Technology

ShinyHunters Claims FBI Breach Exposed Agents and Applicants

Martin HollowayPublished 27m ago4 min readBased on 5 sources
Reading level
ShinyHunters Claims FBI Breach Exposed Agents and Applicants
source:ic3.gov

A hacking group called ShinyHunters says it broke into FBI systems and stole data on thousands of current agents and job applicants. The group made the claim on September 22, 2026.

The claim was posted on ShinyHunters' dark web leak site, a hidden website groups use to publish stolen data, which TechCrunch reviewed. In that post the group claimed to have stolen "sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job" TechCrunch. Reuters also reported on September 22, 2026 that the group known as ShinyHunters says it breached the FBI Reuters.

404 Media first reported the claimed breach after receiving a sample of the material. The sample contained names, home addresses, and phone numbers of FBI agents and their spouses, a portion of which 404 Media verified against public records. That sample covered 5,000 alleged agents 404 Media.

According to 404 Media reporting cited by TechCrunch, the attackers first broke into an Oracle PeopleSoft server, software often used for HR and payroll, and then moved into an Amazon-hosted government cloud system storing agents' and applicants' data TechCrunch. PeopleSoft provided the entry point. The cloud storage held the personnel records.

The public disruption focused on hiring systems. The hackers reportedly defaced the FBI's jobs site apply.fbijobs.gov, including the special agent applicant portal. On September 22, 2026 the site showed "currently down for maintenance."

ShinyHunters said the FBI hack was "not financially motivated" and demanded the FBI remove an IC3 report it says contains false allegations about the group. The group told 404 Media it took terabytes of FBI data and did not say what it would do with the information if the FBI does not take down its published report.

The report at issue is PSA260515, titled "ShinyHunters: Cyber Criminal Group Attacks Learning Management System" IC3. It was published on May 15, 2026. Separately, the FBI had warned organizations about a campaign by cybercriminal groups including Scattered Spider and ShinyHunters to compromise Salesforce platforms, in a notice published September 15, 2025.

TechCrunch described the claimed ShinyHunters incident as the second known breach of an FBI system in 2026, after hackers broke into a system for managing real-time wiretaps and foreign intelligence-gathering warrants.

The broader context here is about design, not just daily operations. When HR-related systems such as PeopleSoft are reachable over a network and have trusted links into cloud storage holding personnel records, an attacker can move sideways from a side system and copy large amounts of personal information at once. Applicant data widens that exposure, because it includes people who never became employees and never went through internal security training or monitoring. How long applicant records are kept, and how separated they are, matters for safety.

In my view, the near-term work for federal IT operators and contractors will be verification. Checking a sample against public records shows a claim is plausible, not that the full scope is confirmed. Full scoping requires comparing PeopleSoft logs, login-system records, cloud access logs, and the amount of data moved against the terabytes claimed. The durable fix is unglamorous. Tighten the connection between older business software and cloud data stores, delete unsuccessful applicant data sooner, and plan for leak-site claims to force notification decisions before an internal investigation ends. Those steps will not stop every break-in, but they limit how much a single entry point can expose.