ShinyHunters claims FBI systems hack, sensitive data "on almost ALL FBI agents"
ShinyHunters says the FBI has 7 days to retract what it calls "false allegations" about the group, while refusing to say what happens if the deadline expires.

Image by Cybernews/Getty Images.
- ShinyHunters claims it breached FBI systems, but the agency says it is investigating unauthorized activity affecting FBIjobs.gov.
- The group says it accessed data from agents and job applicants, including personal, educational, employment, medical, and background information.
- The alleged access may involve Criminal Justice Information Services records, which can include criminal histories, fingerprints, and other law enforcement data.
- ShinyHunters gave the FBI seven days to remove a report disputing the group’s claims and has not said what happens next.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The notorious ShinyHunters gang on Tuesday claims to have breached the FBI, compromising multiple systems and agent data – all in apparent retaliation against the law enforcement agency for publishing false allegations about how the hacker group operates.
In a direct email to Cybernews, ShinyHunters revealed new details about the alleged breach, claiming it gained access to FBI systems on Monday night "immediately after discovering a new z-day in Oracle PeopleSoft."
The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,the federal agency said in a statement sent to Cybernews Tuesday evening.
A banner appearing on top of the FBI Jobs website states "The Special Agent Applicant Portal are currently unavailable," when Cybernews checked Tuesday evening.
Cybernews has also reached out to Oracle for comment and is awaiting a response.
ShinyHunters claims access to FBI systems
ShinyHunters posted a lengthy message on its dark leak site early Tuesday, addressed directly to FBI Director Kash Patel and Assistant Director of the FBI Cyber Division Brett Leatherman.
In the 567-word missive, ShinyHunters says it is “severely offended” by the “circulation of disinformation” that apparently was part of an FBI public service announcement (Alert Number: I-051526-PSA) on the gang from earlier this year.
Apparently because of the alleged diss, the seasoned hacker gang decided to hack the federal agency as payback or at least to make a point.
“Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more,” the group wrote.
We have compromised the FBI.ShinyHunters posted in the leak site entry.
We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.
If ShinyHunters is referring to the FBI's Criminal Justice Information Services (CJIS), the potentially exposed information could be extremely sensitive.
CJIS is the FBI's central repository for criminal justice information, including criminal histories, fingerprints, and other biomentric data, wanted and missing persons records, background checks, arrests, charges, case dispositions, and other law enforcement and identifying information.
What FBI data was allegedly compromised?
Inviting journalists to contact the group for more information on the alleged incident, this journalist took a chance and fired off an email, receiving a response in less than ten minutes.
ShinyHunters provided some basic information about the hack, albeit already circulating among other journalists who obviously had the same idea I did.
This included the alleged breach taking place on Monday following the group's apparent discovery of a zero-day vulnerability in Oracle's PeopleSoft enterprise software.
The PeopleSoft platform is used by large organizations to manage human resources, recruiting, employee records, and other workforce operations – which tracks with the job-related data potentially involved.
And although the group was stingy with other details, such as how many FBI agents and job applicants may have been compromised, and whether I could view some proof samples (maybe, they insinuated), the gang did provide a list of the types of “sensitive data” accessed, presumably from the FBI’s HR systems.
We are confident that we hold data on almost all FBI Agents/Employees and we possess a substantial number of job applications,ShinyHunters told Cybernews.
They went on, calling the information found inside the job applications “a wide variety of data,” including:
- Full personally identifiable information (PII)
- Background information
- Educational data: Specific grades and degrees
- Former US government employment information
- Serious and sensitive medical and drug-related information
- More stuff we can go on and on for
ShinyHunters also did not tell Cybernews whether the data itself had been exfiltrated or if they still had access to any of the FBI systems allegedly breached.
The ransomware operators have now given the FBI exactly seven days “to correct or simply REMOVE the 2026 Quarter 2 FLASH report” and the “FALSE allegations.”
ShinyHunters stressed “unequivocally” that they are exercising their First Amendment rights, actively combating disinformation, and that “our threats and claims are very real.”
Furthermore, ShinyHunters did not say what would happen with the data if the FBI does not remove the content by September 30th, simply telling Cybernews “No Comment.”
Why ShinyHunters is threatening the FBI
The FBI’s PSA, titled ShinyHunters: Cyber Criminal Group Attacks Learning Management System and published May 15th, profiles the group in reference to the recent Canvas by Instructure e-learning platform hack.
Ironically, Canvas admitted it paid ShinyHunters an undisclosed ransom to protect student data and regain access to the platform, which the group hacked during spring finals week, causing chaos at thousands of schools worldwide. In fact, unconfirmed rumors put that amount at $10 million, but I digress.
The passages ShinyHunters is at odds with include three main points, claiming the group:
- Exaggerates claims of access to sensitive or personal information to prompt payment from victims.
- Commonly uses harassment strategies to pressure victims and their family, including threatening text messages, phone calls, and swatting.
- Falsely claims to have sensitive or compromising information on victims, including embarrassing photographs or videos.
“We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats," ShinyHunters says in Tuesday’s post to the FBI.
The group also argues that it has unequivocally “NEVER claimed to have sensitive or compromising information,” further noting in all caps that “WE ARE NOT SEXTORTIONISTS.”
The group also made clear it has nothing to do with “The Com” – a decentralized network of cybercriminals where nihilistic hackers often brag about their hacking exploits and promote violence against victims.
We wish to STATE UNEQUIVOCALLY we are NOT apart of "The Com". We have NEVER been apart of "The Com,ShinyHunters states.
The group further claims the criminal network is simply “a propaganda started by the InfoSec Industry, which has brainwashed past FBI and DOJ officials into formalising this nonsense.”
Finally, ShinyHunters took a swipe at “biased public reporting” from journalists without naming anyone in particular.
The attack on the FBI comes just weeks after the Qilin ransomware gang breached the US Bureau of Alcohol, Tobacco, Firearms and Explosives, otherwise known as the ATF, leaking more than 6.3 GB of sensitive data tied to criminal investigations, phone records, and forensic evidence.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.