Download Privacy Needle App

Type to search

Cybersecurity

ShinyHunters Claims FBI Breach and Demands Report Retraction

Share

The cybercrime group ShinyHunters has claimed to have breached FBI systems, alleging they have accessed sensitive information belonging to nearly all FBI agents and job applicants.

The group asserts it has compromised Criminal Justice, HR, and Medlink services. To support these claims, ShinyHunters defaced a subdomain of the agency’s recruitment website, fbijobs.gov, with a message stating the site had been seized. The domain was subsequently taken offline for maintenance.

Demands for Report Retraction

In a statement, the group claimed the attack was a response to an FBI FLASH report issued in May. ShinyHunters argues the report contained false allegations, including claims that the group uses harassment tactics such as swatting or threats to victims’ families.

The hackers have demanded that the FBI correct or remove the report within one week. They specifically denied being “sextortionists” or having any affiliation with a group known as “The Com,” which they described as a fabricated narrative within the cybersecurity industry.

Potential Data Exposure and Technical Details

The FBI has stated it is aware of claims regarding unauthorised activity affecting fbijobs.gov and is currently investigating the matter. The agency has not yet confirmed the extent of the breach or the validity of the theft claims.

To demonstrate the validity of their claims, ShinyHunters provided a sample of data allegedly representing the personal information of 5,000 FBI employees. The sample reportedly included names, phone numbers, and home addresses. While the origin and authenticity of this data have not been independently confirmed, initial reviews suggest the information appears to be legitimate.

The group alleges the breach was executed by exploiting a zero-day vulnerability in Oracle’s PeopleSoft product, through which they claim to have stolen between 2 and 3 terabytes of data. This follows reports from June that the group had been targeting organisations using PeopleSoft vulnerabilities, such as CVE-2026-35273.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.