ShinyHunters claims an FBI breach and defaces FBIjobs.gov — what's confirmed and what's only claimed
By Sethu Satheesh · 29 Sept 2026 · 11 min read
Threat Actor: ShinyHunters (self-identified extortion group) · Target: U.S. Federal Bureau of Investigation — FBIjobs.gov recruitment portal; claimed agent and applicant data
Source: thehackernews.com
Executive Summary
On September 22, 2026, the extortion group ShinyHunters claimed it had breached the U.S. Federal Bureau of Investigation, defaced the bureau's recruitment portal FBIjobs.gov, and stolen roughly two terabytes of data on "almost all" FBI agents and job applicants.123 As with any ShinyHunters claim, the gap between what is observable, what an outlet has partly verified, and what remains only the group's assertion is the whole story — and here that gap is unusually wide because the target is the FBI.
What is established. FBIjobs.gov and its special-agent applicant portal went offline around the time of the claim; a web archive showed the site displaying a maintenance notice, and ShinyHunters says it defaced the portal with a "This site has been seized by ShinyHunters" banner, reported by 404 Media.12 The FBI acknowledged the incident, stating it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," and — in a fuller statement — that it is "aware of a cyber-criminal enterprise group claiming a compromise" while noting that "the point of breach is still undetermined — whether a third-party or the FBI's enterprise."12 And 404 Media reported that a sample of the leaked data — names, home addresses and phone numbers — checked out against public records.2
What is only claimed. ShinyHunters says it exploited a new Oracle PeopleSoft zero-day for remote code execution on a server used for HR and recruitment, then pivoted to an Amazon-hosted government cloud holding agents' and applicants' data.1 It claims the haul spans systems it names as PEGA, Medlink, FBIJOBS, HR, CJ and PHIRE — including a "Medlink" database of agents' medical records, prescriptions and diagnoses — and covers names, agent statuses, emails, phone numbers, home addresses and, in some cases, spouses' information including Social Security numbers.12 None of this — the scale ("almost all" agents, ~2 TB), the medical data, the PeopleSoft zero-day, or the cloud pivot — has been independently verified, and the FBI has not confirmed that any FBI system was breached at all, only that a group is claiming a compromise whose origin is undetermined.12
The motive ShinyHunters gives is not financial. The group frames the operation as retaliation for a May 2026 FBI public service announcement that described ShinyHunters' targeting of the Canvas learning-management platform and urged victims not to pay — which the group calls "substantial false allegations" and "disinformation" — and it says it is demanding the FBI remove that report.12 That reframes the incident: a criminal group attempting to coerce a federal agency into retracting a warning about the group itself, using a claimed breach as leverage.
For a defensive publication, the responsible position is the one the FBI itself has taken: a compromise is being claimed, a sample of the data is consistent with real people, the recruitment portal was visibly affected, and everything else — including whether the FBI's own systems were breached — is under investigation and unproven. The verified facts are serious enough on their own; the unverified ones, if taken as settled, would overstate what anyone outside the FBI and ShinyHunters currently knows.
Verification of Claims
-
Claim: FBIjobs.gov was defaced / taken offline in connection with a claimed compromise. → Verified → The recruitment portal and special-agent applicant portal went offline; a web archive showed a maintenance notice, ShinyHunters claims a "This site has been seized by ShinyHunters" defacement (reported by 404 Media), and the FBI acknowledges "unauthorized activity affecting FBIjobs.gov."12
-
Claim: ShinyHunters breached the FBI and stole ~2 TB of data on almost all FBI agents. → Unverified → The FBI says it is aware of the claim and that "the point of breach is still undetermined — whether a third-party or the FBI's enterprise."1 404 Media verified only a sample of the leaked data (names, addresses, phone numbers) against public records — not its FBI origin, nor the "almost all agents" / ~2 TB scale.2
-
Claim: The breach exploited a new Oracle PeopleSoft zero-day and pivoted to an Amazon-hosted government cloud. → Unverified → This is ShinyHunters' own account of its method; no vendor, agency or outlet has confirmed a PeopleSoft zero-day or the cloud pivot, and the FBI says the point of breach is undetermined.12
-
Claim: The stolen data includes agents' medical records (a "Medlink" database) and spouses' Social Security numbers. → Unverified → These specific data categories are ShinyHunters' claims and have not been independently confirmed.1
-
Claim: The operation is financially motivated. → False (per the group's stated motive) → ShinyHunters says it is not seeking payment but demanding the FBI retract a May 2026 report about the group's Canvas activity.12
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| May 2026 | FBI | Publishes a public service announcement describing ShinyHunters' targeting of the Canvas learning-management platform and urging victims not to pay | 12 |
| September 22, 2026 | ShinyHunters | Claims it breached the FBI, defaced FBIjobs.gov ("This site has been seized by ShinyHunters"), and stole ~2 TB on almost all agents and applicants; demands the FBI retract the May report | 12 |
| September 22, 2026 | FBI | Acknowledges awareness of claims of unauthorized activity affecting FBIjobs.gov; says the point of breach is undetermined and it is investigating | 12 |
| September 22, 2026 | 404 Media / press | FBIjobs.gov observed offline/defaced; a sample of the leaked data confirmed against public records | 2 |
Attack Anatomy
The defacement/outage is observed; the intrusion chain below is ShinyHunters' claimed method, which the FBI has not confirmed (it says the breach point is undetermined).
Claimed initial access — PeopleSoft zero-day
ShinyHunters says it exploited a new Oracle PeopleSoft zero-day to gain remote code execution on a server used for HR and recruitment (T1190).1 No CVE or vendor advisory corroborates this, and it is the group's own account.12
Claimed escalation — pivot to government cloud
From the PeopleSoft foothold, ShinyHunters claims it pivoted to an Amazon-hosted government cloud storing agents' and applicants' data (T1530, T1213).1 Unverified.
Observed — defacement and outage
FBIjobs.gov and the special-agent applicant portal went offline; ShinyHunters claims a "This site has been seized by ShinyHunters" defacement, reported by 404 Media, and the FBI acknowledges unauthorized activity affecting the site (T1491.002).12
Extortion, not payment
ShinyHunters frames the operation as coercion — demanding the FBI retract its May 2026 Canvas report — rather than a ransom for money.12
Loading diagram...
Threat Actor Profile
- Attacker: ShinyHunters — a long-running data-theft and extortion group, self-identified in the defacement and in statements to media.12 It has been prolific in 2026, and this claim follows a public FBI warning about the group's Canvas activity.1
- Attribution confidence: The defacement and the claim are attributable to ShinyHunters (self-identified). Whether ShinyHunters actually breached the FBI — as opposed to a third party, or possessing data of other provenance — is exactly what the FBI says remains undetermined.1
- Motivation: Coercion / reputation, not payment: the group demands the FBI retract a report about it, and frames the report as false. This is an attempt to use a claimed breach to suppress law-enforcement reporting on the group.12
- Assessment: Extortion actors have a standing incentive to maximise the perceived scale and sensitivity of what they hold ("almost all agents," medical records, spouse SSNs). A partial public-records match on a sample is consistent with real data but does not establish an FBI-source breach or the claimed scope.2
MITRE ATT&CK techniques (the initial-access and collection entries reflect ShinyHunters' claimed method, which is unconfirmed; only the defacement is observed):
| ID | Technique |
|---|---|
| T1190 | Exploit Public-Facing Application (claimed PeopleSoft zero-day) |
| T1530 | Data from Cloud Storage (claimed government-cloud pivot) |
| T1213 | Data from Information Repositories (claimed HR/PeopleSoft data) |
| T1491.002 | Defacement: External Defacement (observed on FBIjobs.gov) |
Technical Indicators
# This is a claimed government breach in an active-investigation state. The only
# observed artifact is the FBIjobs.gov defacement/outage; the mechanism and data
# claims are the attacker's and are unverified.
observed:
- "FBIjobs.gov and special-agent applicant portal offline; maintenance notice in web archive"
- "defacement banner: 'This site has been seized by ShinyHunters' (reported by 404 Media)"
partially_verified:
- "a sample of leaked data (names, home addresses, phone numbers) matched public records (404 Media) — source and scope not confirmed"
claimed_unverified:
- "~2 TB stolen; data on 'almost all' FBI agents and applicants"
- "systems named: PEGA, Medlink, FBIJOBS, HR, CJ, PHIRE"
- "Medlink medical records/prescriptions/diagnoses; spouse info incl. SSNs"
- "initial access via a new Oracle PeopleSoft zero-day (RCE); pivot to an Amazon-hosted government cloud"
fbi_position: "aware of claims; point of breach undetermined (third-party or FBI enterprise); investigating"
motive: "coercion — demanding the FBI retract its May 2026 report on ShinyHunters' Canvas activity"
network_iocs: none disclosed
file_hashes: none disclosedLegal and Regulatory Response
The FBI has publicly acknowledged the matter and stated it is investigating, while explicitly declining to confirm that its own enterprise was breached: it says the point of breach is undetermined and could be a third party.12 No indictment, arrest, or formal attribution has followed at this stage. The incident is unusual in that the extortion demand is not for money but for the retraction of an FBI report about the extortion group — a demand the bureau has not indicated it will entertain.12
Impact Assessment
- Verified: FBIjobs.gov and its applicant portal were affected/offline; ShinyHunters claimed and (per 404 Media) displayed a defacement; the FBI is investigating.12
- Partially verified: A sample of the leaked data matched public records, indicating at least some real personal data — of unconfirmed source and scope.2
- Claimed, unverified: ~2 TB of data on almost all FBI agents and applicants; medical records; spouse SSNs; a PeopleSoft zero-day and government-cloud pivot; that the FBI's own systems (rather than a third party) were breached.12
- Unknown: Whether any FBI system was actually compromised; the true source, scope and sensitivity of the data; and whether the affected individuals face concrete risk. The FBI's investigation is ongoing.1
Lessons and Defensive Recommendations
For threat intelligence and IR teams:
- Hold the line the FBI drew: a claimed compromise with an undetermined breach point is not a confirmed agency breach. A public-records match on a sample proves some data is real; it does not prove the data came from the claimed victim, nor validate the attacker's scale or method. Track this as "ShinyHunters claims an FBI breach; FBI investigating; sample partially corroborated" — not "FBI breached."
- The claimed vector — an Oracle enterprise-application zero-day (here PeopleSoft) as the entry to HR/recruitment data — is a pattern worth monitoring regardless of whether it is true in this case, given the broader 2026 targeting of Oracle enterprise applications. Prioritise patching and monitoring of internet-reachable Oracle HR/ERP systems and the identity paths from them into cloud data stores.
For government and enterprise disclosure teams:
- The FBI's wording is a model for responding to an unverified breach claim: acknowledge awareness, state plainly what is undetermined, and commit to investigating — without confirming scope or source before the evidence supports it. Naming what you do not yet know is what keeps an attacker's claim from becoming the public record by default.
For readers:
- An extortion group demanding that a law-enforcement agency retract a report about that same group is a reason for more scepticism, not less, about the group's claims. The breach may prove real and serious; today, most of its alleged substance is the group's own assertion, and should be read as such.
Sources
Footnotes
-
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants — The Hacker News, September 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29
-
Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data — TechCrunch, September 22, 2026 (includes the FBI statement and 404 Media's sample verification) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26
-
ShinyHunters hackers say they breached FBI, stole data on bureau employees — CNBC, September 22, 2026 ↩
Related Research
Dutch police arrested a 24-year-old Amsterdam man on Sept 15, 2026 in the ShinyHunters investigation; a Rotterdam court remanded him 90 days, and the FBI called him an 'alleged leader.' A separate inquiry into two planned murders abroad is, police say, not part of the ShinyHunters case.
ShinyHunters defaced the Clop ransomware gang's Tor leak site with its Umbreon logo and claims it stole the source code, /var/log, and Clop's onion private keys — retaliation over the 2025 Oracle EBS exploit dispute. Only the defacement is independently confirmed; the theft claims are not.
ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.