FBI Investigates Alleged Breach by ShinyHunters
The FBI is investigating claims that the cybercriminal group ShinyHunters breached its jobs portal and stole sensitive data belonging to thousands of agents and job applicants. The incident, which reportedly involved exploiting vulnerabilities in Oracle PeopleSoft and an Amazon-hosted government cloud, highlights growing risks in cybersecurity and counterintelligence.
LazyFounders

The FBI is investigating claims that the cybercriminal group ShinyHunters breached its jobs portal and stole sensitive data belonging to thousands of agents and job applicants. The incident, which reportedly involved exploiting vulnerabilities in Oracle PeopleSoft and an Amazon-hosted government cloud, highlights growing risks in cybersecurity and counterintelligence.
30 SEC SUMMARY
- ShinyHunters, a cybercriminal group, claims to have breached the FBI and stolen sensitive data of thousands of agents and job applicants.
- The FBI confirmed unauthorised activity on its jobs website and is investigating the incident.
- The breach allegedly involved hacking an Oracle PeopleSoft server and accessing an Amazon-hosted government cloud.
- ShinyHunters demands the FBI remove a report it claims contains inaccurate allegations about the group.
- This is the second major breach of FBI systems in 2026, following an April incident involving China-associated hackers.
TABLE OF CONTENTS
- What happened?
- FBI’s response
- Unusual demands
- Why this matters
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- ShinyHunters claims to have breached the FBI and stolen sensitive data of thousands of agents and job applicants.
- The FBI confirmed unauthorised activity on its jobs website and is investigating the incident.
- The breach allegedly involved hacking an Oracle PeopleSoft server and accessing an Amazon-hosted government cloud.
- ShinyHunters demanded the FBI retract a report it claims contains inaccurate allegations about the group.
- This is the second major breach of FBI systems in 2026, following an April incident involving China-associated hackers.
What happened?
According to reports from Mint (Technology) and The Next Web, the cybercriminal group ShinyHunters claims to have breached the FBI’s jobs portal, FBIjobs.gov, and stolen sensitive data belonging to thousands of FBI agents and job applicants. The group alleges it accessed terabytes of information, including names, home addresses, phone numbers, and details about agents’ spouses.
The breach came to light on September 22, 2026, after 404 Media received a sample of the stolen data, covering approximately 5,000 purported agents. The outlet confirmed some of the data against public records, lending credibility to the claims.
ShinyHunters reportedly exploited a vulnerability in Oracle PeopleSoft, a human resources software platform used by the FBI for recruitment and HR management. The group claims it then gained access to an Amazon-hosted government cloud where the data was stored.
FBI’s response
The FBI acknowledged unauthorised activity on its jobs website and confirmed it is investigating the incident. However, the agency has not verified the extent of the breach or the claims made by ShinyHunters. In a statement, the FBI noted that its special agent applicant portal and job site were temporarily defaced and taken offline during the incident.
Politico reported that two sources with knowledge of the breach consider the claims credible, describing the incident as a "significant counterintelligence failure." The FBI has not provided further details in response to media requests.
Unusual demands
Unlike typical ransomware attacks, ShinyHunters has not demanded a financial payment. Instead, the group is asking the FBI to retract or remove a report it claims contains inaccurate allegations about the group. The report in question was published by the FBI in May 2026, detailing ShinyHunters’ methods following an attack on the Canvas learning platform, which disrupted thousands of schools and universities.
ShinyHunters told 404 Media that the breach was intended to force the FBI to "correct or simply remove" the report. The group has not disclosed what it will do if the FBI refuses its demand.
Why this matters
The breach is the second major incident involving FBI systems in 2026. In April, China-associated hackers gained access to a wiretapping system, raising concerns about the agency’s ability to protect sensitive data.
If confirmed, this breach could have severe counterintelligence implications. Personal information of FBI agents and their families could be used for harassment, coercion, or recruitment by adversarial actors. The incident also highlights the risks of relying on third-party software and cloud providers for handling sensitive data.
What this means
LazyFounders analysis — our interpretation, not reported fact.
For founders and operators, this incident is a stark reminder of the vulnerabilities even the most secure organisations face. First, it underscores the importance of securing third-party software and cloud environments—especially when handling sensitive data. Oracle PeopleSoft and Amazon’s government cloud were reportedly exploited, highlighting how supply chain and infrastructure risks can cascade into major breaches.
Second, the demand for a retraction rather than a ransom payment is unusual and suggests ShinyHunters may be motivated by reputation or operational disruption rather than financial gain. This could signal a shift in cybercriminal tactics, where attackers increasingly weaponise data to achieve non-financial objectives.
Finally, the breach’s counterintelligence implications are severe. Exposure of personal details of agents and applicants could enable harassment, coercion, or even recruitment by adversarial actors. For startups, this reinforces the need for robust data minimisation practices, encryption, and access controls—especially if handling sensitive or regulated data.
Key takeaways
- ShinyHunters claims to have breached the FBI’s jobs portal, stealing sensitive data of agents and applicants.
- The FBI confirmed unauthorised activity and is investigating, but has not verified the extent of the breach.
- The attackers allegedly exploited a vulnerability in Oracle PeopleSoft and accessed an Amazon-hosted government cloud.
- ShinyHunters is demanding the FBI retract a report it claims contains inaccurate allegations, rather than seeking a ransom.
- This is the second major FBI breach in 2026, following an April incident involving China-associated hackers.
FAQ
What data did ShinyHunters allegedly steal?
The group claims to have stolen terabytes of sensitive information, including names, home addresses, phone numbers, and details about the spouses of FBI agents and job applicants.
How did ShinyHunters allegedly breach the FBI?
ShinyHunters reportedly exploited a vulnerability in Oracle PeopleSoft, a human resources software platform, and then accessed an Amazon-hosted government cloud where the data was stored.
What is ShinyHunters demanding from the FBI?
Instead of a ransom, ShinyHunters is demanding that the FBI retract or remove a report it claims contains inaccurate allegations about the group.
Has the FBI confirmed the breach?
The FBI confirmed unauthorised activity on its jobs website and is investigating the incident, but it has not verified the extent of the breach or ShinyHunters’ claims.
Related on LazyFounders
Sources
- Mint (Technology) · 2026-09-23
FBI hacked? ShinyHunters claims brazen theft of sensitive agent data — what the cybercriminal group wants - The Next Web · 2026-09-23
FBI investigating claims that ShinyHunters stole data on its agents
This story is an original summary and analysis written by LazyFounders from the reporting listed above. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's opinion. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links.


