
Technology and Science · updated 1h ago · 2 min read
ShinyHunters Claims It Breached FBI, Stole Agents’ And Applicants’ Data
ShinyHunters claim breach compromised data on thousands of FBI employees and applicants. Data surfaced on dark web; FBI has not confirmed the breach.
Whether Reuters/others can verify the hackers’ proof.
10outlets compared
Same story, two versions
tap a side to read it in full
Some outlets stress lack of verification; others foreground partial corroboration via third-party checks.
Claimed FBI Data Theft
ShinyHunters claimed it breached the Federal Bureau of Investigation and stole data on “almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.” ShinyHunters told Reuters it targeted the FBI in response to a May 2026 agency announcement that detailed ShinyHunters’ methods and advised targets not to pay. Reuters reported that the FBI jobs page displayed “currently unavailable” and that the FBI “Special Agent Applicant Portal” was also “currently unavailable.”
Reuters said it could not verify where the data came from, or whether it had been stolen from the FBI's internal systems as the hackers claimed. Reuters said it partially verified some of the allegedly stolen personnel information by running names and postal address details against credit bureau records and previously breached data preserved by District 4 Labs, finding matches in at least nine cases.

Oracle PeopleSoft Zero-Day
ShinyHunters told CyberInsider it discovered and exploited a previously unknown vulnerability in Oracle PeopleSoft on Monday night, then used it against the FBI shortly afterward.
ShinyHunters claimed it stole between 2TB and 3TB of data and that it was still reviewing the stolen material to determine what other systems and information had been accessed.

ShinyHunters named three allegedly compromised services, “Criminal Justice (CJ),” “Human Resources (HR),” and “Medlink,” and shared a screenshot showing a page on apply.fbijobs.gov under a /PSEMHUB/ path.
404 Media reported that a ShinyHunters representative told it, “We hacked the FBI. We hold data on all FBI employees and applicants,” and 404 Media said the representative provided a sample appearing to contain personal data of 5,000 FBI employees.
CyberInsider reported that ShinyHunters said the PeopleSoft exploitation provided remote code execution (RCE) on an FBI server and that the group then moved laterally into other FBI-managed infrastructure, including systems hosted in AWS GovCloud.
Demands, Maintenance, and Risk
ShinyHunters demanded that the bureau retract a public warning about its tactics within a week, addressing the demand to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman. ShinyHunters said it had “compromised the FBI” and claimed it held “very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.” An FBI jobs page displayed a “Scheduled Maintenance Underway” notice Tuesday and the notice did not identify a security incident or explain whether the outage was related to the hackers’ claims.
TechCrunch reported that ShinyHunters made the claim on its dark web leak site and said it had stolen “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.” TTechCrunch reported that the FBI did not respond to a request for comment about the incident on Tuesday, and TechCrunch said the stolen data could present a major counterintelligence threat by enabling hackers and overseas spies to coerce or extort FBI agents and their families.T