Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

Cybercriminal group ShinyHunters claims to have breached an FBI Oracle PeopleSoft server and an Amazon-hosted government cloud. The attackers assert they stole sensitive data concerning thousands of agents and applicants. Media outlets verified a portion of the stolen records against public records, while the agency has not yet responded.

Cover image for Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

ShinyHunters says it penetrated an Oracle PeopleSoft server used for human‑resources functions and then moved into an Amazon‑hosted government cloud that stored information on FBI personnel and job applicants. The claim is based on a dark‑web leak site that TechCrunch examined, which includes names, home addresses and phone numbers. Media verification matched a portion of the leaked records against public data, but the agency has not confirmed the breach. The alleged breach covers thousands of FBI agents, their spouses and individuals who filed applications for FBI positions. 404 Media first reported the incident after receiving a sample of the stolen data. The exposure could create a counter‑intelligence risk if foreign actors exploit the personal details for coercion or extortion. The hackers state the intrusion is not financially motivated and are demanding the removal of a report they consider false. No public response from the FBI has been recorded, and the agency’s jobs portal was reported as “currently down for maintenance” after the defacement. Uncertainty remains about how the stolen terabytes will be used if the demand is not met.