The cybercriminal group ShinyHunters has purportedly infiltrated FBI systems, gaining access to sensitive information, including data on FBI agents and applicants. The group has called for the retraction of an FBI report they claim mischaracterizes their activities.
Alleged Data Compromise
ShinyHunters assert that they have breached FBI’s Criminal Justice, Human Resources, and Medlink services, acquiring extensive information on the bureau’s personnel. To substantiate these claims, they defaced a subdomain on the FBI’s job site, fbijobs.gov, with the message, “This site has been seized by ShinyHunters.” The site is now undergoing maintenance.
In a detailed online statement, ShinyHunters responded to an FBI FLASH report from May, which they argue contains false accusations. They have given the FBI a one-week ultimatum to amend or withdraw the report.
Disputing FBI Allegations
The hackers refuted specific allegations that they exaggerate their access to pressure victims, engage in harassment tactics like swatting, or falsely claim to have compromising material on victims. They maintained that their threats are credible, denying any involvement in swatting or contacting victims’ families, and rejected being labeled as “sextortionists.”
Further, ShinyHunters distanced themselves from any association with The Com, dismissing it as a baseless narrative promoted by the cybersecurity industry. They framed their statement as an expression of their First Amendment rights, not as an act of ransom or extortion.
FBI’s Response and Investigation
The FBI has acknowledged the claims of unauthorized activity affecting FBIjobs.gov and is actively investigating the matter. However, the agency has not disclosed further details.
ShinyHunters provided 404 Media with a sample of the alleged stolen data, containing personal information of 5,000 FBI employees. Those who examined the sample confirmed that some of the data seems authentic, though its origin remains unverified.
The hackers claimed they exploited a zero-day vulnerability in Oracle’s PeopleSoft software to penetrate FBI systems, allegedly seizing 2-3 terabytes of data. The cybersecurity community identified in June that ShinyHunters had been leveraging a PeopleSoft zero-day vulnerability for data theft, though it is unclear if the same or a new vulnerability was used in the FBI breach, identified as CVE-2026-35273.
Related articles discuss similar cyber incidents, including data theft via Ribon Apps Hack, a supply chain attack affecting CrowdSec, and a looming data breach deadline faced by McKesson.
