ShinyHunters, the notorious cybercrime group, claims to have stolen sensitive data on thousands of FBI employees and job applicants after breaching the bureau's systems. The alleged ShinyHunters FBI breach surfaced on September 22, 2026, when the group said it exploited an Oracle PeopleSoft zero-day to access FBI systems and defaced the FBIJobs.gov portal. The FBI confirmed it is aware of 'unauthorized activity' affecting its jobs website and has launched an investigation.
What We Know About the ShinyHunters FBI Breach
The group claims to have stolen between 2 and 3 terabytes of data from systems including Criminal Justice, HR, and Medlink. A sample of 5,000 records was shared with 404 Media and Reuters, containing full names, home addresses, phone numbers, dates of birth, and information about spouses. 404 Media verified that some phone numbers matched real individuals, while Reuters compared names and postal addresses with previously leaked data. The group's claims echo earlier incidents involving Oracle PeopleSoft vulnerabilities exploited by cybercriminals to breach government systems.
ShinyHunters told Cybernews: 'The data includes full PII, background, education, employment, and sensitive medical and drug-related information.'
How Did ShinyHunters Breach the FBI?
According to the group, the intrusion began with a newly discovered Oracle PeopleSoft zero-day. The exploit allegedly provided access to AWS GovCloud, where the FBI stored personnel and applicant records. ShinyHunters claims to have downloaded 2–3 terabytes of data before defacing FBIJobs.gov with a message reading 'this site is seized by ShinyHunters'. The defacement was later removed, and the portal now displays a maintenance notice.
The Oracle PeopleSoft Zero-Day Exploit
Zero-day exploits target software flaws unknown to the vendor, making them highly valuable to attackers. Security researchers have long warned about government cloud infrastructure security gaps, particularly when legacy applications like PeopleSoft remain unpatched. A June 2026 report indicated an earlier FBI PeopleSoft breach attempt had failed, suggesting the group refined its methods before succeeding.
What Data Was Exposed?
The alleged dataset includes the following categories:
- Full names and home addresses
- Personal phone numbers
- Dates of birth
- Spouse and partner information
- Background, education, and employment history
- Sensitive medical and drug-related records
If authentic, this information could enable doxing, swatting, and even counterintelligence operations targeting FBI personnel.
Why Did ShinyHunters Target the FBI?
ShinyHunters stated the hack was retaliation for an FBI public service announcement in May 2026 that described the group's methods and advised victims not to pay ransoms. The hackers gave the FBI until September 30 to remove the FLASH report, warning their claims are 'very real'. This is not the first time cybercrime extortion groups have retaliated against law enforcement agencies.
Impact and Implications
The breach, if confirmed, would represent one of the most significant compromises of FBI personnel data in recent history. Current, former, and prospective employees may face heightened risk of identity theft, harassment, and physical threats. The FBI has not yet confirmed the scope or origin of the stolen data, but the incident underscores the growing sophistication of groups like ShinyHunters.
FAQ
Did ShinyHunters really hack the FBI?
The FBI is investigating reports of unauthorized activity on FBIJobs.gov. Independent verification has confirmed some sample records, but no forensic investigation has officially confirmed the breach's scope.
What data did ShinyHunters steal?
The group claims to have stolen full PII, background, education, employment, and medical information on FBI employees and applicants, including 5,000 verified sample records.
How did ShinyHunters breach FBI systems?
They claim to have exploited an Oracle PeopleSoft zero-day to access AWS GovCloud and download 2–3 terabytes of data.
What is ShinyHunters?
ShinyHunters is a black-hat cybercrime group active since 2019, known for high-profile data breaches, extortion, and selling stolen data on the dark web.
What should affected FBI personnel do?
Monitor credit reports, enable identity theft protection, and report suspicious activity to FBI security teams immediately.
Follow Discussion