Drooid Logo
Back to story perspectives

Full Breakdown

ShinyHunters Claims Massive FBI Personnel Data Breach

By Drooid · · How we work

Core Event

On September 22, a dark-web post from the cyber-extortion group ShinyHunters announced that it had breached the FBI’s online recruitment portal, FBIjobs.gov, and exfiltrated “very sensitive” personal information on “almost all” FBI agents and job applicants. A sample of roughly 5,000 records—names, home addresses, phone numbers, Social Security numbers, dates of birth and, in some cases, spouses’ details—was supplied to multiple news outlets.

Background & Context

ShinyHunters has been active since at least 2020, targeting large enterprises and educational institutions with supply-chain attacks on Oracle PeopleSoft. The group framed the alleged FBI breach as retaliation for a May 15 advisory, demanding the bureau “correct or simply remove” the bulletin within a week. The FBI’s recruitment systems run on Oracle PeopleSoft and AWS GovCloud, platforms previously exploited by the group.

Data & Statistics

  • Data fields: Names, residential addresses, phone numbers, Social Security numbers, dates of birth, spouse information, job titles.
  • Verification: Reuters cross-checked names, addresses and SSNs against credit-bureau records and District 4 Labs, finding matches in at least nine cases, including FBI Director Kash Patel. 404 Media independently matched several phone numbers to U.S. Department of Justice personnel.
  • Volume claimed: ShinyHunters alleges exfiltration of 2–3 TB of data, though the FBI has not confirmed the amount.

Official Statements & Responses

  • Justice Department & CISA: Spokespersons declined to comment, referring inquiries to the FBI.
  • The group also claimed to have used a previously unknown PeopleSoft zero-day to gain initial access and then moved laterally into AWS GovCloud.

Criticism & Opposition

Kaiser emphasized both short-term physical danger and long-term foreign-intelligence exploitation of the information. She noted that past FBI data leaks have continued to fuel harassment campaigns years after the breach.

Conflicting Reports & Gaps

  • Source verification: 404 Media and Reuters confirmed portions of the sample appear authentic, but could not determine whether the data originated from live FBI systems or archived copies.
  • Technical details: Investigators have not yet confirmed the existence of the alleged PeopleSoft zero-day in the FBI environment. Oracle and AWS have not responded.
  • Scope of breach: The FBI has only acknowledged unauthorized activity affecting the public-facing jobs portal; it has not confirmed access to internal databases or the claimed terabyte-scale exfiltration.

Verbatim Quotes

  • “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” — Agency spokesperson
  • “This type of information could be used by criminals to target or physically harm FBI agents, personnel and their families,” — Cynthia Kaiser, former FBI official
  • “Criminal Justice (CJ), HR, Medlink, and more.” — Jessica Lyons, ShinyHunters spokesperson

What’s Next

The FBI has opened an “active and aggressive” investigation and is reviewing PeopleSoft logs, cloud audit trails and lateral-movement indicators to assess the breach’s true scope. No specific timeline for findings has been disclosed. Organizations using Oracle PeopleSoft are advised to apply the latest security patches and monitor for anomalous administrative activity.