The group claimed it stole terabytes of information – including names, home addresses and phone numbers – and reportedly released a sample of the purported data and a screenshot of a defaced FBI recruitment website [1]. An FBI spokesperson told 404 Media the bureau was "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," according to the report [2]. The FBIjobs.gov website and the special-agent applicant portal were temporarily unavailable on Tuesday, officials said.
ShinyHunters is described as a prolific hacking and extortion group linked to large-scale data thefts targeting major companies and government organizations. The FBI itself warned about the group in May, issuing a cybersecurity advisory that accused hackers associated with ShinyHunters of using threats, harassment and, in some instances, swatting to target victims [3]. The group's claims remain unverified by independent sources, and the FBI has not confirmed the breach or the scale of the alleged data theft.
ShinyHunters said the intrusion began with the compromise of an Oracle PeopleSoft server, which runs software commonly used by human resources departments, according to the group's account. The hackers claimed they then moved into an Amazon-hosted government cloud environment containing FBI personnel and applicant data [1]. Neither the FBI nor the companies involved have publicly confirmed that account.
The group said the attack was "not financially motivated" and demanded that the FBI remove a cybersecurity advisory published in May that ShinyHunters says contains false allegations about it. ShinyHunters has not said what it plans to do with the purportedly stolen information if the FBI refuses its demand.
Reuters reported it was able to find apparent matches for some individuals in a sample of the data but could not establish that the information had actually been taken from FBI systems [3]. The group's claims remain unverified by independent sources, and the FBI has not confirmed the breach or the scale of the alleged data theft.
The FBI has not confirmed the breach or the scale of the alleged data theft, and the group's claims remain unverified by independent sources. Reuters reported it was able to find apparent matches for some individuals in a sample of the data but could not establish that the information had actually been taken from FBI systems [3].
The group has previously been linked to high-profile breaches, including an April data breach of Instructure, the maker of the Canvas school information portal. In this incident, the group claimed to have stolen student and staff data of a total 275 million people [4].
The FBI said it is investigating unauthorized activity affecting FBIjobs.gov, according to the spokesperson's statement to 404 Media, and no further public confirmation has been issued [2]. Officials have not confirmed whether the claimed data came from FBI systems, and the investigation remains active.
The FBI's May advisory represents a rare public warning about a specific cybercriminal group. The bureau stated that hackers associated with ShinyHunters have employed intimidation tactics, including swatting, against victims. Swatting involves making false emergency reports to prompt a heavily armed police response at a target's location, a tactic that has resulted in injuries and deaths [2].
The group's demand that the FBI retract its advisory indicates an attempt to use the purported data as leverage. Cybersecurity analysts note that such demands are unusual for financially motivated groups, though ShinyHunters has previously engaged in extortion campaigns. The group has not provided evidence to support its claim that the advisory contains false allegations [3].
The FBI said it is investigating unauthorized activity affecting FBIjobs.gov, according to the spokesperson's statement to 404 Media, and no further public confirmation has been issued [2]. Officials have not confirmed whether the claimed data came from FBI systems, and the investigation remains active. The incident follows a series of high-profile data breaches this year – including a cyberattack on the Bureau of Alcohol, Tobacco, Firearms and Explosives that was declared a "major incident" [5] – and an Iran-linked breach of FBI Director Kash Patel's personal emails [6].
The FBI has not provided a timeline for the investigation. [1] As the probe continues, the authenticity of ShinyHunters' claims and the potential exposure of FBI personnel data remain unresolved.