Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

3012+ Articles
170+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
NEWS

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

ShinyHunters claims it breached FBI systems via an Oracle PeopleSoft flaw, stealing 2-3TB of data on agents, applicants, and Director Patel.

Dylan H.

News Desk

September 23, 2026
4 min read

The Claim

The cyber extortion group ShinyHunters claimed on September 22, 2026, that it breached the U.S. Federal Bureau of Investigation and stole data belonging to current, former, and prospective employees. In a public statement, the group said: "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." ShinyHunters said the compromised FBI services include Criminal Justice (CJ), HR, and Medlink, among others.

The FBI has confirmed it is investigating, stating it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."


How the Breach Allegedly Happened

According to 404 Media, which first reported the story, the attackers breached an Oracle PeopleSoft server — commonly used by HR and recruiting teams to store job applicants' personal information — and then pivoted to an Amazon-hosted government system. ShinyHunters told Cybernews it gained access "immediately after discovering a new zero-day in Oracle PeopleSoft," then moved data laterally from that server into FBI systems managed on AWS GovCloud.


Scale and Type of Data Claimed

DetailClaim
Total data volumeRoughly 2–3 TB
Employee sample provided~5,000 FBI employees
Agent sample provided~5,000 agents; at least 10 entries cross-checked against outside records, reportedly including one for FBI Director Kash Patel
Employee/agent data typesNames, home addresses, phone numbers — for agents and spouses
Applicant data typesFull PII, background information, education records (including grades/degrees), prior U.S. government employment history, sensitive data
Possible additional scopeCriminal Justice Information Services (CJIS) records — criminal histories, fingerprints, other law enforcement data

The data's ultimate origin and authenticity remain unconfirmed pending FBI's investigation.


Site Defacement and Demands

The FBI's jobs portal at apply.fbijobs.gov was reportedly defaced on September 22, displaying a message reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS" alongside the group's branding and a link to its dark-web leak site.

ShinyHunters says the incident is "not financially motivated." Instead, the group is demanding the FBI retract what it calls a "false" bulletin issued around May 15 — shortly after ShinyHunters' breach of ed-tech platform Instructure/Canvas, which the group claimed exposed data tied to hundreds of millions of students, teachers, and staff. ShinyHunters gave the FBI seven days to comply, without specifying consequences if the deadline passes.


Why This Matters

Nation-state actors compromising law-enforcement personnel data isn't new — the 2015 OPM breach remains the reference incident — but a cybercriminal extortion brand publicly claiming an FBI compromise is a different category of event. Security analysts warn that if the stolen data is genuine, it presents a counterintelligence risk: personal information on agents and their families could be used by hostile foreign actors for coercion or extortion.

This would also mark the second known compromise of an FBI system this year, following an earlier breach of a system used to manage real-time wiretap and foreign intelligence surveillance warrants.


What to Watch

  1. Official FBI confirmation of scope, authenticity, and affected systems once the investigation concludes.
  2. Oracle PeopleSoft patch guidance — if a genuine zero-day was used, expect a vendor advisory and CVE assignment.
  3. Organizations running PeopleSoft HR modules exposed to external identity or authentication flows should review access logs now, rather than wait for Oracle's advisory.
  4. Any leak-site publication if ShinyHunters' seven-day deadline passes without the demanded retraction.

Sources

  • The Hacker News — ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
  • Cybernews — ShinyHunters claims FBI systems hack, sensitive data on almost all FBI agents
  • The Register — ShinyHunters claims FBI hack: 'This is NOT financially motivated'
#ShinyHunters#Data Breach#FBI#Oracle PeopleSoft#Extortion#Cybercrime

Related Articles

Google Confirms ShinyHunters Exploited Oracle PeopleSoft Zero-Day CVE-2026-35273

Google's Threat Intelligence Group confirmed in-the-wild exploitation of Oracle PeopleSoft zero-day CVE-2026-35273 by ShinyHunters, even as Oracle...

5 min read

Oracle Mitigates PeopleSoft Zero-Day Exploited in Data Theft Attacks

Oracle has issued an emergency mitigation for CVE-2026-35273, a critical unauthenticated RCE flaw in PeopleSoft Suite being actively exploited by the...

3 min read

NAIC Says Only Public Data Stolen in ShinyHunters PeopleSoft Breach

The National Association of Insurance Commissioners confirms ShinyHunters exploited an Oracle PeopleSoft zero-day but says only publicly available data,...

4 min read
Back to all News