www.securityweek.com 23 Sept 2026, 07:13 UTC

ShinyHunters Claims FBI Breach Exposed Data on Nearly All Agents

ShinyHunters Claims FBI Breach Exposed Data on Nearly All Agents
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor

SHINYHUNTERS claims it breached FBI systems and accessed sensitive information linked to Criminal Justice, HR and Medlink services, including data on nearly all FBI agents and job applicants. To support the claim, the group defaced a subdomain of the FBI’s jobs website, fbijobs.gov, displaying the message “This site has been seized by ShinyHunters”. The subdomain is currently offline for maintenance. The FBI said it is aware of claims about unauthorised activity affecting FBIjobs.gov and is investigating, but provided no further details.

ShinyHunters also gave 404 Media a sample allegedly containing personal information on 5,000 FBI employees, including names, telephone numbers and home addresses. 404 Media and others said some of the information appeared authentic, although its origin has not been confirmed. The group claimed it exploited a zero-day vulnerability in Oracle PeopleSoft and stole 2–3 TB of data.

ShinyHunters said the operation was retaliation for an FBI FLASH report issued in May, which it described as containing false allegations about its tactics and links to The Com. The group demanded that the FBI correct or remove the report within one week. Security researchers confirmed in June that ShinyHunters had exploited a PeopleSoft zero-day tracked as CVE-2026-35273, but it remains unclear whether that vulnerability was used against the FBI or whether a separate flaw was involved.

View full article

Article by CyberSIXT