← All stories
● Covered by 8 sources · 9 reportsHigh impact6 negative3 neutralDeveloping

ShinyHunters Claims FBI Data Breach, Access to All Employee and Applicant Information

🔄 Updated 3h ago — new reporting from Ars Technica, 404 Media
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ShinyHunters claims to have breached FBI systems.
  • Data includes names, addresses, phone numbers of FBI employees.
  • A sample of 5,000 employee records was provided.
  • FBI jobs website was defaced and is currently unavailable.
  • ShinyHunters demands the FBI remove a report with false allegations.
  • The breach is not financially motivated.
  • Hackers breached an Oracle PeopleSoft server, then Amazon-hosted government cloud.
  • ShinyHunters used a new Oracle PeopleSoft zero-day vulnerability.
  • The vulnerability allows remote code execution.
  • Hackers accessed FBI systems Monday night.
  • ShinyHunters stole between 2TB and 3TB of data.
  • The group compromised FBI Criminal Justice, HR, and Medlink services.
  • ShinyHunters is exploiting the same zero-day against other organizations, including Fortune 500 companies.
  • ShinyHunters claims to have stolen data on job applicants.
  • ShinyHunters targeted the FBI in response to a May 2026 public service announcement.
  • The FBI's May 2026 PSA detailed ShinyHunters' targeting of Canvas.
  • ShinyHunters demands the FBI retract a May report within one week.
  • ShinyHunters denies claims of exaggerating access to pressure victims.
  • ShinyHunters denies using harassment tactics like swatting or threatening families.
  • ShinyHunters denies falsely claiming to possess compromising photos or videos.
  • ShinyHunters denies any affiliation with The Com.
  • ShinyHunters defaced FBIjobs.gov with a Pokemon image.
  • FBIjobs.gov still shows a banner for the special agent application portal.
  • Reuters saw a sample of the stolen data.
  • 404 Media received confirmation from a ShinyHunters representative.
  • The FBI is investigating the alleged compromise of FBIJobs.gov and employee PII.
  • Stolen data includes names of spouses and certain medical information.
  • Stolen data includes potentially sensitive professional information on FBI employees' work focus.
  • The breach exposed members of the FBI's secretive Remote Operations Unit (ROU).
  • The FBI stated the point of breach is still undetermined, whether a third-party or the FBI's enterprise.

Alleged FBI Data Breach

The hacking group ShinyHunters has claimed responsibility for breaching multiple FBI-related services. A representative from the group stated they have obtained data on all FBI employees and applicants. This data reportedly includes sensitive personal information such as names, home addresses, phone numbers, and details about spouses.

Verification of Sample Data

ShinyHunters provided 404 Media with a sample containing personal data for 5,000 alleged FBI employees. This sample included addresses, phone numbers, and dates of birth. 404 Media used open-source intelligence tools to verify some phone numbers, finding they corresponded to individuals with names listed in the sample. Further checks revealed some phone numbers were associated with U.S. Department of Justice personnel.

Website Defacement and Claims

In addition to the data breach claim, ShinyHunters defaced the FBI jobs website on Tuesday. The defacement message stated, 'this site has been seized by ShinyHunters' and claimed that 'All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information.' The FBI jobs website currently displays a message indicating it is unavailable.

Potential Implications

This alleged data breach could have substantial national security and counterintelligence implications. Previously, criminals linked to groups like ShinyHunters have used hacked data to track and harass FBI agents. The sensitive information could also be valuable to foreign intelligence agencies seeking insights into U.S. law enforcement operations, and could pose safety threats to FBI agents and their families if it falls into further criminal hands.

Updates

🕒 2026-09-24 · new reporting from Ars Technica, 404 Media
  • Stolen data includes names of spouses and certain medical information.
  • Stolen data includes potentially sensitive professional information on FBI employees' work focus.
  • The breach exposed members of the FBI's secretive Remote Operations Unit (ROU).
  • The FBI stated the point of breach is still undetermined, whether a third-party or the FBI's enterprise.
🕒 2026-09-23 · new reporting from Engadget
  • Reuters saw a sample of the stolen data.
  • 404 Media received confirmation from a ShinyHunters representative.
  • The FBI is investigating the alleged compromise of FBIJobs.gov and employee PII.
🕒 2026-09-23 · new reporting from The Record
  • ShinyHunters defaced FBIjobs.gov with a Pokemon image.
  • FBIjobs.gov still shows a banner for the special agent application portal.
🕒 2026-09-23 · new reporting from The Hacker News, SecurityWeek
  • ShinyHunters claims to have stolen data on job applicants.
  • ShinyHunters targeted the FBI in response to a May 2026 public service announcement.
  • The FBI's May 2026 PSA detailed ShinyHunters' targeting of Canvas.
  • ShinyHunters demands the FBI retract a May report within one week.
  • ShinyHunters denies claims of exaggerating access to pressure victims.
  • ShinyHunters denies using harassment tactics like swatting or threatening families.
  • ShinyHunters denies falsely claiming to possess compromising photos or videos.
  • ShinyHunters denies any affiliation with The Com.
🕒 2026-09-22 · new reporting from TechCrunch, BleepingComputer
  • ShinyHunters demands the FBI remove a report with false allegations.
  • The breach is not financially motivated.
  • Hackers breached an Oracle PeopleSoft server, then Amazon-hosted government cloud.
  • ShinyHunters used a new Oracle PeopleSoft zero-day vulnerability.
  • The vulnerability allows remote code execution.
  • Hackers accessed FBI systems Monday night.
  • ShinyHunters stole between 2TB and 3TB of data.
  • The group compromised FBI Criminal Justice, HR, and Medlink services.
  • ShinyHunters is exploiting the same zero-day against other organizations, including Fortune 500 companies.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A data breach affecting thousands of FBI officials' personal information, including addresses and phone numbers, has exposed members of the FBI's secretive Remote Operations Unit (ROU), its hacking team. This exposure reveals the identities of individuals within a highly confidential unit, posing significant security risks to the FBI and its operations.

The FBI is investigating claims by the ShinyHunters hacking group that they stole several terabytes of personal data from current and former employees via a vulnerability in the FBIJobs.gov website. The group stated their motive was to retaliate against an FBI advisory that they claimed contained disinformation about their operations, rather than for extortion.

The hacking group ShinyHunters claims to have stolen 2-3TB of sensitive data belonging to FBI employees and job applicants, reportedly using a zero-day exploit in Oracle's PeopleSoft to access AWS GovCloud servers. The FBI is investigating the alleged compromise of its FBIJobs.gov portal and employee Personally Identifiable Information (PII), which could expose details of agents and counter-espionage units.

The FBI is investigating an alleged breach of its FBIjobs.gov platform by the ShinyHunters cybercriminal group, which defaced the site and claims to have stolen data on current and former employees and applicants. Samples of 5,000 stolen FBI agent records provided by ShinyHunters have been confirmed legitimate by news outlets, indicating a significant compromise of sensitive information.

The cybercrime group ShinyHunters claims to have breached FBI systems, accessing sensitive data on agents and applicants, and defaced an FBI subdomain. The group demands the FBI retract a May report that made allegations against them, stating their actions are a response to these claims.

The cyber extortion group ShinyHunters claims it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive data belonging to current and former agents and job applicants. The group stated it compromised FBI services including Criminal Justice (CJ), HR, and Medlink, and exploited a new Oracle PeopleSoft zero-day vulnerability to deface the FBI's jobs site. This incident highlights a significant security vulnerability within a major government agency and raises concerns about the exposure of sensitive personnel data.

The ShinyHunters extortion group claims to have breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, accessing internal services and stealing 2-3TB of data on employees and applicants. The group also claims to be exploiting the same zero-day against other organizations, including Fortune 500 companies.

The ShinyHunters hacking group claims to have breached the FBI, stealing sensitive data on agents and job applicants, including names, home addresses, and phone numbers. The group demands the FBI remove a report containing what they call false allegations, indicating the breach is not financially motivated.

The hacking group ShinyHunters claims to have breached FBI-related services, obtaining personal data for all FBI employees and applicants, including names, addresses, and phone numbers. This breach carries significant national security and counterintelligence implications, as such data could be used by criminals or foreign intelligence agencies.