ShinyHunters Claims FBI Breach and Demands Report Retraction
Share
The cybercrime group ShinyHunters has claimed to have breached FBI systems, alleging they have accessed sensitive information belonging to nearly all FBI agents and job applicants.
The group asserts it has compromised Criminal Justice, HR, and Medlink services. To support these claims, ShinyHunters defaced a subdomain of the agency’s recruitment website, fbijobs.gov, with a message stating the site had been seized. The domain was subsequently taken offline for maintenance.
Demands for Report Retraction
In a statement, the group claimed the attack was a response to an FBI FLASH report issued in May. ShinyHunters argues the report contained false allegations, including claims that the group uses harassment tactics such as swatting or threats to victims’ families.
The hackers have demanded that the FBI correct or remove the report within one week. They specifically denied being “sextortionists” or having any affiliation with a group known as “The Com,” which they described as a fabricated narrative within the cybersecurity industry.
Potential Data Exposure and Technical Details
The FBI has stated it is aware of claims regarding unauthorised activity affecting fbijobs.gov and is currently investigating the matter. The agency has not yet confirmed the extent of the breach or the validity of the theft claims.
To demonstrate the validity of their claims, ShinyHunters provided a sample of data allegedly representing the personal information of 5,000 FBI employees. The sample reportedly included names, phone numbers, and home addresses. While the origin and authenticity of this data have not been independently confirmed, initial reviews suggest the information appears to be legitimate.
The group alleges the breach was executed by exploiting a zero-day vulnerability in Oracle’s PeopleSoft product, through which they claim to have stolen between 2 and 3 terabytes of data. This follows reports from June that the group had been targeting organisations using PeopleSoft vulnerabilities, such as CVE-2026-35273.




Leave a Reply