructure , the company that owns the Canvas online learning platform, in late April and after the initial pay-or-leak deadline passed on May 6.

They injected a ransom message into 330 Canvas school login portals, causing Instructure to take the platform offline for a day - during final exams and Advanced Placement testing for many.

Meanwhile, that PeopleSoft 0day

The ed-tech company ultimately “reached an agreement” with ShinyHunters, which is corporate-speak for they paid the extortion demand. Alliance Risk CEO David Vainer previously told The Register he estimates the figure sits somewhere between $5 million and $30 million.

According to ShinyHunters, the PeopleSoft preauth vulnerability that they exploited in the FBI attack still doesn’t have a patch. Oracle hasn’t responded to The Register ’s questions the zero-day, or any plans for a patch.

Shiny had “no ” whether the gang has abused the PeopleSoft bug to compromise other organizations. But they added: “the zero-day would allow us to access similar HR/Employee personal information for other corporations who are vulnerable.”

They wouldn’t put a dollar amount on how much they earn from extorting businesses, but boasted: “our revenue performance significantly outperforms both our counterparts and legitimate real life businesses. We have reason to believe in a few months or soon an upcoming financial analysis or reports tracking our earnings will reflect substantial revenue growth.”

And they would not when asked if they worried getting arrested and criminally charged for their digital intrusions and extortion attacks. ®

Valen creator drives 'Golden Spike' to connect new languages with Rust

An experiment is afoot to sidestep C as the language of interoperability with Rust

Microsoft cells out, crams multiple values into Excel boxes

Once a single-scalar , spreadsheet cells are being redeveloped to handle many tenants

Huawei Cloud Rolls Out Enterprise AI Products Across the Board, Building an Open Agentic Cloud

PARTNER CONTENT: Huawei Cloud strengthens the silicon bedrock on the cloud

Uncle Sam coughs up $1.9B for grid upgrades as datacenters hit a power wall

Better conductors and improved sensing capabilities expected to unlock at least 23 gigawatts of additional capacity

In the age of AI, teaching networking principles remains more important than learning protocols

Kids can learn why BGP matters in a semester, but that won’t leave them ready to implement it

Fake Google Security Team ad says 'no script reading' in voice phishing - then prints the script

More mockery and memes from the Dark Web Roast

Anthropic decides to support OpenAI's markdown instructions spec

Anthropic decides to support OpenAI's markdown instructions spec

Microsoft agentically ports Copilot runtime to Rust for $120K

Microsoft agentically ports Copilot runtime to Rust for $120K

KPMG tech cuts come with a severance sum some staff call insulting

KPMG tech cuts come with a severance sum some staff call insulting

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

on call Techie fixed Wi-Fi dead zone with a drill

Techie fixed Wi-Fi dead zone with a drill

Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’

Astronomer watches Starlink satellites sinking to build a ‘planetary barometer’

Google's TPUs to catch some rays in orbit week Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit

Google's TPUs to catch some rays in orbit week

Part of Project Suncatcher, the proof of concept aims to see how well lightly modified compute fares in orbit

Meta's new AI fidget is a ... Tamagotchi? We hope Zuck's Muse Charm doesn't die if you neglect it

Meta's new AI fidget is a ... Tamagotchi?

We hope Zuck's Muse Charm doesn't die if you neglect it

CVE flood pushes Ubuntu onto weekly kernel release cycle AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

CVE flood pushes Ubuntu onto weekly kernel release cycle

AI-assisted bug hunting is helping pile up vulnerabilities faster than defenders can patch them, so Canonical is picking up the pace

Google to critical infra orgs: Our AI scanners won't be evil, promise Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech

Google to critical infra orgs: Our AI scanners won't be evil, promise

Gemini 3.8 Flash Cyber and Wiz's Red Agent team up to protect hospitals, public transit, and tech

Shut up and calculate: Jev's new AI primitives for coders Developers test what they can build with TypeSafe's fast, typed decision model

Shut up and calculate: Jev's new AI primitives for coders

Developers test what they can build with TypeSafe's fast, typed decision model

Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Russians are posing as Signal support to launch phishing attacks

PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!

Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack

PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more

Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Black Hat and DEF CON

DEF CON Franklin project enlists hackers to harden critical infrastructure

Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included

Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

EQT buys majority in Swiss cybersecurity biz Acronis

Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified

Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career

Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight

On the plus side, infosec's a good bet for a long, stable career

KDE turns 30 and someone's brought an AI-native desktop proposal Akademy talk imagines Plasma assembling itself around a personal model of each user

KDE turns 30 and someone's brought an AI-native desktop proposal

Akademy talk imagines Plasma assembling itself around a personal model of each user

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line Acquisition gives open source CSS framework 'a stable long-term '

Shopify extends lifeline to Tailwind as vibe coding erodes web dev platform's bottom line

Acquisition gives open source CSS framework 'a stable long-term '

Switzerland tests a FOSS escape route from Microsoft 365 Swiss Army sticks a knife in American cloud apps with its own FOSS push

Switzerland tests a FOSS escape route from Microsoft 365

Swiss Army sticks a knife in American cloud apps with its own FOSS push

Feel peak Windows was 7? You might like Kumander Linux Debian and Xfce – solid, sensible choices – with a pretty skin

Feel peak Windows was 7? You might like Kumander Linux

Debian and Xfce – solid, sensible choices – with a pretty skin

Canonical shuttering some of its legacy chat channels The Ubuntu Pastebin went in June, IRC gets demoted

Canonical shuttering some of its legacy chat channels

The Ubuntu Pastebin went in June, IRC gets demoted

Audacity audio-editing app no longer looks like it's from the early 2000s The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Audacity audio-editing app no longer looks like it's from the early 2000s

The FOSS tool for audio editing has a fresh coat of paint, and new features to boot

Extracted Entities

Attack Types (2)

Campaigns (1)

Companies (1)

Countries (1)

Domains (1)

Tools (1)