FBI Investigates Alleged ShinyHunters Cyber Attack That Compromised Sensitive Personnel Data

ShinyHunters reportedly demanded that the FBI remove a report it characterized as containing false allegations about the group, while claiming the stolen data amounted to terabytes.
The FBI jobs website reportedly displayed the message “This site has been seized by ShinyHunters,” followed by the phrase “Thank you for your attention to this matter,” echoing a line associated with President Donald Trump.
The alleged incident would be the second known breach of an FBI system this year: hackers linked to China reportedly penetrated an agency system used to manage real-time wiretaps and foreign-intelligence-gathering warrants in April.
ShinyHunters has also claimed in recent days that it took control of a dark-web site operated by rival hacking group Cl0p, highlighting unusual infighting among prominent cybercrime groups.
The cybercriminal group ShinyHunters claims it breached FBI systems and stole sensitive personal data on thousands of agents, applicants, and employees, including names, home addresses, phone numbers, and spouse details. 404 Media obtained and verified a sample of about 5,000 records, while the FBI jobs website displayed a message saying "This site has been seized by ShinyHunters." The FBI acknowledged unauthorized activity affecting FBIjobs.gov but has not confirmed the broader hacking allegations or verified the records came from its systems.
ShinyHunters claimed the stolen data amounts to terabytes and demanded the FBI remove a report it characterized as false. Politico reported investigators suspect a vulnerability in Oracle PeopleSoft may have enabled access to an Amazon-hosted government cloud. The group hinted the operation was coerced rather than financially motivated, raising fears exposed data could threaten agents' families or aid foreign intelligence services.
The FBI jobs website reportedly displayed a message stating "This site has been seized by ShinyHunters," followed by "Thank you for your attention to this matter"—a phrase echoing President Donald Trump's rhetoric. Yahoo News reported the FBI jobs website and applicant portals were taken offline or defaced. The agency acknowledged the intrusion but stopped short of confirming ShinyHunters accessed its core systems or that the stolen records actually came from FBI databases.
Investigators reportedly suspect a vulnerability in Oracle PeopleSoft—widely used by government agencies—may have provided initial access to an Amazon-hosted cloud environment storing sensitive FBI data. Politico reported the alleged zero-day exploit and full attack path remain unconfirmed. Security experts warn that even patched systems can be exploited if agencies delay applying updates or misconfigure cloud defenses.
This alleged incident would mark the second confirmed breach of an FBI system this year. Huffpost reported that in April, hackers linked to China penetrated an FBI system used to manage real-time wiretaps and foreign-intelligence-gathering warrants. The back-to-back breaches have intensified concerns about the bureau's cyber defenses and prompted calls for security audits.
ShinyHunters denied the breach was financially motivated and hinted at external coercion, suggesting the group may have been pressured into stealing FBI data. Apps for Nexus reported that ShinyHunters also claimed control of a dark-web site operated by rival hacker group Cl0p, signaling unusual infighting and territorial disputes among prominent cybercrime organizations. The group's cryptic statements have fueled speculation about who may have directed the FBI operation.
Publishers
46
Articles
281
Reach
327