
Back in May, the FBI warned the public about a “cyber criminal group” that steals sensitive data and uses it to extort victims. It appears the FBI is its latest target.
The group, known as ShinyHunters, claims it has stolen personal information on FBI employees and job applicants, according to multiple reports published Sept. 22. The alleged stolen data includes names, home addresses, phone numbers, and details about some employees’ spouses, 404 Media reported. ShinyHunters’ stated demand to the FBI? Take back the warning. The group also reportedly defaced an FBI recruitment website with a message mimicking a law enforcement seizure notice.

Credit: Screenshot/Chance Townsend
ShinyHunters also supplied 404 Media with a sample purportedly containing personal information on 5,000 FBI employees, including home addresses, phone numbers, dates of birth, and, in some cases, details about their spouses. Using OSINT Industries, an open-source intelligence tool, the outlet found that some phone numbers corresponded to the names listed alongside them. A separate check using Darkside, a tool for searching previously compromised data, linked some numbers to Department of Justice personnel.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the agency told PCMag.
While the scope remains unclear, the group has been explicit about what it says it wants.
“This is NOT financially motivated,” a spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”
The grievance dates back to a May 15 FBI advisory, published after an attack on a learning management platform disrupted educational institutions. The bureau warned that attackers use “real or exaggerated claims of access to sensitive or personal information” to pressure victims into paying. It also said ShinyHunters uses “harassment strategies,” including threatening calls and messages to victims and their families, and, in some cases, swatting — or making false emergency reports to send armed police to a victim’s home.

Credit: Screenshot
ShinyHunters disputes that description. “We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations,” the group wrote in a message to FBI Director Kash Patel and the agency’s assistant director for the cyber division, Brett Leatherman (as per quoted by PCMag). “We wish to state unequivocally [that] our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that.”
As for how it supposedly got in, ShinyHunters points to the FBI’s job application website. The group told The Register that it exploited a zero-day vulnerability — a previously unknown security flaw — in Oracle PeopleSoft software. It claims the flaw allowed it to run commands on the servers without first logging in.
From there, the group says it reached FBI-managed servers hosted on AWS GovCloud and downloaded between two and three terabytes of data. It also named human resources, MedLink, and Criminal Justice Information Services among the allegedly compromised services.
Those technical claims remain unverified, though. In an analysis of The Register’s reporting, cybersecurity firm CyPro noted that the account lacked details needed to assess the alleged vulnerability. “ShinyHunters did not publicly identify a vulnerability reference, PeopleSoft component, exploit request, affected configuration or product version,” the firm wrote. The reporting also did not establish how the attackers allegedly moved from the recruitment website into other systems.
Still, this wouldn’t be the group’s first attack involving PeopleSoft. In June, Google’s threat intelligence researchers documented a ShinyHunters campaign exploiting a vulnerability in the software, with educational institutions among its targets. And on Sept. 18, ShinyHunters hijacked the Cl0p ransomware gang’s leak website and demanded an eight-figure payment. That incident also featured a similar mock seizure notice.

Credit: BleepingComputer
For anyone whose information is in the alleged haul, the stakes go well beyond the group’s feud with the FBI. Home addresses, phone numbers, and family details could give scammers, harassers, or foreign intelligence services a way to reach not only employees, but the people closest to them. Even applicants who never got the job could be exposed.
The bureau has already faced a separate, highly personal breach this year. In March, Iran-linked hackers accessed FBI Director Kash Patel’s personal email and published photographs and documents. The FBI said the material was historical and contained no government information.
For now, ShinyHunters has made its demand clear. But for anyone caught up in the alleged breach, the more pressing questions are personal: Does the group have my information, and what will it do with it? Time will tell.
Click here to read more >> https://mashable.com/tech/shinyhunters-fbi-hack-employee-data-claims
IntheNews.tv What's Trending in the news today