HackRead

ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents’ Data


ShinyHunters has claimed responsibility for compromising systems belonging to the U.S. Federal Bureau of Investigation (FBI), with the group defacing the official FBI job application portal and claiming it obtained sensitive information belonging to FBI personnel and people who applied for jobs at the agency.

Hackread.com observed the defacement on September 22, 2026, at apply.fbijobs.gov. Instead of the normal FBI application portal, the site displayed a page carrying the message, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS,” along with the group’s branding and a link to its dark web data leak site.

The defacement also contained a message claiming that FBI data had been compromised, including personally identifiable information (PII) and protected health information (PHI) involving current and former FBI employees, as well as information belonging to applicants.

ShinyHunters subsequently published a longer statement on its data leak site explaining why it says it targeted the FBI and providing additional claims about the extent of its access.

Deface page left by ShinyHunters (Image credit: Hackread.com)

ShinyHunters Claims Multiple FBI Services Were Compromised

In the statement seen by Hackread.com, ShinyHunters claimed it holds sensitive information on “almost ALL FBI Agents” as well as people who submitted job applications to the bureau, including applicants for Special Agent and other positions.

The group also named several FBI services it claims were compromised, including Criminal Justice (CJ), HR and Medlink, adding “and more” without identifying the additional systems.

ShinyHunters did not provide a total number of records in the statement or explain there how each of the named systems was accessed.

The group’s statement was addressed to FBI Cyber Division Assistant Director Brett Leatherman and FBI Director Kash Patel. ShinyHunters said the action was connected to what it described as false allegations made about the group by the FBI during the second quarter of 2026.

ShinyHunters Explains FBI Breach to Hackread

Responding to questions from Hackread.com, ShinyHunters provided additional details about how it says the FBI hack happened and why the group targeted the agency.

The group said apply.fbijobs.gov was the entry point and that it gained access by exploiting a previously unknown vulnerability in Oracle PeopleSoft.

“We gained access to the FBI via a zero-day in Oracle PeopleSoft. The FBI’s AWS GovCloud infrastructure was compromised,” ShinyHunters told Hackread.com.

The group had previously exploited a separate PeopleSoft vulnerability to breach more than 100 organizations, with universities among its main targets.

According to the group, it moved laterally from the FBI Jobs portal to other services and systems, gaining access to several FBI services and internal tools. ShinyHunters said it downloaded between 2TB and 3TB of data, telling Hackread.com, “We downloaded everything – as much as possible.”

The group said it is confident that the stolen information includes data on “nearly all FBI Agents/Employees” and confirmed that it obtained a substantial amount of job applicant data.

ShinyHunters said the applicant information includes full PII, background information, educational records including grades and degrees, details of previous U.S. government employment, and sensitive medical and drug-related information.

ShinyHunters also addressed its dispute with the FBI, claiming that other low-skilled threat actors have impersonated the group to appear credible and carried out attacks or sent threatening emails and text messages to journalists and security researchers using its name.

According to ShinyHunters, those incidents contributed to allegations about the group that it considers false. ShinyHunters also alleged that people within the information security industry know it was not responsible for some of this activity but continue to associate the incidents with the group.

“As stated in our statement, all we want is to set the record straight,” ShinyHunters told Hackread.com.

The group again rejected the characterization of the FBI incident as an attempt to obtain money, telling Hackread.com, “We want to emphasise that this is NOT extortion and this is NOT financially motivated.”

Dispute Centers on FBI Statements About ShinyHunters

ShinyHunters specifically objected to statements published by the FBI about its methods, including allegations concerning exaggerated claims of access, harassment of victims and their families, swatting, and claims involving sensitive or compromising information.

The language identified by ShinyHunters appears in an FBI Internet Crime Complaint Center (IC3) Public Service Announcement (PDF) published on May 15, 2026. The advisory, titled “ShinyHunters: Cyber Criminal Group Attacks Learning Management System” (PDF), describes ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion.

The FBI advisory states that threat actors can use real or exaggerated claims of access to pressure victims into paying. It also attributes harassment tactics, including threatening communications and, in some cases, swatting, to ShinyHunters members.

The advisory further warns that threat actors may falsely claim to possess compromising material. However, ShinyHunters disputes those descriptions.

In its statement, the group denied conducting swatting attacks against personnel at corporate victims or threatening family members of victim personnel. It also denied claiming to possess embarrassing photographs or videos and rejected any association with “The Com.”

The group further claimed that its FBI hack was not financially motivated.

FBI Given One Week Over Disputed Report

Rather than making a monetary demand, ShinyHunters said it was giving the FBI one week to correct or remove what it referred to as the bureau’s “2026 Quarter 2 FLASH report.”

The publicly available FBI document containing the statements quoted by ShinyHunters is identified by the FBI as Alert Number I-051526-PSA, dated May 15, 2026. It is presented on the IC3 website as a Public Service Announcement.

ShinyHunters said its actions were intended to demonstrate that its threats and access claims are genuine. The group described the incident as a response to what it considers misinformation about its operations.

The statement also accused unnamed journalists of contributing to what ShinyHunters considers inaccurate reporting about the group.

ShinyHunters’ message (Image credit: Hackread.com)

FBI Jobs Portal Replaced With Maintenance Page

Following the ShinyHunters defacement, the affected FBI Jobs portal was changed.

Hackread.com subsequently observed the portal displaying an FBI-branded “Scheduled Maintenance Underway” page instead of the ShinyHunters content.

The page states:

“WE’RE SNIFFING OUT SITE UPDATES FOR YOU!”

It says the site is currently down for maintenance and will return, while directing visitors to the FBI Jobs home page and an FBI Jobs eligibility page. However, the maintenance page does not explain the downtime or mention the ShinyHunters incident.

FBI’s job portal at the time of writing (Image credit: Hackread.com)

ShinyHunters, FBI and Its Cybersecurity Issues

The FBI has faced other cybersecurity incidents involving systems and communities connected to the bureau. In December 2022, a hacker known as USDoD breached the FBI’s InfraGard information-sharing program and leaked a database containing information on more than 80,000 members.

Hackread.com reported at the time that the exposed records included names, usernames, email addresses, and other account information. USDoD was later arrested in Brazil in 2024, with Brazilian authorities linking the suspect to the InfraGard breach.

ShinyHunters itself has previously crossed paths with the FBI over Breach Forums. In May 2024, the FBI and international law enforcement partners seized domains associated with the cybercrime forum. A day later, ShinyHunters told Hackread.com that it had regained control of the forum’s clear-web domain through its registrar after authorities gained access to the forum’s infrastructure.

The latest FBI incident also comes days after ShinyHunters began another unusual confrontation. On September 19, Hackread.com reported that the group had taken over the dark web leak site of the Clop ransomware gang and issued an eight-figure payment demand.

Two days later, Clop regained the ability to publish on its onion address and posted a message asking ShinyHunters to make contact.





Source link