Cybercrime group ShinyHunters claims it breached systems connected to the FBI and stole sensitive information belonging to agency personnel and people who applied for jobs with the bureau. The FBI has acknowledged reports of unauthorized activity affecting its recruitment website and says it is investigating.
ShinyHunters announced the alleged intrusion on its dark web leak site on September 22. The group claims it obtained information covering “almost all” FBI agents as well as applicants for Special Agent and other positions, although the full scope of the alleged data theft has not been independently confirmed.
The attackers reportedly provided journalists with a sample containing records associated with roughly 5,000 alleged FBI personnel. Information in the sample was said to include names, home addresses, phone numbers, and other personal details. Some records appeared to correspond with real people, but that does not establish that all of the information came from a newly compromised FBI system.
ShinyHunters claims it entered the environment through a previously unknown vulnerability in Oracle PeopleSoft, software commonly used for human resources and other enterprise functions. The group says it discovered the flaw shortly before the attack, but neither the FBI nor Oracle has confirmed that a PeopleSoft zero-day was responsible.
The FBI’s recruitment infrastructure showed signs of disruption following the claims. FBIjobs.gov and the Special Agent Applicant Portal became unavailable, while reports indicated that the jobs website was temporarily defaced. The bureau said it was aware of claims involving unauthorized activity affecting FBIjobs.gov and had started an investigation.
The hackers have framed the attack as retaliation rather than a conventional ransom operation. Earlier this year, the FBI published a warning describing ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. The advisory said the group may use harassment, threatening communications, and exaggerated claims about stolen information to pressure victims.
ShinyHunters disputed parts of that description and demanded that the FBI retract or correct its warning. The group reportedly gave the agency seven days to respond and has not publicly announced a financial ransom demand connected to the alleged FBI breach.
The FBI’s May advisory followed ShinyHunters’ claimed involvement in an attack against a learning management system that disrupted educational institutions across the United States. The bureau warned at the time that the group frequently targets organizations holding large amounts of sensitive information.
If the latest claims are verified, exposure of personnel and applicant records could carry particularly serious consequences because the information involves law enforcement employees. However, the extent of the intrusion remains uncertain while the investigation continues.
The FBI has so far confirmed only that it is examining unauthorized activity involving FBIjobs.gov. It has not confirmed ShinyHunters’ claims about compromising additional internal systems, exploiting a PeopleSoft zero-day, or obtaining sensitive information on nearly all FBI agents.