FBI Confirms Investigation as ShinyHunters Claims Massive Data Theft

3 min read
Source: The Washington Post
FBI Confirms Investigation as ShinyHunters Claims Massive Data Theft
Photo: The Washington Post
TL;DR

The FBI is actively investigating a breach claimed by the cybercriminal group ShinyHunters, which alleges it stole sensitive personal data on nearly all FBI agents and job applicants. The group claims it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating 2 to 3 terabytes of data. While the FBI has not confirmed the extent of the breach, it is working with third-party providers to mitigate risks. ShinyHunters framed the hack as retaliation for a May 2026 FBI advisory, demanding its retraction rather than a ransom. Experts warn that exposed personal information could endanger agents and their families, though the group’s claims may be exaggerated.

Key points

  • FBI is investigating a breach of its jobs portal claimed by ShinyHunters.
  • ShinyHunters alleges it stole 2-3 terabytes of data, including PII on agents and applicants.
  • The group claims to have used a zero-day exploit in Oracle PeopleSoft to access AWS GovCloud.
  • ShinyHunters demands the retraction of a May 2026 FBI advisory, not a ransom payment.
  • Experts warn exposed data could be used to target or harm FBI agents and their families.

Background

ShinyHunters is a known cyber-extortion group that has previously targeted entities like Rockstar Games and Canvas. In May 2026, the FBI issued a public service advisory labeling ShinyHunters a threat, which the group claims prompted this retaliatory breach. Earlier coverage noted that the FBI jobs portal was defaced and taken offline, with ShinyHunters posting a message mocking the FBI and President Trump’s Truth Social style.

How outlets are covering it

The Washington Post and NBC News report that the FBI is investigating the breach but has not confirmed its extent. NBC News notes that a former FBI deputy cyber director, Cynthia Kaiser, confirmed the authenticity of a sample document but cautioned that ShinyHunters often exaggerates claims. 404 Media reports that ShinyHunters provided a sample of 5,000 records, which were partially verified through open-source tools, and claims the breach was not financially motivated but rather 'coercion.' All sources agree that the FBI jobs portal was defaced and is currently inaccessible.

Why it matters

A breach of this scale could expose sensitive personal information of FBI agents, potentially endangering them and their families. It also raises concerns about the security of federal systems and the effectiveness of the FBI’s cybersecurity measures. The incident highlights the ongoing threat posed by cybercriminal groups like ShinyHunters and the potential for foreign intelligence agencies to exploit such breaches.

What to watch

The FBI is expected to continue its investigation and work with third-party providers to mitigate risks. ShinyHunters has given the FBI one week to retract its May 2026 advisory or face the public release of the stolen data. The outcome of the investigation and any potential arrests of ShinyHunters members will be closely watched.

Share this article

Want the full story? Read the original reporting

Read on The Washington Post