Washington, D.C./ Crime & Emergencies

ShinyHunters Claims FBI Hack, Threatens To Leak Agent Data Over Warning

AI Assisted Icon
Published on September 24, 2026
ShinyHunters Claims FBI Hack, Threatens To Leak Agent Data Over WarningSource: User:Aude / Wikimedia Commons

A notorious cybercrime group claims it broke into the Federal Bureau of Investigation itself, boasting that it stole personal data on thousands of agency employees and vandalized an FBI recruitment website. The FBI has not confirmed the alleged intrusion, and independent verification so far stops well short of proving the bureau's internal networks were compromised.

The group, known as ShinyHunters, said it breached the FBI and posted a screenshot appearing to show a defaced FBI jobs site alongside a sample of what it claims is stolen personnel data, according to Reuters. As of Tuesday, both the FBI's jobs site and its special agent applicant portal were unavailable, and the bureau did not immediately respond to requests for comment, the outlet reported. A screenshot reportedly showed the defacement. Reporters cross-checked names and postal addresses from the alleged data sample against credit bureau records and information from dark-web intelligence firm District 4 Labs, finding matches in at least nine cases. The outlet said it could not establish where the data originated or whether it was actually pulled from FBI internal systems.

Separately, according to independent tech outlet 404 Media, ShinyHunters claimed the data included names, home addresses, phone numbers, and spouse details.

A Zero-Day Exploit and a Cloud Pivot

ShinyHunters claims it exploited an unauthenticated zero-day remote code execution vulnerability in an internet-facing Oracle PeopleSoft server before pivoting into an Amazon Web Services government cloud environment, according to CyPro. The claim adds technical detail beyond the basic website defacement, though it remains unconfirmed by federal authorities.

In statements posted online, ShinyHunters said the breach was not financially motivated, and instead demanded that the FBI formally retract a public advisory it issued in May 2026 detailing the group's tactics, per Nextgov/FCW. That May 15 advisory, issued by the FBI's Internet Crime Complaint Center, said ShinyHunters used harassment and threatening communications, with swatting occurring in some cases. The warning followed a major breach of an online learning management system used by educational institutions nationwide.

A Group With a Long Rap Sheet

ShinyHunters is no stranger to headline-grabbing extortion campaigns. In May 2024, the group claimed to have stolen 1.3 terabytes of personal and payment data belonging to 560 million Ticketmaster customers, offering the database for sale on dark-web forums for $500,000, according to CBS News. That same year, French citizen Sebastien Raoult was sentenced in federal court in Seattle to three years in prison and ordered to pay over $5 million in restitution after pleading guilty to conspiracy to commit wire fraud and aggravated identity theft as a member of the group, the U.S. Department of Justice announced.

ShinyHunters has been associated with BreachForums, a dark-web marketplace that has undergone multiple shutdowns and relaunches, according to Sophos. The group also said it had gone to war with the Cl0p ransomware gang, per Recorded Future News.

Part of a Bigger PeopleSoft Problem

The alleged FBI intrusion follows a broader campaign that has rattled institutions well beyond federal law enforcement. In June 2026, reports described active exploitation of an Oracle PeopleSoft vulnerability affecting more than 100 organizations, according to Cybersecurity Dive.

For now, the core facts remain unresolved. Reuters has confirmed that pieces of the alleged data sample correspond to real people, but the outlet could not establish whether that information was actually taken from FBI internal systems or where it ultimately came from. The FBI said it was aware of claims of unauthorized activity affecting FBIjobs.gov and was investigating.