ShinyHunters Claims FBI Breach via Zero-Day, Threatens to Leak Agent Data
4:51
author photo
By SecureWorld News Team
Thu | Sep 24, 2026 | 1:54 PM PDT

The cyber extortion group ShinyHunters says it breached the FBI's network and stole personal data on thousands of current, former, and prospective employees. The FBI is investigating but has not confirmed where, or whether, its systems were breached.

What the hacking group is claiming

ShinyHunters says it got in on Monday, September 21, and announced the breach on its dark web site the next day. It claims to hold data on nearly all FBI agents and job applicants, drawn from FBI PEGA, Medlink, FBIJOBS, HR, CJ, and PHIRE, and possibly other internal services. It told Axios the data include names, agent statuses, emails, phone numbers, home addresses, and sometimes spouse information including Social Security numbers.

How the attackers say they got in

The group says it found a new zero-day in Oracle PeopleSoft Monday night and immediately used it for remote code execution. It says it then moved into FBI-managed AWS GovCloud servers and downloaded roughly 2 to 3 terabytes of data. It also says the flaw remains unpatched and that it plans to use it against other targets. FBI documents confirm the bureau's recruiting arm uses both PeopleSoft and AWS GovCloud. The group also defaced part of FBIJobs.gov, which remains offline.

What's known about the vulnerability

No public CVE or vendor confirmation exists for the claimed new flaw. ShinyHunters previously exploited CVE-2026-35273, a critical PeopleTools remote code execution flaw, as a zero-day against more than 100 organizations, mostly in higher education, before Oracle patched it on June 10, 2026. If the new claim is accurate, systems patched for that flaw could still be exposed.

The FBI's response and what has been verified

In a September 23 statement, the FBI acknowledged the claimed compromise of FBIJobs.gov and alleged impact to employee PII. It said it has not determined whether the point of breach is a third party or its own enterprise.

404 Media received a sample allegedly covering 5,000 employees, and reviewers say at least some of it appears to be authentic. Reuters found matches in at least 10 instances, including FBI Director Kash Patel. A former FBI agent confirmed a sample document to NBC News.

The stated motive

The group says the attack is retaliation, not a moneymaking effort. It points to a May 2026 FBI public service announcement about its attack on the Canvas learning platform. It gave the FBI one week from its September 22 post to correct or remove that report, and has declined to say whether it will release the data if the bureau doesn't comply.

[RELATED: ShinyHunters Hits Canvas Again: 275M Records at Risk Across 9K Schools]

Expert perspectives

Reacting to the group's claims, VJ Viswanathan, Founding Partner at CYFORIX, a research-driven strategic risk advisory and intelligence analysis firm, said:

"Targeting the FBI isn't just a data breach—it's a calculated, asymmetric escalation. When a group like ShinyHunters pivots from corporate extortion to directly retaliating against federal law enforcement via zero-day vectors in enterprise platforms like PeopleSoft, it serves as a sobering reminder: fortress mentalities are obsolete in modern cybersecurity.

The real crisis here isn't just the 2 terabytes of exfiltrated data: it's the human risk vector. Exposing the personally identifiable information (PII), home addresses, and family details of federal agents creates compounding national security vulnerabilities. This shifts the threat landscape from digital remediation to physical and operational threat mitigation. It's a stark reminder that software supply chain hygiene and timely application hardening and patching remain critical blind spots."

Col. Cedric Leighton, CNN Military Analyst, U.S. Air Force (Ret.), said:

"This hack reminds me in some ways of the hack of the federal government's Office of Personnel Management (OPM), which was publicly announced back in 2015. At that time, some 21.5 million people had their government personnel or security clearance records breached, so this breach is much smaller in that it impacts only 37,000 FBI personnel. But what's key here is the type of people who are being impacted, and that's where the targets of the two breaches are similar. If the personally identifiable information of FBI agents is revealed, it will not only potentially impact their personal safety, but it can also damage the bureau's ability to carry out counterintelligence operations as well as criminal investigations. There's nothing worse than a security breach with national security implications that also puts the lives of agents at risk while they are doing their jobs."

Comments