Article Content
- •ShinyHunters claims to have stolen data on nearly all FBI employees and applicants.
- •The group demands the FBI retract a public warning about their activities within a week.
- •The breach could have serious national security implications due to the sensitive nature of the data.
The hacking group ShinyHunters claims to have breached FBI systems, stealing sensitive data on nearly all FBI employees and applicants. They demand the FBI retract a public warning about their activities within a week, asserting that their actions are not financially motivated. The breach reportedly includes personal information such as names, addresses, phone numbers, and details about spouses. ShinyHunters claims to have exploited a zero-day vulnerability in Oracle's PeopleSoft, accessing AWS GovCloud servers to exfiltrate between two and three terabytes of data. The FBI's jobs website has been defaced, displaying a notice from ShinyHunters. The authenticity of the stolen data has been partially verified by independent sources, but the FBI has not confirmed the breach. The situation poses significant national security risks, as the exposed data could be used to intimidate or target FBI personnel.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track DarkSide and FBI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…