Skip to content

ShinyHunters Hackers Claim They Breached the FBI, Say They Stole Personal Data on Nearly All Bureau Employees

Getting your Trinity Audio player ready...

ShinyHunters Hackers Claim They Breached the FBI, Say They Stole Personal Data on Nearly All Bureau Employees

A notorious cybercriminal extortion group calling itself ShinyHunters said Tuesday it had broken into Federal Bureau of Investigation systems and stolen sensitive personal information belonging to what it described as almost all FBI agents and everyone who has ever applied for a job with the bureau. The claim, posted to the group’s dark-web site and repeated during an online exchange with Reuters, immediately triggered a federal investigation, though the FBI has stopped well short of confirming the hackers’ account of what actually happened.

In a statement, the FBI said it is aware of claims involving unauthorized activity affecting FBIjobs.gov and is currently looking into the matter. Notably, the bureau’s statement referred only to unauthorized activity on that specific recruitment website, not to the sweeping, bureau-wide breach ShinyHunters itself is claiming, an important distinction that hasn’t yet been resolved publicly.

According to ShinyHunters, the stolen material includes names, FBI agent status, email addresses, phone numbers, home addresses, and in some cases information about employees’ spouses, including their Social Security numbers. The group told Axios it also broke into systems tied to the FBI’s criminal justice and human resources functions, and said the total volume of data it pulled came to somewhere between 2 and 3 terabytes, covering current employees, former employees, and people who had simply applied for a position with the bureau at some point. As evidence, ShinyHunters shared what it described as a screenshot of a defaced FBI careers website and a small sample of the data it claims to have taken. By Tuesday afternoon, both the FBI jobs site and the bureau’s Special Agent Applicant Portal were confirmed to be down.

Real More:  Boards Prepare for Digital Infrastructure Shocks Amid Rising Cyber Risk, Capgemini Survey Finds

ShinyHunters has also offered a specific explanation for its own motive, one that sets this incident apart from the group’s usual financially driven extortion campaigns. According to the group, it isn’t seeking any payment from the FBI at all. Instead, it says it wants the bureau to retract statements from a May 2026 advisory that described ShinyHunters’ tactics in detail and explicitly urged the group’s targets not to pay ransom demands. The hackers claim they targeted the FBI specifically in retaliation for that public warning, framing the breach as a reputational strike rather than a financial one.

Reuters made a genuine effort to test whether any of this holds up. Reporters cross-referenced names and address details from the sample data ShinyHunters provided against credit bureau records and against previously breached information archived by dark-web intelligence firm District 4 Labs. In at least nine instances, those details appeared to match real records, and a person familiar with the matter said job descriptions in the sample data lined up correctly in at least some cases as well. Separately, records reviewed by 404 Media using a different data tool found some of the phone numbers in the sample were associated with Department of Justice personnel, and open-source lookups on other sample phone numbers matched the names listed alongside them. Notably, among the individuals whose details reportedly appeared to check out was FBI Director Kash Patel himself.

Real More:  Global Ransomware Attack Update: Hospitals and Energy Giants Hit in Coordinated 2026 Cyber Offensive

Despite those partial matches, Reuters was careful to note what it could not establish: where the data actually originated, or whether it was genuinely stolen directly from the FBI’s internal systems the way ShinyHunters claims. Attempts by reporters to reach the individuals named in the sample data for confirmation were unsuccessful. That gap between partially verified personal details and an unconfirmed claim about how and where they were obtained is the central uncertainty hanging over this entire story right now.

ShinyHunters has described the technical path into the breach in some detail, claiming the intrusion began through a zero-day vulnerability in Oracle’s PeopleSoft platform, the human resources software the group says the FBI relies on, before moving laterally into servers the bureau manages through Amazon’s AWS GovCloud. None of those specific technical claims have been independently confirmed by the FBI or by outside security researchers as of Tuesday.

Reaction from cybersecurity experts pointed to the unusual position ShinyHunters has now put itself in. Cynthia Kaiser, a former senior official in the FBI’s own cyber division, told Axios that when hackers target the bureau directly, the typical response is a faster, more intensive law enforcement push to identify and prosecute them. Allan Liska, a threat intelligence analyst at Recorded Future, offered a different read on where the lasting damage actually falls, telling Axios that regardless of what happens to the hackers, the more significant long-term impact is likely to land on the FBI employees and their families whose personal information has now potentially been exposed.

Real More:  Boston Scientific Says Cyberattack Likely to Hurt 2026 Sales, Profit as Company Now Expects to Miss Full-Year Guidance

This isn’t ShinyHunters’ first high-profile target by any means. The group has claimed responsibility for the theft of millions of business records from Rockstar Games, maker of the Grand Theft Auto franchise, and has been linked to the massive 2024 Snowflake data breach along with a broader 2026 campaign targeting customers of Salesforce’s Experience Cloud platform. ShinyHunters is generally understood to operate as part of a loosely affiliated network of Western cybercriminal groups sometimes referred to collectively as “The Com.” Just days before Tuesday’s FBI claim surfaced, the same group had also publicly claimed it hijacked the dark-web infrastructure of a rival extortion gang, cl0p, in an escalating feud between the two groups.

For now, the FBI’s investigation into the claims remains ongoing, and much of what ShinyHunters has alleged, the scope of the breach, the specific technical method used, and whether the data genuinely came from the bureau’s own systems, remains unconfirmed. What isn’t in question is that a notorious hacking group has once again put federal law enforcement on the defensive, this time by turning the target directly onto the agency most responsible for chasing groups like it down.

Leave a Comment