INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Claims FBI Hack Exposes Almost All Agents
| 2026-09-23 07:13 CRITICAL HIGH CYBERATTACK (GENERAL)
Executive Summary
AI-generated
The FBI is currently investigating claims of unauthorized activity affecting its job portal, [IOC HIDDEN • LOGIN REQUIRED], following a breach allegedly perpetrated by the notorious cybercrime group ShinyHunters. According to reports, the hackers exploited a zero-day vulnerability in Oracle's PeopleSoft product to access sensitive information, including names, phone numbers, and home addresses of nearly 5,000 FBI employees. The stolen data was provided to media outlet 404 Media as evidence, with at least some samples appearing authentic but the origin of the data yet to be confirmed. ShinyHunters claims it breached FBI systems and accessed sensitive information, while denying any affiliation with another group known as The Com. The hackers also framed their statement as an exercise of First Amendment rights rather than an act of ransom or extortion. As a result, 2-3 TB of data was allegedly stolen from the breach, which is believed to have occurred using CVE-2026-35273 vulnerability.
Technical Mitigations AI-generated
• Implementing a robust PeopleSoft security patch management process to prevent exploitation of zero-day vulnerabilities.
• Conducting regular vulnerability assessments and penetration testing on FBI systems to identify potential entry points for attackers like ShinyHunters.
• Utilizing advanced threat detection tools, such as anomaly-based intrusion detection systems (IDS), to monitor network activity and detect suspicious behavior.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
fb•••••.gov
ap•••••.gov
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
CVE-2026-35273CVE-2026-35273
Target & Sectors
Global Scope
educationeducation
technologytechnology
Incident Timeline
2026/09/23
ShinyHunters claimed to have breached the FBI's systems, accessing sensitive information on nearly all agents and job applicants.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
FBI investigating ShinyHunters’ claims
In a statement to the media, the FBI said it is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
ShinyHunters provided
404 Media
with a sample of the stolen data allegedly representing the personal information of 5,000 FBI employees, including names, phone numbers, and home addresses.
The Monday breach, first reported by
404 Media
, allowed ShinyHunters to temporarily deface the FBI jobs site.
The notorious cybercrime and extortion group
ShinyHunters
claims it breached FBI systems and accessed sensitive information.
To demonstrate their claims, they
defaced
a subdomain on the FBI’s jobs website, fbijobs.gov, posting the message “This site has been seized by ShinyHunters”.
In a lengthy statement on its website, ShinyHunters said it was responding to an
FBI FLASH report
from May that made what it called false allegations against the group.
The FBI is investigating an attack on its own systems after ShinyHunters claimed responsibility for the incident, putting the prolific cybercrime group in the most direct conflict yet with agents responsible for investigating data extortion attacks.
ShinyHunters claims attack on FBI exposes almost all agents.
ShinyHunters claims it targeted the FBI in response to a
public service announcement
it says contains false allegations about the group.
The FBI issued the PSA following ShinyHunters’
ShinyHunters doesn’t appear to be seeking a payoff in this case, but rather a bid to coerce the FBI into amending or removing the May PSA.
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report.
ShinyHunters insisted its threats are genuine, denied ever conducting swatting or contacting victims’ families, and denied being “sextortionists”.
The cybersecurity community confirmed in June that ShinyHunters had been
exploiting a PeopleSoft zero-day
to steal data from organizations.
The attack marks a sobering escalation by ShinyHunters, a notorious group that previously targeted major cloud platforms, healthcare organizations,
universities
, technology companies, retailers and education service providers.
“The ShinyHunters ransomware group appears to be actively trying to put a target on their back,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop.
Previous victims of ShinyHunters this year include
Instructure
,
Salesforce
, Snowflake and
McKesson
.
“While ShinyHunters has in the past been hyperbolic about the criticality of the data they’ve accessed, the group has established itself as a legitimate threat,” Flashpoint analysts told CyberScoop.
“This attack benefits ShinyHunters by bolstering their reputation as a credible threat,” the analysts added.
victims
5,000 FBI employees
ShinyHunters provided
404 Media
with a sample of the stolen data allegedly representing the personal information of 5,000 FBI employees, including names, phone numbers, and home addresses.
organisation
Oracle’s
The hackers told 404 Media that they exploited a zero-day vulnerability in Oracle’s PeopleSoft product to breach FBI systems, from which they allegedly stole 2-3 TB of information.
organisation
PeopleSoft
The hackers told 404 Media that they exploited a zero-day vulnerability in Oracle’s PeopleSoft product to breach FBI systems, from which they allegedly stole 2-3 TB of information.
data_breach
2 TB
The hackers told 404 Media that they exploited a zero-day vulnerability in Oracle’s PeopleSoft product to breach FBI systems, from which they allegedly stole 2-3 TB of information.
organisation
Criminal Justice
The hackers claim to have compromised Criminal Justice, HR, and Medlink services, and say they now possess data on nearly all FBI agents and job applicants.
organisation
Halcyon’s
“The ShinyHunters ransomware group appears to be actively trying to put a target on their back,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop.
organisation
CyberScoop
“The ShinyHunters ransomware group appears to be actively trying to put a target on their back,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop.
organisation
First Amendment
The group also denied any affiliation with The Com, calling it a fabricated narrative pushed by the cybersecurity industry, and framed its statement as an exercise of First Amendment rights rather than an act of ransom, coercion, or extortion.
organisation
Canvas
May attack on Instructure, the company behind Canvas, a widely used central hub for K-12 and university coursework, exams and communication.
Tactical Metrics
Metrics
victims
5,000
Fbi Employees
Click for context!
ShinyHunters provided
404 Media
with a sample of the stolen data allegedly representing the personal information of 5,000 FBI employees, including names, phone numbers, and home addresses.
Metrics
data_breach
2
Tb
The hackers told 404 Media that they exploited a zero-day vulnerability in Oracle’s PeopleSoft product to breach FBI systems, from which they allegedly stole 2-3 TB of information.
Intelligence Sources
CyberScoop
2026-09-22
SecurityWeek
2026-09-23
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-05T06:05
Comprehensive Tactical Telemetry
Highly Correlated Entities
7x
organisation
Identified Entity
Oracle’s
entity
4x
industry
Targeted Sector
Media
sector
4x
attribution
Attributing Entity
FBI
authority
3x
tactic
Cyber Operation Type
Extortion
tactic
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
ShinyHunters
actor
general metric
Media
404
media
victims
Fbi Employees
5,000
fbi employees
data breach
Tb
2
tb
vulnerability
Exploited CVE
CVE-2026-35273
cve
general metric
Cve-2026
35,273
cve-2026
source region
Origin Country
United States
country
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.