On September 22, 2026, the cyber extortion group ShinyHunters claimed it had breached multiple FBI systems and stolen data on current and former employees, job applicants, and agents. The group said it took between 2TB and 3TB of data, including sensitive personal and health-related information, and defaced the FBI jobs portal at apply.fbijobs.gov with a banner reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS." TechCrunch reported on September 22 that the group made the claim on its dark web leak site, which the publication reviewed. The FBI said it was aware of claims regarding unauthorized activity affecting FBIjobs.gov and was investigating, but it did not confirm that its systems were breached or that data was stolen.
ShinyHunters is a prolific cybercriminal group known for large-scale data theft and extortion. 404 Media first reported the breach after receiving a sample of stolen names, home addresses, and phone numbers of FBI agents and their spouses. The sample appeared to contain the personal data of 5,000 FBI employees, including an alleged address, phone number, date of birth, and in some cases details on a spouse. 404 Media reported on September 22 that it verified a portion of the data against public records and found that some sample phone numbers corresponded to people with the same names as listed in the file.
The group said it carried out the hack on Monday night, September 21, 2026, and posted its claim the next day. The defacement displayed ShinyHunters' Umbreon Pokémon logo and a message that read, "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)". The portal showed it was down for maintenance, and the special agent applicant portal was also down. BleepingComputer reported on September 22 that the banner claimed all FBI data was compromised, including sensitive PII and PHI on incumbent and former FBI employees and all applicant information, with the group adding, "We have a lot more than what we claim here."
Key Facts
ShinyHunters told BleepingComputer that initial access came through a new, unpatched Oracle PeopleSoft zero-day vulnerability that allowed remote code execution. The group said it used the flaw on Monday night to access FBI systems and then moved laterally into FBI-managed AWS GovCloud infrastructure. The compromised services reportedly included Criminal Justice, HR, Medlink, and additional internal services. BleepingComputer quoted the group saying, "The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI." BleepingComputer noted that it had not independently verified the alleged zero-day, the lateral movement, or the amount of stolen data.
The data volume claimed by ShinyHunters is between 2TB and 3TB. The sample shared with 404 Media covered about 5,000 employee records. The group did not say exactly how many people had their information taken, but it told TechCrunch it was "very confident we have data on mostly all of FBI" and that "a substantial amount of applicants data [is] involved as well." In its dark web statement, the group said, "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." It added that the compromised services included Criminal Justice, HR, Medlink, and more, covering special agents and other roles.
The motive is unusual because ShinyHunters said the operation was not financially motivated. The group demanded that the FBI remove a report it says contains false allegations about the group. The Hacker News reported on September 23 that the FBI was targeted in response to a May 2026 public service announcement that detailed the threat actor's targeting of Canvas, an online Learning Management System, while urging victims not to pay. The attackers issued their own counter public service announcement describing the FBI's claims as substantial false allegations. BleepingComputer reported that the group later claimed the attack was retaliation for a May 2026 FBI FLASH report and rejected claims that it is part of The Com cybercrime community. The key numbers summary identifies the demanded retraction as the May 2026 IC3 PSA, numbered PSA260515.
The FBI's public response has been limited. The bureau said, "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." The FBI confirmed to BleepingComputer that it was investigating the claims but did not confirm whether its systems were breached or data stolen. ShinyHunters said the FBI quickly became aware of the intrusion, immediately took affected systems offline, and that access to multiple FBI networks was terminated simultaneously. The group described the response by saying, "They literally pulled the plug on everything." BleepingComputer also reported that the gang shared two sample records, one allegedly associated with an FBI special agent involved in a previous BreachForums investigation and one allegedly associated with FBI Director Kash Patel, but the publication did not verify their authenticity.
Several technical details remain uncertain. The Hacker News reported on September 23 that there are currently no details of a PeopleSoft pre-authenticated remote code execution zero-day. However, ShinyHunters weaponized a similar flaw, tracked as CVE-2026-35273, in June 2026 to break into enterprise networks and extort victims. BleepingComputer reported that ShinyHunters claims it is now exploiting the same alleged zero-day against other organizations, including Fortune 500 companies. TechCrunch noted that this is the second known breach of an FBI system this year. The group told 404 Media it took terabytes of data but did not say what it would do with the data if the FBI does not take down its report.
Analysis
Security experts are treating the claim as credible enough to warrant serious attention, even without independent confirmation. Etay Maor, vice president of threat intelligence at Cato Networks, said, "ShinyHunters' claim of an FBI breach is an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups and should absolutely be taken seriously." Maor noted that nation states or nation-state-connected groups have compromised law enforcement organizations before, with the 2015 OPM breach remaining the most notable example, but he said a cybercrime brand publicly claiming an FBI compromise is different. He also observed the September 23 timestamp on the group's post while the news emerged September 22 in the U.S.; if that reflects the group's real operating environment, he said it points toward activity in Asia, though it is not definitive attribution. The Hacker News reported those comments on September 23.
What this really means is that the most dangerous part of this episode is not the defacement or the terabytes themselves, but the specific categories of data allegedly taken. Names, home addresses, phone numbers, dates of birth, and spouse details are exactly the kind of information that can be used for coercion, extortion, and physical targeting. 404 Media reported that criminals from the same ecosystem as ShinyHunters have previously used hacked phone records to track, intimidate, and harass FBI agents investigating them. TechCrunch noted that the stolen data could present a major counterintelligence threat in which hackers and overseas spies use the information to coerce or extort FBI agents and their families into cooperating with a foreign government. The group's claim that the operation was not financially motivated does not reduce that risk. It may increase it, because the data could be traded, stockpiled, or used for leverage rather than simply sold for money.
The bigger picture here is that the FBI's public posture is cautious for good reason. The bureau acknowledged only that it is investigating unauthorized activity affecting FBIjobs.gov, and it did not confirm a breach or data theft. BleepingComputer could not independently verify the zero-day, the lateral movement, or the amount of stolen data. Some of the most dramatic claims, including the sample record allegedly associated with FBI Director Kash Patel, remain unverified. But the defacement of a public FBI jobs portal, the shutdown of the applicant portal, and the FBI's own statement that it is investigating unauthorized activity provide concrete evidence that something real happened. The group's history, plus the June 2026 exploitation of CVE-2026-35273, gives the PeopleSoft claim technical plausibility.
Why It Matters
If the breach claim is accurate, the national security consequences could be severe. FBI agents and applicants expect that their personal information will be protected, especially when it is held in human resources and recruiting systems. The data described by 404 Media goes well beyond names and email addresses. It includes home addresses, phone numbers, dates of birth, and spouse information. That combination is enough to locate people, impersonate them, or threaten them. TechCrunch reported that the stolen data could present a major counterintelligence threat because hackers and overseas spies could use the information to coerce or extort agents and their families into cooperating with a foreign government. 404 Media added that foreign intelligence agencies could use the data to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. Even a partial leak would create years of risk for the people named in the sample.
The incident also highlights the security of Oracle PeopleSoft and the cloud infrastructure that stores government HR data. PeopleSoft is widely used by human resources and recruiting teams to hold job applicants' personal information, which makes it a high-value target. ShinyHunters claims it exploited a new zero-day in the product, then pivoted into FBI-managed AWS GovCloud. The Hacker News reported that no details of a PeopleSoft pre-authenticated remote code execution zero-day are currently public, but ShinyHunters weaponized a similar flaw, CVE-2026-35273, in June 2026. BleepingComputer reported that the group says it is now exploiting the same alleged flaw against other organizations, including Fortune 500 companies. If that is true, the FBI is not the only organization at risk. Enterprises that run PeopleSoft should treat the claim as a warning to review access controls, patch levels, and monitoring.
Next Up
The immediate focus will be the FBI's investigation and whether the bureau confirms that its systems were breached or that data was stolen. The FBI has said only that it is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating. Investigators will likely examine the Oracle PeopleSoft environment, the path into AWS GovCloud, and whether the attackers maintained persistence. Oracle has not yet commented in the materials reviewed here, and no public details of the alleged zero-day have emerged. Security teams will watch for a patch, an advisory, or technical indicators that could help other PeopleSoft customers determine whether they are exposed. The group's claim that it is already exploiting the same flaw against Fortune 500 companies means the next disclosure may not involve the FBI at all.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.