Drooid Logo
Back to story perspectives

Full Breakdown

ShinyHunters Claims FBI Data Breach

By Drooid · · How we work

Core Event: Alleged FBI System Intrusion

On September 22, the digital extortion group ShinyHunters announced on its dark-web leak site and in an online chat with Reuters that it had breached the Federal Bureau of Investigation. The group says it stole data on thousands of current and former agents and job applicants, defaced the FBI jobs portal and the “Special Agent Applicant Portal,” and left both sites displaying “currently unavailable” messages. ShinyHunters attributes the intrusion to a zero-day vulnerability in Oracle PeopleSoft used on the FBI’s recruitment website, which they claim allowed remote code execution and lateral movement to Amazon-hosted government cloud servers where 2–3 TB of data were downloaded.

Background & Context

ShinyHunters is a prolific cyber-extortion gang known for large-scale thefts, including raids on video-game publisher Rockstar Games and the education platform Canvas. In May 2026 the FBI issued a bulletin describing the group’s methods and advising potential victims not to pay ransom. ShinyHunters says the FBI announcement prompted the attack on its systems. The group is also engaged in a public feud with rival ransomware outfit Cl0p, having defaced Cl0p’s dark-web leak site on September 18.

Data & Statistics

The hackers released a sample that reportedly contains names, home addresses, phone numbers and spousal information for roughly 5,000 individuals linked to the FBI. Reuters and the dark-web intelligence firm District 4 Labs cross-checked the sample against credit-bureau records and previously leaked datasets, finding matches for at least nine records. ShinyHunters claims the total volume of exfiltrated data is between 2 TB and 3 TB.

Official Statements & Responses

The FBI has not responded to multiple requests for comment as of September 22. The agency’s public job portal displayed a notice that the site and the “Special Agent Applicant Portal” were “currently unavailable.” No official confirmation of a breach or of the data’s origin has been issued.

Conflicting Reports & Gaps

Reuters could not verify the authenticity of the screenshot showing the defaced FBI site, nor could it confirm that the stolen files originated from internal FBI systems. The source of the data remains unclear, and attempts to contact individuals whose information appears in the sample were unsuccessful. Oracle and Amazon Web Services have not commented on the alleged PeopleSoft zero-day or the purported AWS GovCloud intrusion.

Why It Matters

If the claimed personal information is accurate, it could be leveraged for counter-intelligence operations, coercion or extortion of FBI personnel and their families by foreign actors or other cybercriminals. The incident underscores vulnerabilities in government recruitment platforms that rely on commercial enterprise software.

What’s Next

ShinyHunters gave the FBI one week to retract the May 15 bulletin, threatening to release the full dataset if its demand is not met. No further action from the FBI has been reported, and the status of the alleged Oracle PeopleSoft zero-day remains unconfirmed.