ShinyHunters Claims Massive FBI Data Breach via Zero-Day Exploit

3 min read
Source: nypost.com
ShinyHunters Claims Massive FBI Data Breach via Zero-Day Exploit
Photo: nypost.com
TL;DR

The hacking group ShinyHunters claims to have breached the Federal Bureau of Investigation, stealing data on nearly all current and former agents and job applicants. The group alleges it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers and exfiltrate two to three terabytes of data. ShinyHunters stated the breach was a retaliatory response to a May 2026 FBI advisory warning targets not to pay ransoms. The group defaced the FBI job application portal, which remained unavailable on Tuesday. While the FBI has not officially confirmed the breach, Reuters partially verified nine records from a sample of stolen data against credit bureau records. The incident follows a pattern of high-profile intrusions by ShinyHunters, including breaches of Rockstar Games and the education platform Canvas.

Key points

  • ShinyHunters claims to have stolen data on almost all FBI agents and job applicants, including names, addresses, phone numbers, and Social Security numbers.
  • The group alleges it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers and exfiltrate two to three terabytes of data.
  • ShinyHunters stated the breach was a retaliatory response to a May 2026 FBI advisory warning targets not to pay ransoms.
  • The FBI job application portal was defaced and remained unavailable on Tuesday, with a message stating both the site and the Special Agent Applicant Portal were currently unavailable.
  • Reuters partially verified nine records from a sample of stolen data against credit bureau records, but could not confirm the source of the data or whether it was stolen from FBI internal systems.
  • The FBI did not respond to repeated messages seeking comment on Tuesday, and the bureau has not officially confirmed the breach.

Background

ShinyHunters is a notorious digital extortion group known for high-profile intrusions, including the purported theft of millions of business records from video game developer Rockstar Games and a May 2026 intrusion centered on the education tool Canvas that caused widespread disruption across US schools. Earlier this month, AI company Anthropic reported catching ShinyHunters-linked hackers attempting to use its tools. The group also announced a public score-settling against another cybercrime group, cl0p, on Sunday. This latest claim follows a previous major intrusion by ShinyHunters earlier in 2026.

Why it matters

The alleged breach of the FBI, if confirmed, represents a significant cybersecurity incident involving a major US law enforcement agency. The theft of personal data on agents and applicants could pose security risks to individuals and potentially compromise ongoing investigations. The incident highlights the ongoing threat posed by sophisticated hacking groups like ShinyHunters, which target high-profile organizations for both financial gain and reputational damage. The breach also underscores the vulnerability of government systems to zero-day exploits and the importance of robust cybersecurity measures.

What to watch

The FBI is expected to investigate the alleged breach and determine the extent of the data theft. The bureau may issue a public statement confirming or denying the breach and outlining the steps taken to secure its systems. ShinyHunters may continue to release more stolen data or make further demands, potentially escalating the incident. The incident may also prompt a review of the security of Oracle PeopleSoft and AWS GovCloud systems used by the FBI and other government agencies.

Share this article

Want the full story? Read the original reporting

Read on nypost.com