> ## Content Index
> Fetch the complete content index at: https://sourced.cbrasch.me/llms.txt
> Use this file to discover other available public pages before exploring further.

# ShinyHunters Claims It Breached the FBI, Stole Data on Agents and Applicants
- URL: https://sourced.cbrasch.me/shinyhuntersfbi2026/
- Published: 2026-09-23T15:42:05.000Z
- Updated: 2026-09-23T15:55:43.000Z
- Description: A cyber extortion group says it accessed multiple FBI systems and is threatening to release stolen employee data unless the bureau retracts a public warning about its tactics.
- Author: Christian Brasch
- Tags: Justice & Crime, Technology

**WASHINGTON** — The extortion group known as ShinyHunters said on September 22 that it had breached the Federal Bureau of Investigation and obtained personal data on a large share of current and former bureau employees, along with people who had applied for jobs there. The claim was first reported by 404 Media's Joseph Cox, who says a representative of the group told him directly that they held data "on all FBI employees and applicants." The group also said in a statement on its dark web site that it had compromised multiple FBI services, including Criminal Justice, HR, and Medlink systems.

Cox reported that 404 Media was given a sample of roughly 5,000 records containing names, home addresses, phone numbers, and information on agents' spouses, and that the outlet was able to verify some of the phone numbers by matching them to people with ties to the Justice Department. According to his reporting, the hackers said they exploited a previously unknown vulnerability in Oracle's PeopleSoft software, a system commonly used by HR departments and recruiters, then moved from there into an Amazon-hosted government cloud environment holding agent and applicant records. He cautioned that the verification only shows the hackers hold some genuine information, not that the full multi-terabyte dataset they claim is as extensive as described.

Hackread.com reported observing the FBI's job application portal, apply.fbijobs.gov, defaced on September 22 with a message declaring the site "seized" by ShinyHunters, along with a link to the group's leak site. Reuters reported that the group shared what it described as a screenshot of the defaced portal along with information on roughly 5,000 agents, calling it a sample of a larger stolen dataset, though Reuters said it could not independently verify the screenshot's authenticity.

## Why ShinyHunters says it targeted the FBI

ShinyHunters told Reuters the attack was carried out in response to a May 2026 FBI announcement that described the group's methods and advised its targets not to pay ransoms. The group is demanding the bureau retract that warning within a week, addressing its demand to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, and says the effort was not financially motivated. In its own statement, the group called the FBI's characterization of it "substantial false allegations" and said it was disappointed an agency of that standing would circulate what it called disinformation.

ShinyHunters has also pushed back on reporting that ties it to a broader collective known as "The Com," describing that link as an industry narrative pushed onto former officials. That May advisory itself stemmed from a separate incident: an attack on Instructure's Canvas learning platform, after which the FBI's Internet Crime Complaint Center warned schools and users that data from the breach could still be misused even after a ransom was reportedly paid.

## The FBI's response

Official confirmation has been limited. The bureau later said in a statement that it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." Earlier in the day, the FBI had not responded to repeated requests for comment from Reuters. As of this writing, neither the FBI nor the Department of Justice has confirmed the scope of any data taken or addressed ShinyHunters' retraction demand directly.

## What's at stake

Security researchers cited by TechCrunch note that the exposure could pose a counterintelligence risk beyond ordinary identity theft, since stolen contact and family information could be used by hackers or foreign intelligence services to pressure or extort FBI personnel. Nextgov/FCW, citing the FBI's own past warnings, reported that ShinyHunters has previously used harassment tactics against victims, including threats to family members and, in some cases, swatting.

It's worth noting ShinyHunters' own account, as relayed to reporters, is the primary source for most of the specific claims here, the "almost all agents" language and the scope of compromised systems included. The bureau has not confirmed those details, and Reuters was explicit that it could not verify the leaked screenshot on its own.

## Background

ShinyHunters is a financially motivated extortion group that has been active since roughly 2019 and has claimed breaches at companies including Ticketmaster, Charter Communications, and several Salesforce customers, in addition to the Canvas/Instructure incident. The FBI has targeted the group's infrastructure before: in October 2025 and again this year, U.S. and French authorities seized domains tied to BreachForums, a marketplace the group used to host and sell stolen data.

### Sources

- Cox, Joseph. "'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees." *404 Media*, 22 Sept. 2026\. [404media.co](https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/?ref=sourced.cbrasch.me)
- Whittaker, Zack. "Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data." *TechCrunch*, 22 Sept. 2026\. [techcrunch.com](https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/?ref=sourced.cbrasch.me)
- Lakshmanan, Ravie. "ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants." *The Hacker News*, 23 Sept. 2026\. [thehackernews.com](https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html?ref=sourced.cbrasch.me)
- Gripas, Yuri (Reuters). "ShinyHunters hackers say they breached FBI, stole data on bureau employees." *CNBC*, 22 Sept. 2026\. [cnbc.com](https://www.cnbc.com/2026/09/22/shinyhunters-hack-fbi-stole-data.html?ref=sourced.cbrasch.me)
- Reuters. "ShinyHunters hackers say they breached FBI, stole employee data." *CBC*, 22 Sept. 2026\. [cbc.ca](https://www.cbc.ca/lite/story/9.7354002?ref=sourced.cbrasch.me)
- "Hacking group purports to have stolen FBI employee data in cyber attack." *ABC News (Australia)*, 23 Sept. 2026\. [abc.net.au](https://www.abc.net.au/news/2026-09-23/hacking-group-purports-to-have-stolen-fbi-data-in-cyber-attack/107184164?ref=sourced.cbrasch.me)
- Nextgov/FCW. "ShinyHunters claims FBI data theft, demands bureau retract cyber warning." 2026\. [nextgov.com](https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/?ref=sourced.cbrasch.me)
- Hackread. "ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents' Data." [hackread.com](https://hackread.com/shinyhunters-hacks-fbi-jobs-portal-fbi-agents-data/?ref=sourced.cbrasch.me)