Hacker group ShinyHunters claims to have breached FBI system, stolen personnel and applicant data
A rare incident recently occurred in cyberspace as the notorious malware extortion group ShinyHunters publicly claimed to have successfully breached the systems of the Federal Bureau of Investigation (FBI). Beyond defacing the agency's recruitment website, the group also asserted that it holds a large volume of sensitive data related to special agents and job applicants.

Sensitive data compromised and how ShinyHunters breached FBI systems
According to an announcement posted on its dark web site, ShinyHunters claimed to have gained access to several internal FBI services, including Criminal Justice (CJ), Human Resources (HR), Medlink, along with several other portals. The group stated that it holds detailed data on most current FBI special agents, former employees, as well as individuals who previously submitted job applications to the agency.
The most visible incident was recorded at the official recruitment address FBIjobs.gov. The website previously displayed a banner stating "This website has been seized by ShinyHunters" before switching to a status indicating temporary suspension for system maintenance.
Regarding the intrusion method, a spokesperson for ShinyHunters told the press that they exploited an undisclosed security vulnerability (zero-day vulnerability) on the Oracle PeopleSoft platform. This vulnerability allows attackers to perform remote code execution (RCE) to deeply tamper with the system. Although details regarding this new PeopleSoft flaw have not been made public, analysts noted that ShinyHunters previously used a similar scenario (vulnerability code CVE-2026-35273) in June 2026 to attack corporate networks.
In response to media inquiries, an FBI representative confirmed that they are aware of unusual activities related to the FBIjobs.gov website and are currently investigating to clarify the matter.
Motivations behind and notable actions
According to statements from ShinyHunters itself, this attack was aimed at "retaliation" against a public service announcement (PSA) issued by the FBI in May 2026. In that announcement, the FBI mentioned ShinyHunters targeting Canvas - an online learning management system (LMS) - while calling on victims not to pay ransoms. The hacker group rejected the FBI's information, calling it "false allegations" and asserting that the authorities' intervention efforts had failed.
Additionally, ShinyHunters denied reports claiming that they belong to "The Com" (a distributed cybercrime network), describing this as fabricated information from the cybersecurity industry.
Notably, the claimed attack on the FBI occurred right after ShinyHunters executed another sensational move: taking control of the data leak website of rival ransomware group Clop to demand a ransom amounting to tens of millions of dollars.
Perspectives from cybersecurity experts
Analyzing the incident, Mr. Etay Maor, Vice President of Threat Analysis at Cato Networks, assessed that a cybercrime group publicly claiming to take down the systems of a major law enforcement agency like the FBI is an extremely rare provocative move.
The expert pointed out a minor technical detail: the hacker group's post was timestamped September 23, whereas news began breaking in the U.S. on September 22. This time zone difference serves as a clue indicating that the attackers may be operating from Asia.
Furthermore, Mr. Maor evaluated ShinyHunters as a highly resilient cybercrime brand that continually evolves rather than remaining a fixed group of individuals. Their recent operational methods go beyond merely breaking through external technical perimeter defenses, focusing instead on exploiting identity trust chains: help desk social engineering, abusing OAuth authentication applications, or stealing cloud service integration credentials (SaaS). This serves as a major lesson for organizations in safeguarding trust relationships with third-party systems.
Both the FBI and cybersecurity entities are continuing to closely monitor the situation. The incident once again highlights the fragile boundary of information security, where even leading law enforcement organizations can become targets of sophisticated cyberattack campaigns.
Refer to: The Hacker News - ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants












Comments