FBI Confirms Investigation as ShinyHunters Claims Massive Data Theft

The FBI is actively investigating a breach claimed by the cybercriminal group ShinyHunters, which alleges it stole sensitive personal data on nearly all FBI agents and job applicants. The group claims it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating 2 to 3 terabytes of data. While the FBI has not confirmed the extent of the breach, it is working with third-party providers to mitigate risks. ShinyHunters framed the hack as retaliation for a May 2026 FBI advisory, demanding its retraction rather than a ransom. Experts warn that exposed personal information could endanger agents and their families, though the group’s claims may be exaggerated.
Key points
- FBI is investigating a breach of its jobs portal claimed by ShinyHunters.
- ShinyHunters alleges it stole 2-3 terabytes of data, including PII on agents and applicants.
- The group claims to have used a zero-day exploit in Oracle PeopleSoft to access AWS GovCloud.
- ShinyHunters demands the retraction of a May 2026 FBI advisory, not a ransom payment.
- Experts warn exposed data could be used to target or harm FBI agents and their families.
Background
ShinyHunters is a known cyber-extortion group that has previously targeted entities like Rockstar Games and Canvas. In May 2026, the FBI issued a public service advisory labeling ShinyHunters a threat, which the group claims prompted this retaliatory breach. Earlier coverage noted that the FBI jobs portal was defaced and taken offline, with ShinyHunters posting a message mocking the FBI and President Trump’s Truth Social style.
How outlets are covering it
The Washington Post and NBC News report that the FBI is investigating the breach but has not confirmed its extent. NBC News notes that a former FBI deputy cyber director, Cynthia Kaiser, confirmed the authenticity of a sample document but cautioned that ShinyHunters often exaggerates claims. 404 Media reports that ShinyHunters provided a sample of 5,000 records, which were partially verified through open-source tools, and claims the breach was not financially motivated but rather 'coercion.' All sources agree that the FBI jobs portal was defaced and is currently inaccessible.
Why it matters
A breach of this scale could expose sensitive personal information of FBI agents, potentially endangering them and their families. It also raises concerns about the security of federal systems and the effectiveness of the FBI’s cybersecurity measures. The incident highlights the ongoing threat posed by cybercriminal groups like ShinyHunters and the potential for foreign intelligence agencies to exploit such breaches.
What to watch
The FBI is expected to continue its investigation and work with third-party providers to mitigate risks. ShinyHunters has given the FBI one week to retract its May 2026 advisory or face the public release of the stolen data. The outcome of the investigation and any potential arrests of ShinyHunters members will be closely watched.
- Hacking group claims to have stolen thousands of FBI employee records The Washington Post
- Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records The New York Times
- FBI investigating hacking group’s claim of massive breach of agent info NBC News
- ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees 404 Media
- FBI investigating possible cyber breach of its job application website: Sources ABC News - Breaking News, Latest News and Videos
Want the full story? Read the original reporting
Read on The Washington Post