Cybercriminal group ShinyHunters, known for large-scale data theft and extortion, claims it breached the FBI and stole data belonging to thousands of employees and applicants.
The hackers made the claim on their dark-web site, saying they had stolen “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.”
‼️ BREAKING: ShinyHunters claims it breached the FBI through an unpatched Oracle PeopleSoft zero-day and stole 2 to 3TB of data on current and former employees and job applicants.
The group says the hack is retaliation for a May FBI alert that profiled it and has given the… pic.twitter.com/o7tZAQ6EmY
— International Cyber Digest (@IntCyberDigest) September 22, 2026
The stolen data reportedly included personal information from about 5,000 employees, including names, home addresses, phone numbers, Social Security numbers, job assignments and, in some cases, family members’ names.
ShinyHunters told 404 Media that it hacked the FBI through an alleged zero-day vulnerability in Oracle PeopleSoft, an enterprise software platform commonly used for human resources and recruiting.
The group claimed the vulnerability allowed it to remotely access an FBI jobs system before moving into other FBI-managed systems hosted on Amazon Web Services’ GovCloud environment.
The hackers said the breach was not financially motivated and demanded that the FBI remove a May 2026 advisory about the group.
The advisory warned organizations about ShinyHunters’ extortion tactics and said the group had used harassment strategies, including threatening messages and calls to victims and their families.
“This is not financially motivated,” a ShinyHunters spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”
The FBI jobs website and its special agent applicant portal are currently down. The FBI said in a statement that the agency “is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
The incident came amid a broader ShinyHunters campaign targeting organizations.
Earlier this month, the ShinyHunters published stolen records from Florida’s driver and vehicle database after the state declined to pay a ransom, releasing data the group said covered more than 200,000 people.
The group’s recent activities also include attempts to compromise Oracle PeopleSoft servers at more than 100 organizations, the reported theft of millions of Rockstar Games records, and a May attack on Canvas that disrupted schools and universities.
Click Here For The Original Source.
