A hacking crew known for stealing massive amounts of data is now claiming it broke into FBI related systems and obtained sensitive information connected to employees, former staff members, and people who applied to work for the bureau. ShinyHunters says the alleged FBI data breach exposed names, home addresses, phone numbers, birth dates, and, in some cases, information about employees’ spouses.
ShinyHunters provided 404 Media with what it described as a sample containing records for roughly 5,000 FBI employees. 404 Media reported that it checked some phone numbers using open-source intelligence tools and found matches between names in the dataset and people connected to the U.S. Department of Justice. The outlet stressed that the sample supports portions of the hackers’ claims but does not independently prove every claim ShinyHunters has made about the scope of the FBI data breach.
Reuters conducted its own review and reported that the sample appeared to contain names, home addresses, Social Security numbers, work assignments, and, in some cases, relatives’ names. Reuters said it partially verified information in at least 10 records by comparing details with credit bureau records and previously compromised data. However, Reuters could not determine where the records originally came from or independently establish that they were stolen directly from internal FBI systems.
The hackers have been much more definitive about their version of events. A ShinyHunters representative told 404 Media, “We hacked the FBI. We hold data on all FBI employees and applicants,” while claiming the group obtained far more information than the sample it provided.
The group also allegedly took over part of the bureau’s employment website. According to The National News Desk report, the defaced page displayed the message “this site has been seized by ShinyHunters.” The same message reportedly claimed, “All FBI data was compromised, including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.” Application services connected to FBI Jobs were reported unavailable Tuesday afternoon.
The FBI has since acknowledged the situation. In an update published by 404 Media, an FBI spokesperson said, “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” The bureau had not publicly confirmed the hackers’ broader claims about the amount or types of information allegedly taken as of the latest reporting Tuesday.
ShinyHunters told 404 Media that attackers entered through a zero-day vulnerability in Oracle PeopleSoft before reaching servers hosted in AWS GovCloud, where the group claims it downloaded between two and three terabytes of information. Those specific details remain claims from the hackers and have not been independently confirmed by the FBI.
The PeopleSoft allegation is particularly notable because ShinyHunters has recently been connected to a separate campaign targeting the Oracle software. In June, Google Threat Intelligence Group and Mandiant reported that ShinyHunters, which Google tracks as UNC6240, exploited a critical PeopleSoft vulnerability known as CVE 2026 35273 before Oracle publicly disclosed it. Google said the campaign affected more than 100 potentially vulnerable organizations, with higher education making up a large share of exposed targets. Google documented that activity between May 27 and June 9, but the company’s report does not establish that the same vulnerability was responsible for the alleged September FBI data breach.
The timing also comes with an unusual backstory. In May, the FBI Internet Crime Complaint Center published a public warning describing ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. The bureau warned that people operating under the ShinyHunters name had used threatening messages, phone calls, harassment, and, in some cases, false emergency reports to pressure victims. The FBI advised victims not to send payments in response to demands.
ShinyHunters now claims that the warning helped motivate its action against the FBI. According to 404 Media, the group accused the bureau of making “false allegations” and demanded that the FBI correct or remove its report within one week. When asked whether the FBI operation was another attempt at financial extortion, the representative gave a different description. As quoted in The National News Desk report, “what we plan to do is not something I’d call extortion, [maybe coercion].”
The name ShinyHunters has circulated in cybercrime investigations for years. U.S. Department of Justice records show that French citizen Sebastien Raoult was sentenced in January 2024 to three years in prison and ordered to pay more than $5 million in restitution for hacking activity connected to the ShinyHunters group. Prosecutors said data taken from more than 60 companies was advertised for sale between April 2020 and July 2021 and that hundreds of millions of customer records were stolen during the broader scheme.
That history makes the latest claims difficult to dismiss, but it does not automatically prove them. Reuters reported that former FBI official and cybersecurity executive Cynthia Kaiser warned that stolen personal information tied to federal agents can remain useful to criminals for years, particularly when it exposes the people investigating them. At the same time, both Reuters and 404 Media have been careful to separate what they could verify from what ShinyHunters says it accessed.
For now, the most consequential questions remain unanswered: exactly how ShinyHunters obtained the records, how many people are affected, whether the attackers reached systems beyond FBI employment infrastructure, and what information may still be in their possession. Until the bureau completes its investigation and establishes the full scope of the incident, the FBI data breach remains a serious but still partly unverified claim with potentially lasting consequences for employees, applicants, and their families.
