ShinyHunters claims FBI jobs portal hack, data theft

The digital extortion group ShinyHunters says it hacked FBI systems behind the bureau’s online jobs portal, defaced the site and stole personnel data on thousands of agents and applicants.[1][5][6] The group’s dark-web leak site (https://shnyhntww34phqoa6dcgnvps2yu7dlwzmy5lkvejwjdo6z7bmgshzayd.onion/) claims it obtained “very sensitive data on almost ALL FBI agents and individuals who filed an application with the FBI for a job,” a description echoed in multiple media reports.[2][3][10] The FBI has said it is aware of “claims regarding unauthorized activity affecting FBIjobs.gov” and is investigating, but has not confirmed the alleged intrusion or scale of any data theft.[2][3][14]

In a lengthy manifesto posted to its leak site, ShinyHunters frames the incident as a retaliatory strike against the FBI for what it calls defamatory allegations in a recent cybercrime notice about the group’s tactics.[4][13] The statement, addressed to senior FBI cyber officials, demands that the bureau retract or remove the warning within a week and insists the group’s threats are “very real,” not exaggerated attempts to coerce victims.[4][15] ShinyHunters also denies carrying out swatting attacks, harassing victims’ families or engaging in sextortion, while simultaneously warning that journalists who repeat the FBI’s characterisation of the gang may face “forceful” responses intended to defend its reputation.[4][13]

ShinyHunters claims the breach began with exploitation of a previously unknown vulnerability in Oracle PeopleSoft running on the FBI’s recruitment infrastructure, allegedly allowing remote code execution and access to internal services.[5][6][15] From there, the group says it moved laterally into FBI systems hosted on AWS GovCloud and siphoned between 2 and 3 terabytes of data, including records tied to Criminal Justice, human resources and medical systems.[6][11][15] These technical details, along with the scope of the claimed data theft, have not been corroborated by the FBI, Oracle or AWS, and some analysts caution that the narrative should be treated as an unverified threat-actor account.[11]

To bolster its claims, ShinyHunters reportedly shared a sample dataset with journalists containing records on roughly 5,000 FBI agents, including names, home addresses, phone numbers and information about spouses.[8][10][14] Outlets such as 404 Media are said to have verified portions of the sample, but neither the full dataset nor the assertion that it covers “almost all” agents and applicants has been independently confirmed.[7][11][14] The group also took credit for defacing the bureau’s jobs portal with a “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS” banner, a nod to law-enforcement takedown notices, before the site was pulled offline.[5][7][12]

The manifesto centres on a May 2026 FBI public notice about ShinyHunters’ attacks on learning management systems, which warned that the gang used harassment, threatening calls and exaggerated claims about possessing sensitive or compromising material to pressure victims into paying.[4][10][13] ShinyHunters disputes that characterisation, insisting it is not part of any broader criminal network and portraying the notice as “disinformation” inspired by biased security researchers and reporters.[4][15] That framing allows the group to cast its alleged FBI breach as a form of reputational “correction” rather than financially motivated extortion, even as the incident exposes current and prospective government employees to heightened risks of targeted scams, stalking and physical-security concerns.[3][9][10]

Until the FBI clarifies what, if anything, was accessed, current and former bureau employees, applicants and their families should assume their personal information could be exposed and watch FBI.gov for official updates and tailored advice.[2][3][14] Anyone who held an account on the FBI jobs portal should change reused passwords elsewhere, enable strong two-factor authentication where possible and be alert to phishing, impersonation attempts and social-engineering calls that exploit the uncertainty around the incident.[6][9][11] Given the sensitivity of the claimed data, identity-monitoring services and proactive credit-file safeguards may help detect misuse early, but they cannot compensate for the long-term operational and personal-safety implications if ShinyHunters’ account of the breach proves accurate.[1][10][11]

References

  1. Hacking group ShinyHunters claims it breached the FBI, stole …
  2. ShinyHunters hackers say they breached FBI, stole employee data
  3. ShinyHunters hackers say they breached FBI, stole data on bureau employees
  4. ShinyHunters claims FBI data theft, demands bureau …
  5. ShinyHunters Hacks FBI Jobs Portal, Claims Data on Nearly All FBI …
  6. ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day …
  7. High profile hacking group claims it hacked the FBI and stole data …
  8. ‘We Hacked the FBI’: ShinyHunters Hands Over 5,000 Employee …
  9. ShinyHunters hacking group claims FBI breach
  10. FBI investigating claims that a major cybercrime group stole sensitive personnel data
  11. ShinyHunters FBI Hack Claim Remains Unverified
  12. FBI Security Breach: Hackers ‘Steal Data’ on Every One of Kash Patel’s Agents
  13. ShinyHunters claims FBI breach and data theft — CBC World
  14. FBI Investigates Claimed Hack of Jobs Site Affecting Agents … – Yahoo
  15. ShinyHunters claims FBI hack: ‘This is NOT financially motivated’

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply