ShinyHunters Claims FBI Data Theft With an Unusual Motive

It's not about the money.
Lily Morris
Contributing Writer

ShinyHunters claims it breached FBI systems and obtained sensitive information on nearly all FBI employees and people who applied for jobs at the agency. The allegedly stolen records include names, home addresses, phone numbers, dates of birth, applicant information, and details about employees’ spouses.

FBI officials have confirmed an investigation into claims of unauthorized activity affecting FBIjobs.gov.

The hackers say they exploited a zero-day vulnerability in Oracle PeopleSoft, gained access to AWS GovCloud servers, and exfiltrated between two and three terabytes of data. A sample containing 5,000 alleged FBI employee records was partially corroborated using open-source intelligence and compromised-data tools.

Claims about the full size and contents of the stolen dataset remain unverified.

Why It Matters: A breach that starts in HR software and reaches government cloud infrastructure shows how an overlooked enterprise system can open a path to highly sensitive data. It raises a larger security concern around how much access any single application can provide once compromised. Personnel data makes that exposure difficult to contain because much of it cannot be changed after it is stolen.

  • Parts of the Stolen Dataset Appear to Be Authentic: ShinyHunters provided a sample containing alleged personal information for 5,000 FBI employees. Checks of some records found phone numbers corresponding to the people named in the files, while others were linked to Justice Department personnel. ShinyHunters claims it has information on nearly all FBI employees and applicants, though the full scope has yet to be independently verified.
  • The Claimed Intrusion Began With Oracle PeopleSoft: ShinyHunters says a zero-day vulnerability in the enterprise software gave it an initial foothold. The hackers say they then accessed AWS GovCloud servers and downloaded between two and three terabytes of information. The FBI jobs site was also defaced with a fake seizure notice, while its job application portals became unavailable. The FBI says it is investigating unauthorized activity affecting FBIjobs.gov.
  • The Stolen Information Could Create Long-Term Security Risks: The alleged dataset contains home addresses, phone numbers, dates of birth, spouse information, and applicant records. Such information could be used for social engineering, harassment, tracking, or coercion. Criminals associated with the same hacking ecosystem have previously used stolen telecommunications records to track and intimidate FBI investigators. Personnel records could also help foreign intelligence services identify FBI employees and their family connections.
  • The Hackers Say Money Is Not Their Objective: ShinyHunters has previously stolen corporate data and sought payment from victims, yet the group says this FBI operation is “not financially motivated.” It is demanding that the FBI correct or remove a report accusing the group of exaggerating access to pressure victims into paying, threatening victims and their families, and carrying out swatting attacks. ShinyHunters gave the FBI one week to respond and called its planned pressure campaign “coercion.”
  • The Incident Follows Other FBI Security Compromises Reported in 2026: Earlier this year, unidentified hackers reportedly accessed an FBI system used to manage real-time wiretaps and foreign-intelligence surveillance warrants, potentially revealing surveillance targets. In a separate incident, the Iran-linked Handala group claimed it hacked and leaked FBI Director Kash Patel’s personal email. The ShinyHunters case puts attention on how ordinary enterprise applications can contain data with consequences far outside the business function they were built to serve.

Go Deeper -> ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees – 404 Media

Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data – TechCrunch

Cybersecurity updates, executive insights, and the stories shaping the enterprise.

Browse past editions of TNCR newsletters. 

Technology news, cybersecurity, & executive insights.

×
You have free article(s) left this month courtesy of the CIO Professional Network.

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Would You Like To Save Articles?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Thanks for subscribing!

We’re excited to have you on board. Stay tuned for the latest technology news delivered straight to your inbox.

Save My Spot For TNCR LIVE!

Thursday April 18th

9 AM Pacific / 11 PM Central / 12 PM Eastern

Register for Unlimited Access

Already a member?

Digital Monthly

$12.00/ month

Billed Monthly

Digital Annual

$10.00/ month

Billed Annually

Would You Like To Save Books?

Enter your username and password to access premium features.

Don’t have an account? Join the community.

Log In To Access Premium Features

Sign Up For A Free Account

Name
Newsletters