American Frontline News logo

Hacking group ShinyHunters claims it stole personal data on every FBI employee and applicant

The FBI confirmed it is investigating claims that the notorious hacking group ShinyHunters breached the bureau’s jobs website, stole personal data on current, former, and prospective agents, and defaced the portal with a mock law enforcement seizure notice, all in apparent retaliation for an FBI report about the group’s own criminal tactics.

The FBI’s jobs portal, apply.fbijobs.gov, and its Special Agent Applicant Portal were both listed as “currently unavailable” after ShinyHunters said it carried out the defacement Monday night. Fox News reported that FBIjobs.gov was taken completely offline and remained non-operational as of Wednesday morning.

If the claims hold up, the breach would represent one of the most damaging cyberattacks ever directed at a U.S. law enforcement agency, exposing the home addresses, phone numbers, dates of birth, Social Security numbers, assignment details, and family members’ names of the very people charged with investigating cybercrime.

What ShinyHunters says it took

A ShinyHunters representative told the investigative outlet 404 Media plainly: “We hacked the FBI. We hold data on all FBI employees and applicants.” The group claimed it pulled between two and three terabytes of information from servers it accessed through a zero-day exploit in Oracle’s PeopleSoft software, then pivoted to AWS GovCloud servers where the data was stored.

The defacement message posted on the FBI jobs site read: “this site has been seized by ShinyHunters.” It continued: “All FBI data was compromised including PII/PHI on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”

That language, “personally identifiable information and protected health information”, is not the boilerplate of amateur vandals. It is the vocabulary of groups that know exactly what they are holding and what it is worth.

Partial verification raises the stakes

404 Media reviewed a sample of the alleged stolen data covering 5,000 purported agents. The records included names, home addresses, phone numbers, dates of birth, and details about employees’ spouses. Reporters used the open-source intelligence tool OSINT Industries and the compromised-data tool Darkside, built by cybersecurity firm District 4, to cross-check phone numbers. Some of those numbers turned up associations with U.S. Department of Justice personnel, Breitbart News reported.

Separately, the New York Post reported that Reuters was able to partially verify at least nine records from the alleged stolen data, matching names, addresses, and Social Security numbers against credit bureau records. That independent check moves the story beyond a hacker’s boast and into something the FBI cannot wave away.

The bureau’s public response has been minimal. An FBI spokesperson said: “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” The bureau has not confirmed or denied that any data was actually exfiltrated.

Retaliation for an FBI report

ShinyHunters said the attack was not about money. “This is not financially motivated,” the group’s representative told 404 Media. Instead, the breach appears tied to a dispute over an FBI report about the group, a report that, according to ShinyHunters, contained “false allegations.”

That FBI report described ShinyHunters as a group that exaggerates its access to victims’ systems to pressure them into paying ransoms. It also said the group sends threatening messages and calls to victims and their families, and has in some cases carried out swatting attacks. Fox News described the FBI’s May 2026 public service announcement as a warning to organizations about ShinyHunters’ extortion tactics.

ShinyHunters posted on its leak website demanding the FBI correct or remove the report within one week. When that deadline apparently passed without action, the group struck. The FBI has dealt with major breaches before, including the dismantling of a Chinese state-linked hacking network that compromised U.S. government agencies. But this time the bureau is not the investigator. It is the target.

A group with a track record

ShinyHunters is not an unknown entity. The group previously shut down Canvas, a tech platform running K-12 and college schools built by a company called Instructure. In that case, Instructure paid ShinyHunters’ ransom. The group’s willingness to escalate, from corporate extortion to direct confrontation with the FBI, marks a shift that cybersecurity professionals will not overlook.

The alleged method of entry matters, too. ShinyHunters claims it exploited a zero-day vulnerability in Oracle’s PeopleSoft software, meaning a flaw Oracle had not yet discovered or patched. Oracle has not been quoted confirming or denying the existence of such a vulnerability. If the claim is accurate, it raises hard questions about the security of commercial software platforms running inside federal government infrastructure.

The broader pattern is hard to ignore. A Florida DMV breach earlier this year saw a hacker group claim 200,000 stolen driver records. Foreign hackers have infiltrated Colorado water utilities, altering pumps and disabling alarms. A cyberattack knocked out a California city’s 911 system. Each incident underscores how vulnerable American infrastructure remains, and how often the federal government is playing defense.

What remains unknown

Several critical questions remain unanswered. The FBI has not said whether any data was actually exfiltrated or whether the breach was limited to the defacement of the jobs portal. Oracle has said nothing publicly about a PeopleSoft zero-day. The 5,000-record sample reviewed by 404 Media has been partially cross-checked, but the full scope of the claimed two-to-three-terabyte haul has not been independently verified.

It is also unclear whether the FBI responded to ShinyHunters’ demand to retract or correct the report within the one-week window the group set. And the identity of the ShinyHunters representative speaking to reporters has not been independently authenticated, though the defacement itself and the portal outage are observable facts.

The Department of Justice has pursued charges against foreign nationals involved in cyberattacks on American infrastructure. Whether it can identify and reach the individuals behind ShinyHunters is another matter entirely.

The real cost

If the stolen data is authentic, the people most at risk are not politicians or bureaucrats in corner offices. They are working agents, analysts, and applicants, people whose home addresses, family details, and Social Security numbers may now sit on a criminal group’s servers. Every one of them signed up to protect the country. Now the institution they serve may have failed to protect them.

The FBI’s statement, that it is “aware” and “investigating”, is the minimum any agency would say. What the public needs is a clear accounting: what was taken, how it happened, and what is being done to prevent it from happening again. Vague reassurances do not cut it when the personal data of federal law enforcement officers is potentially in criminal hands.

When a hacking group can breach the FBI’s own hiring portal, deface it with a taunt, and walk away with terabytes of agent data, and the bureau’s best public answer is that it’s “aware”, the rest of us are entitled to wonder who exactly is minding the store.

AMERICAN FRONTLINE ALERTS

Never Miss a Story.

By signing up, you agree to receive newsletters and promotional content from American Frontline News and selected publications in the American Digest Media Network, operated with Patriot Mom Digest LLC, and you accept our Terms of Use and Privacy Policy. You may unsubscribe at any time.

AMERICAN FRONTLINE ALERTS

Never Miss a Story.

Breaking stories and the coverage the other guys won't touch — straight to your inbox.

By signing up, you agree to receive newsletters and promotional content from American Frontline News and selected publications in the American Digest Media Network, operated with Patriot Mom Digest LLC, and you accept our Terms of Use and Privacy Policy. You may unsubscribe at any time.