ShinyHunters Claims to Have Breached FBI, Stole Employee Data
An infamous hacking group, ShinyHunters, has asserted that it has stolen data on all employees and applicants of the FBI, even going as far as defacing the bureau’s job website to validate their claim. They reportedly exploited Oracle’s Peoplesoft platform to gain access.
“We hacked the FBI. We hold data on all FBI employees and applicants,” a spokesperson from the group stated, as reported by a news outlet. This assertion coincided with the defacement of the FBI jobs site on Tuesday, which the representative said occurred the previous night. At the time of the report, the FBI’s job portal and its Special Agent Applicant Portal were labeled as “currently unavailable,” with the site showing a message indicating such.
The defacement utilized a format reminiscent of law enforcement seizure notices, stating, “this site has been seized by ShinyHunters.” The message claimed that a far-reaching breach had occurred, stating: “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have much more than we declare here.”
A review of a part of the alleged stolen data, reportedly featuring 5,000 supposed agents, included sensitive details like names, home addresses, phone numbers, dates of birth, and even information about employees’ spouses. Journalists verified some of the phone numbers with an open-source intelligence tool, and they corresponded with the names listed in the data shared. A different check using a tool from a cybersecurity firm also revealed numbers linked to personnel in the U.S. Department of Justice.
ShinyHunters claimed the breach was made possible through a zero-day exploit in the Oracle PeopleSoft software, which allowed them to infiltrate AWS GovCloud servers and download substantial amounts of data—between two and three terabytes, as per the group’s statement.
This operation deviates from ShinyHunters’ typical modus operandi. Generally, they hack a system and threaten to leak the data unless they receive ransom. However, the group emphasized that “this is not financially motivated.”
The hacking incident may stem from disagreements regarding an FBI report on the group that asserted ShinyHunters may inflate its claims about access to systems to intimidate victims into compliance, along with making threats and even executing swatting attacks. The group has labeled the report as “false allegations” and has demanded a correction within a week.
An FBI representative confirmed to the news outlet that the agency is aware of the claims concerning unauthorized access affecting its job site and is currently investigating the matter.
Previously, ShinyHunters made headlines when they disrupted Canvas, a tech platform used by various educational institutions, prompting Instructure, the company behind Canvas, to pay a ransom to resolve the issue.






