
Anna Moneymaker/Getty Images
ShinyHunters claims FBI data theft, demands bureau retract cyber warning
The hacking group says it obtained sensitive employee and applicant records. The full scope of the claimed breach remains unclear.
The ShinyHunters cybercriminal group claims it has stolen sensitive information about FBI employees and job applicants and is demanding that the bureau retract a public warning about its tactics within a week.
The demand, addressed to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, seeks to pressure the agency into changing its public account of the group’s activities. The group claims the effort was not financially motivated.
In a statement attributed to the group, the hackers claimed access to several FBI services, including human resources systems and a service identified as Medlink.
“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” the statement says.
An FBI jobs page also displayed a “Scheduled Maintenance Underway” notice Tuesday, saying the site was temporarily unavailable. The notice did not identify a security incident or explain whether the outage was related to the hackers’ claims. An earlier version of the webpage appears to show a seizure notice posted by the group.
The language ShinyHunters wants removed appears in a May 15 FBI public service announcement issued after an attack disrupted an online learning management system used by educational institutions.
In the announcement, the FBI warned that ShinyHunters uses harassment to pressure victims, including threatening communications to victims and family members and, in some cases, swatting, the practice of calling in false emergency reports intended to trigger an armed police response at someone’s home. The alert also warned that attackers may exaggerate their access to personal information or falsely claim to possess compromising photographs or videos.
ShinyHunters denied those practices in its statement and gave the bureau one week to correct or remove the warning.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said in a statement after this story was published. Nextgov/FCW has also reached out to the FBI Agents Association, which advocates on behalf of active and retired FBI special agents.
If the claimed employee records are authentic, their exposure could give criminals or foreign intelligence services information useful for identifying, contacting or intimidating FBI personnel and their families.
The claims come as the FBI works to pursue a more coordinated campaign focused on dismantling hackers’ infrastructure and arresting cybercrime operatives. Its new cyber strategy released this month in part emphasizes disrupting criminal hackers even when those responsible remain beyond the immediate reach of U.S. law enforcement.
A ShinyHunters representative sent Nextgov/FCW a text file appearing to contain sensitive personal information on nearly 5,000 FBI employees, including their names, home addresses, phone numbers, and data about their spouses and siblings. Nextgov/FCW queried some of the listed peoples’ names online and found that they are employed with the FBI. The job postings in the data included employees designated as intelligence analysts, attorneys, student trainees and special agents, among other roles. The entire data set was not verified.
A representative told 404 Media, which earlier reported the incident Tuesday, that the hackers gained access Monday night through what they described as a previously unknown vulnerability in Oracle’s PeopleSoft software, then accessed servers in Amazon Web Services’ GovCloud environment. The representative claimed the group took between two and three terabytes of data.
The account of the intrusion has not been independently verified. Nextgov/FCW has asked Oracle and AWS for comment.
Cybersecurity specialists should focus on the group’s claims regarding an exploit in the PeopleSoft platform because it could be used more broadly to breach other systems, said Dan Calderone, the chief technology officer at cybersecurity and AI firm Suzu Labs.
“They also say this isn't financially motivated, but I’d take that with a grain of salt. I have a hard time believing terabytes of FBI personnel data just sit on a shelf,” Calderone said. “Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data.”
On top of that, FBI agents and their spouses “could have their home addresses posted publicly within a week if this threat is followed through,” he added.
Editor’s Note: This story was updated to include a statement from the FBI, remarks from Dan Calderone and additional details about the data allegedly accessed by ShinyHunters.
David DiMolfetta can be reached on Signal via username djd.99
NEXT STORY: Trump wants an ‘AI Force.’ What would that actually look like?




