ShinyHunters Claims FBI Breach and Theft of Agent, Applicant Data

Cyber extortion group ShinyHunters has claimed it breached the U.S. Federal Bureau of Investigation and obtained sensitive data relating to current and former FBI employees, as well as people who applied for FBI jobs. The group said the alleged compromise affected Criminal Justice, HR, Medlink and other FBI services, while the FBI said it was investigating claims of unauthorized activity affecting FBIjobs.gov.
The claim, first reported by 404 Media, has not been independently verified. ShinyHunters said it held information on “almost ALL FBI Agents” and job applicants. FBIjobs.gov later displayed a maintenance message: “Scheduled Maintenance Underway. We're Sniffing Out Site Updates for You!”
Claim centers on an alleged PeopleSoft zero-day
A ShinyHunters spokesperson told The Register that the group gained remote code execution through a new Oracle PeopleSoft zero-day and used access to deface the FBI jobs site with a message claiming the site had been seized. No details have been published for a pre-authenticated PeopleSoft remote-code-execution zero-day.
The group had weaponized a similar PeopleSoft vulnerability, CVE-2026-35273, in June 2026 to enter enterprise networks and extort victims. That earlier activity does not establish the method used in the alleged FBI incident, but it gives context to the attackers’ public claim.
In a statement shared with Reuters, the FBI said it was aware of the claims concerning FBIjobs.gov and was investigating. The agency did not confirm a breach, the nature of any affected data, or the intrusion route described by ShinyHunters.
A public confrontation with law enforcement
ShinyHunters said it targeted the FBI after the agency issued a May 2026 public service announcement about the group’s targeting of Canvas, an online learning management system, and advised victims not to pay. The attackers rejected that warning as false allegations and disputed assertions that they are part of The Com decentralized collective.
The disclosure followed another high-profile move by the group: the hijacking of the dark-web leak site used by the Clop, also known as Cl0p, ransomware operation. Etay Maor, vice president of threat intelligence at Cato Networks, described a cybercrime group publicly claiming an FBI compromise as an unusually provocative development in the contest between law enforcement and criminal operators.
Maor also noted that ShinyHunters has persisted through takedowns, arrests and forum seizures by changing methods and attracting new operators. He described a recent playbook focused on trusted identity paths, including help-desk social engineering, malicious OAuth applications and stolen SaaS integration tokens, rather than only technical perimeter breaches.
What organizations should examine
The FBI claim remains an allegation, and the stated vulnerability has not been detailed. Still, the case reinforces the need to assess the systems and relationships that can turn a single trusted access path into broad organizational exposure.
- Review access controls and patch status for HR, recruitment and other internet-facing enterprise applications.
- Inventory OAuth applications and SaaS integration tokens, then remove unused or excessive permissions.
- Test help-desk identity-verification procedures against social-engineering scenarios.
- Prepare incident-response procedures for defacement claims and potential exposure of applicant or employee information.
For businesses and public-sector agencies, the practical implication is to treat identity workflows, integration tokens and third-party trust relationships as critical security controls alongside vulnerability management.

