Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsTools
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

3030+ Articles
170+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. FBI Investigating Alleged ShinyHunters Breach of Its Jobs Site
FBI Investigating Alleged ShinyHunters Breach of Its Jobs Site
NEWS

FBI Investigating Alleged ShinyHunters Breach of Its Jobs Site

ShinyHunters defaced the FBI's jobs site and claims to hold data on nearly all FBI agents and applicants; the FBI says it is investigating.

Dylan H.

News Desk

September 24, 2026
6 min read

FBI Confirms Investigation Into ShinyHunters Claims Against Its Jobs Portal

The FBI confirmed it is investigating claims of "unauthorized activity" affecting FBIjobs.gov after the extortion group ShinyHunters defaced the bureau's recruitment site on September 22, 2026, replacing agency imagery with a fake seizure banner and a Pokémon image the group has adopted as its unofficial mascot. Hours later, ShinyHunters escalated the claim, saying it had stolen data on "almost ALL FBI Agents" and job applicants — including home addresses, phone numbers, and family information — after allegedly breaching an Oracle PeopleSoft server and pivoting into an Amazon GovCloud environment. The FBI, Oracle, and Amazon have not confirmed that attack path, though people familiar with the investigation told Politico the bureau is treating the claim as credible.


Incident Details

AttributeValue
TargetFBIjobs.gov and Apply.fbijobs.gov (FBI recruitment/applicant portals)
Threat ActorShinyHunters (operating within the "Scattered Lapsus$ Hunters" collective)
MethodAlleged exploitation of an unpatched Oracle PeopleSoft HR bug, followed by a claimed pivot into an Amazon-hosted GovCloud system
StatusDefacement removed; applicant portals taken offline; FBI investigation ongoing, breach path unverified
Data ExposedClaimed 2–3 TB of records including agent and applicant names, home addresses, phone numbers, and family details; unconfirmed by the FBI

What Happened

On the afternoon of September 22, visitors to FBIjobs.gov found the site's official imagery replaced with a banner reading "This site has been seized by ShinyHunters" alongside the group's Pokémon mascot. An FBI spokesperson told The Record that "the FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," declining to answer further questions. By Tuesday afternoon the defacement had been removed, and both Apply.fbijobs.gov and the Special Agent Applicant portal were listed as unavailable — a status that persisted into Wednesday morning.

Later that day, ShinyHunters posted a lengthy statement on its leak site claiming a far deeper compromise: possession of data on nearly every current and former FBI employee, plus everyone who has applied for a bureau job. The group provided samples of 5,000 FBI agent records to 404 Media and other outlets, which reported the samples appeared authentic. A ShinyHunters representative told 404 Media the initial foothold came through a previously unknown bug in Oracle's PeopleSoft software used for HR and recruiting, and that the group used it to reach an Amazon GovCloud environment storing agent and applicant data, exfiltrating an estimated 2 TB to 3 TB. None of that technical narrative — the PeopleSoft flaw, the GovCloud pivot, or the total volume — has been independently confirmed by the FBI, Oracle, or Amazon.

Who Is ShinyHunters

ShinyHunters is a financially motivated data-theft and extortion group that has been active for roughly a year under its current wave of operations, though the name dates back to 2020-era breaches. The FBI's own Cyber Division has previously called the group "a big problem," and it has been linked to high-profile attacks on Ticketmaster, AT&T, McGraw Hill, Carnival Cruise Line, 7-Eleven, Coca-Cola, Cisco, Qantas, Coinbase, and the Salesforce-integration breaches that hit Instructure's Canvas platform in May 2026, disrupting K-12 and university coursework nationwide. Through 2025 and 2026, ShinyHunters increasingly operated as part of a merged collective known as "Scattered LAPSUS$ Hunters," combining Scattered Spider's social-engineering access techniques, ShinyHunters' data-theft and leak-site infrastructure, and LAPSUS$-style public extortion amplification.

Notably, the group says this attack is "not financially motivated." Its stated demand is that the FBI retract a public service announcement issued after the May Instructure breach, which ShinyHunters claims contains false allegations — including that the group conducts swatting, sends threatening texts to victims' families, or holds embarrassing photos and video for sextortion. ShinyHunters gave the bureau "a time of 1 week to correct" or remove the report before threatening to publish the full trove.


Impact Assessment

Impact AreaDescription
Personnel SafetyIf verified, exposure of agents' home addresses and family details could enable swatting, harassment, or physical threats against law enforcement personnel
Counterintelligence RiskAnalysts warn that stolen personal data on federal agents could be leveraged by hostile foreign intelligence services for coercion or recruitment attempts
Operational DisruptionFBI recruitment and applicant portals remain offline, disrupting hiring pipelines for new agents and support staff
Reputational ExposureA second known FBI-adjacent system compromise disclosed in 2026, following an earlier incident affecting wiretap and surveillance systems
Verification GapCore technical claims — the PeopleSoft flaw and GovCloud pivot — remain unconfirmed by the FBI, Oracle, or Amazon as of this writing

Recommendations

For Government Agencies

  • Treat any Oracle PeopleSoft HR/recruiting instance as high priority for patch review and out-of-band vulnerability scanning until Oracle issues guidance or an advisory tied to this incident
  • Audit federated and cross-cloud trust relationships (e.g., on-prem PeopleSoft to Amazon GovCloud) for excessive service-account privileges or stale credentials that could enable lateral pivoting
  • Establish rapid takedown and defacement-monitoring procedures for public-facing recruitment and career portals, which are lower-security surfaces than core case-management systems but carry high reputational and personnel-safety stakes

For Security Teams

  • Monitor ShinyHunters' and the broader Scattered LAPSUS$ Hunters leak-site activity for sample data drops that could validate or refute the claimed breach scope
  • Review PeopleSoft and other HR/ERP platforms in your own environment for outstanding patches, especially internet-facing applicant or self-service modules
  • Where staff or their families could be named in a leaked government dataset, prepare incident-response and personal-safety guidance in coordination with physical security teams

For Affected Individuals

  • Current and former FBI employees or job applicants should monitor official bureau communications for breach notification guidance rather than acting on unverified leak-site claims
  • Consider placing fraud alerts or credit monitoring proactively, given the sensitivity of the data allegedly involved
  • Report any suspicious contact — phishing, vishing, or unsolicited outreach referencing personal details — to FBI security channels immediately

Key Takeaways

  1. ShinyHunters defaced FBIjobs.gov on September 22, 2026, and the FBI has confirmed it is investigating "unauthorized activity" affecting the site.
  2. The group's follow-on claim — theft of data on nearly all FBI agents and job applicants via an Oracle PeopleSoft bug and an Amazon GovCloud pivot — remains unverified by the FBI, Oracle, or Amazon.
  3. ShinyHunters provided 5,000 sample agent records to journalists, which were reported as appearing authentic, lending some credibility to the broader claim even without full confirmation.
  4. The group states the attack is not financially motivated; its demand is retraction of an FBI public service announcement tied to the May 2026 Instructure/Canvas breach.
  5. If confirmed, exposure of agents' home addresses and family data would raise serious personnel-safety and counterintelligence concerns beyond typical data-breach fallout.
  6. This is the second known FBI-adjacent system compromise disclosed in 2026, underscoring continued targeting of federal law enforcement infrastructure by the ShinyHunters/Scattered LAPSUS$ Hunters collective.

Sources

  • FBI investigating alleged ShinyHunters breach of its jobs site — The Record
#Data Breach#ShinyHunters#Government#Cybercrime

Related Articles

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

ShinyHunters claims it breached FBI systems via an Oracle PeopleSoft flaw, stealing 2-3TB of data on agents, applicants, and Director Patel.

4 min read

ShinyHunters Hacks Clop Leak Site, Threatens to Extort Ransomware Gang

ShinyHunters defaced Clop's Tor leak site and claims to have stolen its onion service private keys, threatening to extort the ransomware gang.

5 min read

ShinyHunters Hijacks Cl0p's Ransomware Leak Site, Demands Extortion Payment

ShinyHunters seized Cl0p's dark web leak site, defaced it, and is demanding an eight-figure payment plus a public apology.

3 min read
Back to all News