SHINYHUNTERS claims it breached the FBI in retaliation for what it calls false allegations in an agency report. In a post published on its leak site on 23 September 2026, the extortion group said it had accessed sensitive information relating to “almost ALL FBI Agents” and people who had applied for jobs with the agency. It named Criminal Justice, HR and Medlink services among those allegedly compromised, and gave the FBI one week to remove or correct the report. The group also denied carrying out swatting, threatening victims’ relatives, claiming compromising photographs or videos, or being part of “The Com”.
The report appears to refer to the FBI/IC3 public service announcement “ShinyHunters: Cyber Criminal Group Attacks Learning Management System”, issued on 15 May 2026. That advisory says threat actors may exaggerate access to personal information, use harassment tactics and falsely claim to possess compromising material.
ShinyHunters reportedly supplied 404 Media with a sample containing information on roughly 5,000 FBI agents, including names, home addresses, phone numbers and spouse details; the publication reportedly verified parts of the sample, but the full dataset and broader breach claims remain unconfirmed. The FBI said it was aware of claims involving unauthorised activity affecting FBIjobs.gov and was investigating, without confirming that the site had been breached or identifying affected data.
Potentially affected people should follow FBI updates, change reused passwords, enable multi-factor authentication and be alert to impersonation attempts.