The Claim
The cyber extortion group ShinyHunters claimed on September 22, 2026, that it breached the U.S. Federal Bureau of Investigation and stole data belonging to current, former, and prospective employees. In a public statement, the group said: "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." ShinyHunters said the compromised FBI services include Criminal Justice (CJ), HR, and Medlink, among others.
The FBI has confirmed it is investigating, stating it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
How the Breach Allegedly Happened
According to 404 Media, which first reported the story, the attackers breached an Oracle PeopleSoft server — commonly used by HR and recruiting teams to store job applicants' personal information — and then pivoted to an Amazon-hosted government system. ShinyHunters told Cybernews it gained access "immediately after discovering a new zero-day in Oracle PeopleSoft," then moved data laterally from that server into FBI systems managed on AWS GovCloud.
Scale and Type of Data Claimed
| Detail | Claim |
|---|---|
| Total data volume | Roughly 2–3 TB |
| Employee sample provided | ~5,000 FBI employees |
| Agent sample provided | ~5,000 agents; at least 10 entries cross-checked against outside records, reportedly including one for FBI Director Kash Patel |
| Employee/agent data types | Names, home addresses, phone numbers — for agents and spouses |
| Applicant data types | Full PII, background information, education records (including grades/degrees), prior U.S. government employment history, sensitive data |
| Possible additional scope | Criminal Justice Information Services (CJIS) records — criminal histories, fingerprints, other law enforcement data |
The data's ultimate origin and authenticity remain unconfirmed pending FBI's investigation.
Site Defacement and Demands
The FBI's jobs portal at apply.fbijobs.gov was reportedly defaced on September 22, displaying a message reading "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS" alongside the group's branding and a link to its dark-web leak site.
ShinyHunters says the incident is "not financially motivated." Instead, the group is demanding the FBI retract what it calls a "false" bulletin issued around May 15 — shortly after ShinyHunters' breach of ed-tech platform Instructure/Canvas, which the group claimed exposed data tied to hundreds of millions of students, teachers, and staff. ShinyHunters gave the FBI seven days to comply, without specifying consequences if the deadline passes.
Why This Matters
Nation-state actors compromising law-enforcement personnel data isn't new — the 2015 OPM breach remains the reference incident — but a cybercriminal extortion brand publicly claiming an FBI compromise is a different category of event. Security analysts warn that if the stolen data is genuine, it presents a counterintelligence risk: personal information on agents and their families could be used by hostile foreign actors for coercion or extortion.
This would also mark the second known compromise of an FBI system this year, following an earlier breach of a system used to manage real-time wiretap and foreign intelligence surveillance warrants.
What to Watch
- Official FBI confirmation of scope, authenticity, and affected systems once the investigation concludes.
- Oracle PeopleSoft patch guidance — if a genuine zero-day was used, expect a vendor advisory and CVE assignment.
- Organizations running PeopleSoft HR modules exposed to external identity or authentication flows should review access logs now, rather than wait for Oracle's advisory.
- Any leak-site publication if ShinyHunters' seven-day deadline passes without the demanded retraction.