A hacking group called ShinyHunters claims it has breached multiple FBI-related services and stolen data on all FBI employees and applicants, according to statements made to 404 Media.

According to a ShinyHunters representative, the stolen data includes FBI agents’ names, home addresses, phone numbers, and information on their spouses. The group provided 404 Media with a sample file allegedly containing personal data on 5,000 FBI employees, including addresses, phone numbers, dates of birth, and spouse details. When 404 Media verified some of the sample phone numbers using open-source intelligence tools, they found matches corresponding to people with the same names listed in the files.
The group also defaced the FBI jobs website on Tuesday, posting a message stating “this site has been seized by ShinyHunters.” The defacement claimed that “all FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information.” The FBI jobs website displayed an unavailability message at the time of reporting.
According to the ShinyHunters representative, the group exploited a zero-day vulnerability in Oracle’s PeopleSoft software to gain access to AWS GovCloud servers, from which they downloaded between two and three terabytes of data.
An FBI spokesperson confirmed to 404 Media that “the FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
The breach carries significant security implications. According to 404 Media, criminals in the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass FBI agents investigating them. The sensitive data could also interest foreign intelligence agencies seeking to understand how the FBI operates, and if it reaches other criminals, FBI agents and their families could face serious safety threats.
ShinyHunters typically attempts to extort compromised organizations by threatening to release more data unless they pay a ransom. When asked about extortion, the representative said what the group “plan[s] to do is not something I’d call extortion, maybe coercion,” and stated “this is not financially motivated.” In a post on its leak website, ShinyHunters claimed the FBI made “false allegations” in a previous report and gave the FBI “a time of 1 week” to correct or remove it.
Key facts
- ShinyHunters claims to have breached FBI services and stolen data on all FBI employees, applicants, and their families
- The stolen data allegedly includes names, addresses, phone numbers, dates of birth, and spouse information
- A sample of 5,000 employee records was provided to 404 Media and verified using open-source intelligence tools
- The group exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers
- Between two and three terabytes of data were allegedly exfiltrated
- The FBI jobs website was defaced and became unavailable
- An FBI spokesperson confirmed the agency is investigating the claims
