The ShinyHunters hacking group claims to have breached FBI systems and stolen sensitive data belonging to agents and job applicants.
The extortion group known as ShinyHunters claims it breached FBI systems on Monday evening. The group says the attack was prompted by a public FBI warning that, in its view, contains false claims about how the group operates.
FBI Confirms Investigation, Not the Claims
The FBI told tech publication Cybernews on Tuesday evening that it was aware of claims involving unauthorized activity on FBIjobs.gov and was currently investigating the incident. On Tuesday evening, the FBI’s applicant website displayed a notice stating that the application portal for Special Agents was temporarily unavailable. At the time of reporting, there was no confirmation of ShinyHunters’ broader claims.
Alleged Zero-Day in Oracle PeopleSoft
ShinyHunters told Cybernews that it gained access by exploiting a previously unknown vulnerability in Oracle PeopleSoft, enterprise software used by large organizations to manage human resources, recruiting and other personnel processes.
Between late May and early June 2026, the group had already exploited a different, known PeopleSoft vulnerability to compromise more than 300 instances across more than 100 organizations, most of them universities, including the University of Nottingham. According to a TechCrunch report, one of ShinyHunters’ stated goals during that earlier campaign was to breach a PeopleSoft server operated by the FBI. The group was unsuccessful at the time.
What Data Is Allegedly Affected?
In a detailed statement posted to its own leak site, ShinyHunters directly addressed FBI Director Kash Patel and FBI Cyber Division Deputy Director Brett Leatherman. The group wrote:
“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.”
ShinyHunters
According to the group, the affected systems include Criminal Justice, human resources and the Medlink medical system. ShinyHunters claims to have obtained a range of sensitive information from job applications, including full personal information, background details, educational records such as grades and degrees, previous employment with U.S. government agencies, as well as sensitive medical and drug-related information.
If the group did in fact gain access to the FBI’s Criminal Justice Information Services system, criminal records, fingerprints and other biometric data could also be affected. ShinyHunters did not tell Cybernews how many people may be affected or whether the data has already been exfiltrated. It also did not clarify whether the group still has access to the systems.
Seven-Day Deadline for FBI Leadership
ShinyHunters gave the FBI seven days to correct or fully withdraw a report published by the agency in May. The group did not tell Cybernews what it would do with the allegedly stolen data if the deadline expires. Asked about its plans, the group responded only, “no comment.”
Background: Dispute Over an FBI Warning
The dispute stems from a public FBI warning published on May 15, 2026, concerning ShinyHunters and an attack on Instructure’s Canvas learning platform. In particular, ShinyHunters rejects allegations that it routinely exaggerates the extent of its access to victims’ personal data, uses threats and harassment against victims and their families, including so-called swatting, and possesses compromising photos or videos of victims. The group also denies any ties to the cybercriminal network known as “The Com.”
The latest incident comes only weeks after an attack by the Qilin ransomware group on the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). According to earlier reports, more than 6.3 gigabytes of sensitive data related to criminal investigations, phone records and forensic evidence were published in that incident.
(Editorial Team)