US

ShinyHunters Claims FBI Data Breach: Hacker Group Says It Stole Records of All Employees and Applicants

ShinyHunters claimed an FBI data breach exposing personnel and applicant records via an alleged PeopleSoft zero-day on AWS GovCloud. While sample matches raise counterintelligence concerns, federal reviews continue as investigators assess the claims' scope. Scroll below to know more about the alleged FBI data breach.

ShinyHunters Claims FBI Data Breach: Hacker Group Says It Stole Records of All Employees and Applicants
FBI (Photo Credit: Twitter)
1
2
3
4
5

The high-profile cybercrime collective ShinyHunters claims to have compromised multiple FBI-affiliated systems and exfiltrated records spanning virtually all agency personnel and job applicants, according to disclosures reported by security research and tech media outlets on Tuesday, September 22.

Scope of the Allegations and Sample Data

  • The Claim: A representative for ShinyHunters told 404 Media that the group holds comprehensive records covering current personnel and applicants, stating: “We hacked the FBI. We hold data on all FBI employees and applicants".
  • Exposed Fields: A provided sample covering roughly 5,000 individuals reportedly includes full names, home addresses, phone numbers, dates of birth, and spousal details.
  • Verification Checks: Independent spot-checks by reporting platforms using open-source intelligence tools matched subsets of the sample's phone numbers and personnel records to Justice Department or law enforcement directories.

Alleged Attack Vector and Demands

  • The Vector: The collective claims entry via an unpatched zero-day vulnerability in Oracle PeopleSoft software linked to recruitment infrastructure (fbijobs.gov), enabling unauthenticated command execution and subsequent data extraction from AWS GovCloud-hosted environments.
  • Non-Financial Motive: Unlike traditional ransomware operations tied to financial extortion, group representatives characterised the breach as retaliatory, demanding that the FBI retract or modify a May public service announcement warning about the collective's extortion and harassment tactics.
  • Recruitment Site Defacement: The campaign reportedly featured alterations to recruitment portal displays mimicking law enforcement seizure banners.

Security Assessment and Agency Response

  • Investigative Status: Federal law enforcement acknowledged awareness of unauthorised activity affecting recruitment infrastructure, with internal reviews ongoing. Independent security analysts note that technical details regarding the alleged PeopleSoft zero-day remain sparse or unverified.
  • Broader Implications: Security researchers warn that compromise of personnel and applicant home addresses, phone numbers, and family metadata presents severe downstream counterintelligence risks, physical intimidation vectors, or targeting value for foreign intelligence services.

As federal investigators audit the scope of the alleged PeopleSoft exposure, the incident underscores persistent vulnerabilities in recruitment portals tied to government cloud infrastructure. Whether the sample represents a systemic compromise or a limited database scrape, the fallout highlights the acute counterintelligence challenges posed by targeted retaliation campaigns against federal law enforcement.

Rating:3

TruLY Score 3 – Believable; Needs Further Research | On a Trust Scale of 0-5 this article has scored 3 on LatestLY, this article appears believable but may need additional verification. It is based on reporting from news websites or verified journalists (404 Media), but lacks supporting official confirmation. Readers are advised to treat the information as credible but continue to follow up for updates or confirmations

(The above story first appeared on LatestLY on Sep 23, 2026 07:16 AM IST. For more news and updates on politics, world, sports, entertainment and lifestyle, log on to our website latestly.com).