ShinyHunters Demands the FBI Retract Its Own Threat Report — Or Else
For the first time in its 2026 run of high-profile intrusions, ShinyHunters is not asking for money. According to reporting from CyberScoop, the extortion-focused cybercrime collective claims to have stolen sensitive data on nearly every Federal Bureau of Investigation (FBI) agent and job applicant, defaced the bureau's careers site, and is now demanding that FBI leadership retract a threat advisory describing the group's tactics — giving Director Kash Patel and Cyber Division Assistant Director Brett Leatherman a one-week deadline. Cybercrime experts told CyberScoop they are stunned that the group would risk both agent safety and intense federal heat over what amounts to a reputational grievance rather than a payday.
Incident Details
| Attribute | Value |
|---|---|
| Threat actor | ShinyHunters (extortion-focused cybercrime collective) |
| Target agency | Federal Bureau of Investigation |
| Visible action | Defacement of the FBI careers site, FBIjobs.gov, on September 22, 2026; the site and the Special Agent Application Portal remained offline as of publication |
| Claimed data | Personal contact information, family-member details, office/duty assignments, and personnel specialties for "almost all" FBI agents and job applicants, drawn from HR, criminal-justice, and medical-records systems the group says it accessed |
| Claimed intrusion vector | An Oracle PeopleSoft vulnerability and FBI-managed cloud infrastructure, per ShinyHunters' own unverified claims — not confirmed by the FBI |
| Demand | Retract or remove the FBI's Q2 2026 FLASH report on ShinyHunters within one week — no ransom payment demanded |
| Addressed to | FBI Director Kash Patel; Cyber Division Assistant Director Brett Leatherman |
| FBI response | "Actively and aggressively investigating" the incident, its root cause, and the alleged impact to employee personal data; has not confirmed the breach's scope or formally attributed it |
| Expert reaction | Widespread alarm over the safety of agents and their families; analysts widely expect the FBI to hold firm rather than retract |
Background: A Report ShinyHunters Says Went Too Far
The dispute traces back to a FLASH report — the technical bulletins the FBI circulates to industry and government partners — that the bureau issued around May 8, 2026, describing what it characterized as ShinyHunters' ecosystem: use of stolen credentials, abuse of trusted vendor and cloud relationships, and data theft and extortion that the report said sometimes involved harassment. (Separately, the FBI's Internet Crime Complaint Center also published a May 15 public advisory on ShinyHunters' disruption of Instructure's Canvas learning-management platform, an attack CosmicBytez Labs covered at the time.)
ShinyHunters disputes three specific claims in the FLASH report: that it exaggerates its access to pressure victims into paying, that it uses harassment tactics such as swatting or threats against victims' families, and that it falsely claims to hold compromising photos or videos of targets. "WE ARE NOT SEXTORTIONISTS," the group wrote in a lengthy statement posted to its leak site. Leatherman had discussed the report's findings publicly at a press briefing roughly two weeks before the attack.
This is the latest entry in a year of unusually aggressive ShinyHunters activity that CosmicBytez Labs has tracked from the May Canvas/Instructure disruption, through the June exploitation of an Oracle PeopleSoft zero-day (CVE-2026-35273), to the more recent Florida DMV and ReliaQuest incidents in September — but the FBI standoff is a distinct escalation, aimed not at a victim organization but at the federal agency that investigates the group itself.
What Happened
In its leak-site post, ShinyHunters said it had compromised FBI systems and obtained between two and three terabytes of data, including records on nearly all agents and everyone who has ever applied for a job with the bureau. As proof, the group temporarily defaced FBIjobs.gov with a seizure-style banner and shared data samples directly with journalists. The FBI has confirmed it is investigating "unauthorized activity" tied to FBIjobs.gov but has not verified the volume or authenticity of the claimed data, nor attributed the incident to ShinyHunters by name.
Rather than a leak-site countdown tied to a ransom, the group's message set a one-week deadline for the FBI to "correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations," adding: "We wish to state unequivocally [that] our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that."
Why Experts Are Alarmed
Researchers who reviewed the sample data shared with journalists say the safety implications go well beyond a typical breach notification. Jon DiMaggio, co-founder of threat-intelligence firm Arkem Cyber, told CyberScoop: "The counterintelligence concern is that assignment information could help hostile actors identify people working on issues relevant to them. That creates risk for personnel and could put sources or investigations connected to their work at risk." DiMaggio, who has spent years infiltrating ransomware and extortion groups, added: "I know firsthand what it is like to have the people you are investigating know who you are."
Another researcher who reviewed the sample described it more starkly to CyberScoop, calling it "a roadmap for every ... country, cartel, and person to locate exactly who in the FBI they have grievance with," and warned that ShinyHunters' "best course of action would be to walk away from the entire situation."
Cynthia Kaiser, a former FBI official now serving as senior vice president at Halcyon's ransomware research center, pointed out that the exposure is already effectively irreversible regardless of what the FBI decides. Because the sample data was posted where anyone with forum access could retrieve it, she noted: "The link no longer works, but the damage is done. Screenshots, downloads, emails — once data is disseminated, you can't pull it back and delete all copies." Kaiser added that "even technically, once threat actors send victims a sample of what they stole, they have probably made five-plus copies of the stolen data" — meaning no retraction or negotiated outcome can undo the exposure agents already face.
Implications for Law Enforcement and Extortion Norms
Analysts widely expect the FBI to hold firm; federal agencies rarely walk back a public threat bulletin under pressure from the very group it describes, and doing so would set a precedent that extortion works even when there is nothing left to ransom. CyberScoop framed the standoff as putting ShinyHunters in its most direct conflict yet with the agents whose job is to investigate the exact kind of extortion crime the group is known for. Security researchers separately noted that targeting law enforcement directly — rather than a private victim — carries a different risk calculus than ShinyHunters' usual campaigns, since it invites a level of investigative and prosecutorial attention that a corporate victim rarely can.
The episode also arrives amid a rougher year for FBI leadership security more broadly: in March 2026, Iran-linked hackers separately accessed Director Kash Patel's personal email and published documents and photographs from it, an unrelated incident that nonetheless underscores how personally exposed bureau leadership has become to hostile actors in 2026.
Key Takeaways
- ShinyHunters is demanding a retraction, not a ransom — a first-of-its-kind pivot from its usual financially motivated extortion campaigns to a dispute over its public reputation.
- The group claims to have stolen data on nearly every FBI agent and job applicant, including contact details, family information, and duty assignments, though the FBI has not confirmed the scope or authenticity of the data.
- The target is a Q2 2026 FBI FLASH report that accused ShinyHunters of harassment tactics, swatting, and false claims of possessing compromising material — allegations the group explicitly denies.
- Experts warn the exposure is already irreversible: sample data shared with journalists was accessible on ShinyHunters' own forum, meaning it has almost certainly been copied and redistributed regardless of what happens next.
- Researchers see direct counterintelligence and physical-safety risk to agents and their families if the claimed dataset is authentic and further disseminated.
- Analysts expect the FBI to hold its ground rather than retract the advisory, setting up a standoff that puts ShinyHunters in unusually direct conflict with federal law enforcement itself.
Sources
- CyberScoop — ShinyHunters trades financial extortion for a reckless war of ego with the FBI
- CyberScoop — ShinyHunters claims attack on FBI exposes almost all agents
- SecurityWeek — ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
- Nextgov/FCW — ShinyHunters claims FBI data theft, demands bureau retract cyber warning
- Malwarebytes — ShinyHunters claims FBI breach was revenge for "false" report