A well-known extortion group says it broke into Federal Bureau of Investigation systems and walked away with personal data on nearly every agent, employee and job applicant in the bureau’s history. The claim, first reported by 404 Media on September 22, 2026, comes from ShinyHunters, the same hacking collective behind a string of Oracle-linked breaches this year. The FBI has confirmed it is investigating, but as of September 24, 2026, no government agency has verified the full scope of what the group is claiming.
What makes this different from the usual extortion playbook is the group’s own explanation for why it did it. ShinyHunters says the FBI hack was not built for a payday. It says the bureau published false claims about the group in a threat advisory earlier this year, and this breach is retaliation. Whether that framing holds up, the technical claims behind it, and what happens next for roughly 35,000 FBI employees are the parts worth tracking closely.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What ShinyHunters Claims It Stole From the FBI
According to 404 Media’s reporting, a ShinyHunters representative told the outlet directly, “We hacked the FBI. We hold data on all FBI employees and applicants.” The group says its haul totals between 2 and 3 terabytes, covering current and former employees along with people who ever applied for a job with the bureau, according to TechCrunch.
To back the claim, the group handed reporters a sample covering roughly 5,000 employee records. Outlets that reviewed the sample, including 404 Media and RedState, described fields such as full names, home addresses, phone numbers, dates of birth, Social Security numbers and, in some records, emergency contact and spouse information. That is a materially deeper data set than a typical HR breach, since it ties agents’ identities to home addresses and family members rather than just work emails and job titles.
ShinyHunters also claims it defaced FBIJobs.gov, the bureau’s applicant portal, replacing content on the site with a message stating the site had been seized by the group. Beyond the jobs portal, the group told researchers it reached FBI Criminal Justice, HR and Medlink-linked systems, and that it moved laterally into Amazon Web Services GovCloud infrastructure tied to the bureau, per CyberInsider. None of those deeper claims have been independently verified by a third party as of this writing.
How the Alleged Breach Happened: an Oracle PeopleSoft Zero-Day
The attack vector ShinyHunters describes is a new zero-day vulnerability in Oracle PeopleSoft, the enterprise resource planning suite widely used by government agencies and large companies for HR and applicant processing. Per BleepingComputer, the group says the flaw allows remote code execution against PeopleSoft-linked web infrastructure, which it used to gain an initial foothold on servers tied to FBIJobs.gov before pivoting deeper into bureau systems.
This is not ShinyHunters’ first run at PeopleSoft in 2026. The group already ran a large-scale PeopleSoft exploitation campaign that hit more than 100 organizations, most of them universities, using a related flaw tracked as CVE-2026-35273. Security researchers say the FBI intrusion appears to use a separate, previously undisclosed bug in the same software family rather than a reused exploit, which would explain why patches issued for the June campaign did not stop this one.
ShinyHunters has also told researchers it is running the same zero-day against Fortune 500 companies beyond the FBI, according to CyberInsider’s sourcing. That detail matters for enterprise security teams: if the flaw is real and unpatched, the FBI disclosure functions as an early warning for every other PeopleSoft customer running exposed instances, not just the bureau.
The FBI’s Response So Far
The bureau has not confirmed the breach outright, but it has not dismissed it either. The FBI issued a statement acknowledging it is aware of a criminal group’s claim that it compromised the FBIJobs.gov portal and may have affected employee personally identifiable information. The bureau said the point of entry, whether through a third-party vendor or its own enterprise systems, remains undetermined, and that it is actively investigating alongside the third-party providers that support the jobs portal, per reporting from Forbes.
The Register reported that the FBI did not respond to its specific request for comment as of publication, and multiple outlets note that neither Oracle nor AWS has confirmed whether GovCloud infrastructure was actually touched. That gap between a loud public claim and a cautious institutional response is typical of ShinyHunters cases this year, several of which took days or weeks to move from disputed claim to confirmed breach.
Who Is ShinyHunters?
ShinyHunters is not a new name in cybercrime circles. Security researchers also track the group under the aliases Bling Libra, UNC6040 and UNC6240, and its resume goes back to 2020. The group’s most consequential prior campaign hit Snowflake-connected cloud environments in 2024, a credential-stuffing wave that led to confirmed breaches at Ticketmaster, Santander Bank and dozens of other companies, exposing hundreds of millions of records in the process. Tech Insider covered the fallout when the same wave reached Rockstar Games through its Snowflake and Anodot exposure.
Since then, the group’s model has stayed consistent: find a vulnerability in software used by hundreds or thousands of organizations at once, automate the exploitation, then monetize through public leak pressure rather than quiet ransom notes alone. That approach shows up again in the group’s 2026 record, including its claimed breach of McKesson, where the group claimed 284 million records, and a string of other corporate targets throughout the year.
Why This Isn’t About Money: the FBI Advisory Grudge
The most unusual part of this incident is the motive ShinyHunters is giving for it. A spokesperson for the group told The Register, “This is NOT financially motivated,” a framing that breaks from the group’s typical ransom-driven pattern. Instead, the group says it wants the bureau to walk back statements made in a Quarter 2, 2026 FLASH advisory that described ShinyHunters tactics, including claims about harassment campaigns and swatting threats against victims and their families.
The Register also quoted the group demanding a retraction directly: “We want the FBI to correct or retract their statements they made, which included substantial false allegations.” A separate message the group sent, addressed to FBI leadership and the bureau’s cyber division, set a hard deadline: “We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations.”
The group has pushed back specifically on the swatting and harassment allegations, telling Axios that lower-skilled copycat actors have been misusing the ShinyHunters name for their own attacks, and that the advisory unfairly lumped that behavior in with the group’s own operations. It closed its messaging with a warning meant to head off any assumption that this is a bluff: “We wish to state unequivocally [that] our threats and claims are very real. Not exaggerated and never a bluff.”
A Pattern: ShinyHunters’ 2026 Breach Spree
The FBI claim does not exist in isolation. It caps a year in which ShinyHunters has run one of the most active extortion campaigns security researchers have tracked, moving from cloud platforms to enterprise software to, now, a federal law enforcement agency. The table below lines up the group’s confirmed and claimed activity across 2026.
| Date | Target | Attack Vector | Claimed or Confirmed Scale |
|---|---|---|---|
| March 14, 2026 | Salesforce Experience Cloud customers | Misconfigured Aura endpoints | Hundreds of organizations affected |
| May 27–June 10, 2026 | 100+ organizations, mostly universities | Oracle PeopleSoft PeopleTools RCE (CVE-2026-35273) | ~300 PeopleSoft instances compromised |
| Throughout 2026 | McKesson, Carhartt, Abbott, Kodak, Match Group, Instructure Canvas | Vishing, OAuth token theft, credential stuffing | Tens to hundreds of millions of records claimed combined |
| September 19, 2026 | Clop ransomware’s own Tor leak site | Unauthenticated file-upload flaw in Grav CMS | Site defaced; 8-figure extortion demand issued |
| September 22, 2026 | FBI (FBIJobs.gov, HR, Criminal Justice, Medlink systems) | New, undisclosed Oracle PeopleSoft zero-day | 2–3TB claimed; 5,000-record sample published |
Read across that timeline and a strategy emerges. ShinyHunters increasingly targets the software layer underneath an organization, not the organization’s own front door, then scales the same exploit across every customer of that software it can find. Oracle PeopleSoft, used across thousands of government and enterprise HR departments, gave the group a rare kind of leverage: one flaw, potentially thousands of victims.
National Security Stakes: What FBI Employee Data Exposure Means
Losing HR records is bad for any company. Losing home addresses, phone numbers, dates of birth and family details for federal agents is a different category of problem. Undercover agents, confidential informants and organized crime investigators depend on their home life staying separate from their professional one. A leak that ties an agent’s identity to a home address and a spouse’s name creates a direct physical safety risk, not just an identity-theft one.
There is also an operational security angle. Applicant data, if the claim holds up, would expose people who applied for FBI jobs but never joined, some of whom may currently work in other parts of government, the military, or in sensitive private-sector roles where a background check history could be valuable to a foreign intelligence service. That is part of why the bureau’s own past advisories have flagged HR-adjacent software as a high-value target, a warning that Tech Insider covered in the context of driver’s license data breaches earlier this year.
Historical Context: How This Stacks Up Against Past Federal Breaches
Federal personnel data breaches are not new, but they are rare enough that each one gets compared to the last major one. The 2015 breach of the U.S. Office of Personnel Management remains the benchmark: intrusions attributed to state-linked hackers exposed background-check and personnel records tied to roughly 21.5 million people, including fingerprint data and security clearance details. That breach reshaped how federal agencies think about background-investigation data years after the fact.
This year already produced another large federal-adjacent breach, when a driver’s license data vendor breach tied to IDScan.net and Nexus exposed roughly 153 million records and drew an active FBI investigation into 153 million exposed driver’s licenses. Tech Insider also tracked how slow the political response was compared to OPM, noting the gap between congressional silence on that breach versus the fallout after OPM. The ShinyHunters FBI claim now puts the bureau in the unusual position of being both the investigator of a major breach and, allegedly, a victim of one in the same year.
| Incident | Year | Records (Claimed or Confirmed) | Verification Status |
|---|---|---|---|
| OPM breach | 2015 | ~21.5 million personnel records | Confirmed by federal government |
| IDScan.net / Nexus driver’s license breach | 2026 | ~153 million records claimed | Breach confirmed by vendor; FBI investigating scope |
| ShinyHunters Oracle PeopleSoft campaign | 2026 | 100+ organizations, ~300 instances | Confirmed victim-by-victim by affected institutions |
| ShinyHunters FBI claim | 2026 | 2–3TB claimed; 5,000-record sample published | Unconfirmed by FBI as of September 24, 2026 |
The Technical Chain, Summarized
Stripped of the back-and-forth statements, the alleged attack chain that researchers have pieced together from ShinyHunters’ own claims and outlet reporting looks like this:
1. Initial access: exploitation of an undisclosed Oracle PeopleSoft
remote-code-execution flaw against FBIJobs.gov infrastructure
2. Defacement: FBIJobs.gov portal content replaced with a
ShinyHunters-attributed message
3. Lateral movement: claimed pivot into AWS GovCloud-hosted
FBI systems (unconfirmed by AWS or FBI)
4. Data staged: HR, Criminal Justice and Medlink-linked
records allegedly exfiltrated, totaling 2-3TB claimed
5. Proof-of-claim: 5,000-record sample shared with journalists
6. Extortion demand: retraction of a Q2 2026 FBI FLASH advisory,
with a one-week deadline, in lieu of a ransom payment
That sixth step is the outlier compared to almost every other ShinyHunters campaign this year, where the demand has been a cash payment tied to a leak-site countdown. Here, the group is asking for a public statement, not a wire transfer, which is why several outlets have described this incident as reputational warfare dressed up as a data breach.
Market and Industry Impact
For Oracle, this is the second high-profile PeopleSoft security story in four months, following the June campaign that hit over 100 organizations. Enterprise customers running on-premises PeopleSoft deployments, particularly in government, healthcare and higher education, are the ones most exposed, since those environments tend to run older, more heavily customized versions of the software that are slower to patch.
For cloud providers, the claimed AWS GovCloud angle is the detail worth watching most closely. GovCloud is AWS’s isolated region built specifically to meet federal compliance requirements, including ITAR and FedRAMP High. If any lateral movement into that environment is eventually confirmed, even at a limited scale, it would raise hard questions for every agency and contractor that relies on GovCloud’s compliance boundary as a security guarantee rather than just a paperwork one.
For the broader cybersecurity vendor market, incidents like this tend to accelerate budget conversations around identity governance and attack surface management for legacy enterprise software, the same category of tooling covered in comparisons like Tech Insider’s breakdown of how the ransomware and extortion economy actually operates. Expect renewed pressure on federal agencies to accelerate PeopleSoft patch cycles and to audit third-party vendors that touch HR and applicant data specifically.
What Security Researchers and Reporters Are Saying
Coverage of the claim has been notably cautious compared to how quickly some past ShinyHunters breaches were confirmed. The Hacker News and other outlets tracking the group have flagged that, as of publication, no government agency, Oracle, or AWS had independently corroborated the deeper claims about GovCloud access or the full 2-3TB figure. The 5,000-record sample is the only piece of evidence made public so far, and while journalists who reviewed it described consistent, plausible-looking employee data, a sample of that size does not by itself prove the “almost all” employees framing ShinyHunters is using.
That gap between claim and confirmation is exactly why the group’s own quotes matter here as primary source material. Its members are on the record with 404 Media and The Register, using their real messaging to journalists rather than anonymous leak-site posts, which is a shift in how the group has chosen to make its case public this time.
How This Compares to ShinyHunters’ Other 2026 Targets
Set against the group’s other 2026 work, the FBI claim stands out on three axes: sensitivity of the data, motive, and target profile. Corporate victims like McKesson or Carhartt lose customer or employee records that carry financial and identity-theft risk. An FBI employee data set carries that same risk plus a physical safety dimension tied to law enforcement work. On motive, nearly every other 2026 campaign from this group has run on a leak-site countdown clock tied to payment. The FBI case runs on a retraction demand instead. On target profile, a federal law enforcement agency invites a different level of government response than a retailer or healthcare vendor, up to and including potential criminal referrals that private companies rarely pursue as aggressively.
What Happens Next: Legal and Regulatory Paths
The FBI’s own statement leaves the door open on attribution, since it has not said whether the breach point was internal or a third-party vendor supporting FBIJobs.gov. That distinction determines a lot about what comes next. If a vendor is at fault, expect a vendor-breach notification process similar to what played out with the IDScan.net incident, including likely congressional inquiries given the federal law enforcement angle. If the bureau’s own enterprise systems were the entry point, expect an inspector general review and internal FBI cybersecurity audit that could take months to conclude.
Separately, ShinyHunters’ one-week deadline for the FBI to retract its advisory has almost certainly already passed by the time most readers see this story, since the group’s message was reported on September 22. Whether the bureau grants any concession, stays silent, or escalates enforcement action against the group is likely to shape whether ShinyHunters follows through on further data releases.
Predictions: Where This Story Goes From Here
The FBI will not retract its advisory. Federal agencies rarely walk back public threat bulletins under pressure from the group the bulletin describes, since doing so would set a precedent for every future extortion group to demand the same.
More PeopleSoft victims will surface within weeks. Given ShinyHunters’ stated intent to run the same zero-day against Fortune 500 targets, expect additional disclosures from companies running exposed PeopleSoft instances before the end of October.
Oracle will ship an emergency patch. Given the pattern from the June 2026 PeopleSoft campaign, Oracle is likely to issue an out-of-band security update once the specific zero-day is confirmed and disclosed responsibly.
Congressional attention will lag the news cycle. Based on the pattern seen with the IDScan.net driver’s license breach earlier this year, expect a slower and quieter congressional response than the scale of the claim might suggest, at least in the first few weeks.
Verification will take time, not days. Large-scale breach claims involving government systems typically take weeks to independently confirm at full scope, and this one involves at least three parties, the FBI, Oracle and AWS, none of which have moved quickly on similar claims in 2026.
Frequently Asked Questions
Did ShinyHunters actually hack the FBI?
The FBI has confirmed it is investigating a claim from ShinyHunters that the bureau’s FBIJobs.gov portal and related HR systems were compromised, but as of September 24, 2026, the agency has not confirmed the full scope of the claim, including the 2-3TB figure or the alleged AWS GovCloud access.
What data did ShinyHunters claim to steal?
The group says it holds data on nearly all FBI employees and job applicants. A 5,000-record sample reviewed by journalists included names, home addresses, phone numbers, dates of birth, Social Security numbers, and in some cases spouse and emergency contact information.
How did the alleged breach happen?
ShinyHunters says it exploited an undisclosed zero-day vulnerability in Oracle PeopleSoft, the HR and applicant-processing software the FBI uses through its jobs portal, to gain remote code execution and move deeper into bureau systems.
Is this the same group that hit Oracle PeopleSoft earlier in 2026?
Yes. ShinyHunters ran a separate large-scale PeopleSoft campaign in May and June 2026 that hit more than 100 organizations, mostly universities, using a different tracked vulnerability. Researchers believe the FBI intrusion uses a new, previously undisclosed flaw in the same software family.
Why does ShinyHunters say this isn’t about money?
A spokesperson for the group told The Register the hack “is NOT financially motivated.” Instead, ShinyHunters is demanding the FBI retract statements from a Q2 2026 FLASH advisory that described the group’s tactics, which it disputes as inaccurate.
Has the FBI responded to the claim?
The FBI issued a statement acknowledging it is aware of the claim and is actively investigating, including whether the breach originated with a third-party vendor or the bureau’s own systems. It has not confirmed or denied the specific figures ShinyHunters has published.
How does this compare to the 2015 OPM breach?
The 2015 OPM breach, confirmed by the federal government, exposed personnel and background-check records for roughly 21.5 million people, including fingerprint data. The ShinyHunters claim, if fully confirmed, would be smaller in raw record count but similarly sensitive given the direct exposure of law enforcement personnel.
What should current or former FBI employees do?
Security researchers generally recommend that anyone potentially affected by a federal HR data claim monitor credit reports, place a fraud alert or credit freeze with major bureaus, and watch for phishing attempts referencing personal details that would only be known from an HR record, pending official FBI guidance.


