Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

Cybercriminal group ShinyHunters claims it breached FBI systems and exfiltrated personal data on thousands of current agents and job applicants, according to postings on the group's dark web site reviewed by TechCrunch. Independent reporting by 404 Media, which examined a sample of the leaked records, says the stolen information includes names, home addresses and phone numbers and that the attackers accessed an Oracle PeopleSoft server before moving to a government cloud hosted on Amazon.

By AI Newsroom· Reviewed by Pranav, Founder & Editor-in-ChiefPublished 8 minutes agoUpdated 8 minutes ago0 views
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

Why It Matters

If the theft is genuine and widespread, the exposed personal information could be used for coercion, extortion or foreign intelligence recruitment, posing a significant counterintelligence risk to the agency and its personnel. The incident also follows other recent intrusions into FBI systems this year, highlighting persistent cybersecurity challenges for the bureau.

Key Facts

  • Claiming group: ShinyHunters
  • Primary reporting outlets: TechCrunch and 404 Media
  • Types of data reviewed: Names, home addresses and phone numbers (sample verified by 404 Media)
  • Alleged initial access vector: Oracle PeopleSoft server
  • Alleged subsequent access: Amazon-hosted government cloud storing agents' and applicants' data

ShinyHunters, a cybercriminal group known for mass data thefts and extortion, has posted on its dark web leak site that it breached FBI systems and obtained sensitive information on thousands of current agents and individuals who applied for FBI jobs. TechCrunch reviewed the group's claim, and independent outlet 404 Media reported on the incident after receiving and partially verifying a sample of the stolen records against public sources.

According to 404 Media's reporting, the attackers initially accessed an Oracle PeopleSoft server—a platform commonly used for human resources and applicant records—then moved laterally into an Amazon-hosted government cloud where the agency stores personnel and applicant information. The sample records shared with 404 Media included names, home addresses and phone numbers for agents and their spouses.

ShinyHunters told reporters it took multiple terabytes of data and asserted the breach was not motivated by financial gain; the group demanded that the FBI remove a report they contend contains false allegations about them. The hackers also reportedly defaced the FBI's jobs website, which was displaying a maintenance message and had the special agent applicant portal offline at the time of publication.

The FBI confirmed it was aware of reported unauthorized activity affecting FBIjobs.gov and said it is investigating. The claim is the latest in a string of intrusions affecting the bureau this year, following a separate breach of a system used to manage wiretap and foreign-intelligence warrants and a separate compromise of FBI director Kash Patel's personal email, which was leaked by an Iran-aligned group.

If the breach proves extensive, security experts warned that exposed personal details could create counterintelligence vulnerabilities, where adversaries or criminal actors might try to coerce or extort agents or their family members. At the time of reporting, ShinyHunters had not specified an exact number of affected individuals but said it was confident it had data on "mostly all of FBI" and a substantial amount of applicant records, while the FBI investigation was ongoing.

Keep Reading