ShinyHunters Claims FBI Data Breach Affecting Thousands
The FBI’s jobs portal at apply.fbijobs.gov carried a banner that read, “This site has been seized by ShinyHunters.” The phrasing copied the seizure notices the bureau itself posts when it takes down criminal sites. Below that line the group added a longer claim: “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.” The banner closed with “Thank you for your attention to this matter,” the exact sign-off Donald Trump uses on Truth Social. Ross Ibbetson, writing in the Daily Mail, framed that last line as a deliberate troll of the president. The defacement was public and brief, the first open mark of the claimed intrusion before discovery.
A ShinyHunters representative handed Joseph Cox at 404 Media a sample of roughly 5,000 records. “We hacked the FBI. We hold data on all FBI employees and applicants,” the representative said. The rows carried names, home addresses, phone numbers, dates of birth, and in places the details of spouses. 404 Media became the first outlet to report the breach after examining that file. Staff there ran some of the phone numbers through the OSINT Industries tool, an open-source platform that cross-checks public records. The numbers matched people who shared the same names listed in the sample. Several of those numbers linked to Justice Department personnel, according to the outlet’s own checks. Charlotte Hazard of the National News Desk picked up the same claim that day, noting that a ShinyHunters representative had told 404 Media the group held names, addresses, and phone numbers on FBI employees. The sample remained the first concrete measure of what the group said it possessed.

ShinyHunters told Lawrence Abrams of BleepingComputer that the attack took place Monday night. The group claimed initial access through an unpatched Oracle PeopleSoft zero-day, a previously unknown software flaw that granted remote code execution—the power to run arbitrary commands on the compromised system. PeopleSoft is the Oracle-owned human-resources and recruiting suite used to store applicant and employee data. From that entry the attackers said they moved laterally into AWS GovCloud services, the Amazon cloud platform built to hold sensitive United States government information, naming three of them: Criminal Justice, Human Resources, and Medlink. Between two and three terabytes of data were allegedly stolen. Abrams received the technical account along with a screenshot of the defaced apply.fbijobs.gov path. In parallel, Alex Lekander of CyberInsider reported the same PeopleSoft entry: the zero-day discovered and used that Monday night, remote code execution on an FBI server, then the lateral move into the named GovCloud systems. One screenshot shared with CyberInsider showed a page at apply.fbijobs.gov under the /PSEMHUB/ path displaying what appeared to be system information, which the group called its way in. Neither outlet verified the zero-day itself.
In the interview with 404 Media the ShinyHunters representative set out the motive in plain terms. “What we plan to do is not something I'd call extortion, maybe coercion,” the representative said. The same voice added that the operation was “not financially motivated.” ShinyHunters then published a lengthy statement on its dark-web leak site. The group framed the breach as retaliation for the FBI’s May 2026 FLASH report, which had described the group’s methods and advised targets not to make payments. Lev Shevtsov, summarizing the CBC World account for UA.News, recorded that May-report motive as the stated reason for the attack. The statement gave the bureau one week to correct or remove the report. Zack Whittaker of TechCrunch noted that the group posted the same non-financial claim. The group declined to say whether it would dump the data if the demand were ignored.

Reuters ran names, postal addresses, Social Security numbers, and related identifiers from the material against credit-bureau records and against previously breached data preserved by District 4 Labs. Matches appeared in at least nine cases. The matches did not prove FBI origin. Reuters could not establish where the data had come from, or whether it had been stolen from the bureau’s internal systems as the group claimed. Attempts to reach the people whose details sat in the sample were unsuccessful. Partial alignment with commercial files and earlier leaks was only that—alignment—and the contested limits of those checks left the question of provenance open.
ShinyHunters gave BleepingComputer two sample records it said came from the intrusion. One allegedly held information associated with an FBI special agent involved in a previous BreachForums investigation. The other was allegedly tied to Kash Patel. BleepingComputer declined to publish it.

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said. After discovery, the FBI jobs site went offline. The Special Agent Applicant Portal went offline with it. Apply.fbijobs.gov stopped returning its ordinary pages and displayed service notices instead. One notice stated that apply.fbijobs.gov and the Special Agent Applicant Portal were currently unavailable. Other notices announced scheduled maintenance underway. Still others said the portal was currently down for maintenance. The unavailable notice that appeared on the jobs domain named both portals in a single sentence. ShinyHunters told BleepingComputer that the FBI became aware of the intrusion on Tuesday and immediately took the affected systems offline. The group claimed that access across multiple networks was terminated simultaneously. “They literally pulled the plug on everything,” ShinyHunters said. Apply.fbijobs.gov showed only the maintenance notice.
Reuters could not establish where the data had come from, or whether it had been stolen from the bureau’s internal systems as the group claimed.





