FBI Jobs Breach Exposes Hacking Unit Details, FBI Confirms Investigation

3 min read
Source: The Guardian
FBI Jobs Breach Exposes Hacking Unit Details, FBI Confirms Investigation
Photo: The Guardian
TL;DR

The FBI is investigating a breach of its jobs website after the hacking group ShinyHunters claimed to have stolen sensitive data on nearly all agents and applicants. The group, which previously targeted Rockstar Games and Canvas, alleges it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating two to three terabytes of data. The FBI jobs portal was defaced and taken offline. ShinyHunters demanded the removal of a May 2026 FBI advisory that labeled them a cyber-criminal group, rather than demanding ransom. The FBI confirmed it is investigating the unauthorized activity but declined to verify the extent of the data theft.

Key points

  • FBI confirmed it is investigating unauthorized activity affecting FBIjobs.gov, which remained offline Wednesday morning.
  • ShinyHunters claimed responsibility, stating they compromised 'very sensitive data' on almost all FBI agents and job applicants.
  • The group alleged it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating two to three terabytes of data.
  • ShinyHunters demanded the FBI remove a May 2026 public service announcement that characterized them as a 'cyber criminal group' specializing in extortion.
  • 404 Media verified parts of a 5,000-record list shared by ShinyHunters, finding data on members of the FBI's Remote Operations Unit (ROU), including addresses, phone numbers, and spouse details.
  • The FBI stated the point of breach is undetermined, whether a third-party or the FBI's enterprise, and is working with third-party providers to mitigate risks.

Background

This incident follows a pattern of high-profile intrusions by ShinyHunters, including breaches of Rockstar Games and the education platform Canvas. In March 2026, the FBI disclosed investigating 'suspicious activities' on an internal system containing sensitive surveillance data. Also in March, a pro-Iranian hacking group claimed to have hacked FBI Director Kash Patel's account, posting years-old photographs and personal documents. In September 2026, the FBI also investigated a breach at an ID-verification company that exposed digital copies of up to 160 million licenses and IDs.

How outlets are covering it

The Guardian reported that the FBI is aware of claims regarding unauthorized activity and is investigating, but declined to comment further on the specifics of the data theft. 404 Media provided deeper analysis, verifying parts of the stolen data and highlighting that the breach includes members of the FBI's secretive Remote Operations Unit (ROU), potentially revealing who is in that hacking team. 404 Media noted that the stolen data includes job titles related to investigating China or Russia, as well as 'remote operations units.' The FBI's statement emphasized that the point of breach is undetermined and that they are working with third-party providers to mitigate risks, while ShinyHunters framed the breach as a retaliatory response to the FBI's May 2026 advisory.

Why it matters

The breach exposes sensitive personal data on FBI agents, including members of the Remote Operations Unit, which could compromise ongoing investigations and national security operations. The incident highlights vulnerabilities in government systems and the potential for hackers to exploit zero-day vulnerabilities in critical infrastructure. The FBI's investigation and the group's demand for the removal of a prior advisory underscore the ongoing tension between law enforcement and cyber-criminal groups.

What to watch

The FBI is actively investigating the breach and working with third-party providers to mitigate risks. ShinyHunters has given the FBI one week to correct or remove the May 2026 advisory. The FBI has not confirmed the extent of the data theft, and verification of the stolen data remains ongoing. The incident may lead to further scrutiny of the FBI's cybersecurity measures and the Remote Operations Unit's operations.

Share this article

Want the full story? Read the original reporting

Read on The Guardian