Join the movement to end censorship by Big Tech. StopBitBurning.com needs donations and support.
Hacker Group Claims Massive Breach of FBI Agent Data
By edisonreed // 2026-09-24
Mastodon
    Parler
     Gab
 
The cybercriminal group ShinyHunters announced on its dark-web leak site Tuesday, Sept. 22, that it compromised the Federal Bureau of Investigation (FBI) and holds sensitive data on almost all FBI agents and individuals who applied to work at the agency, according to the group's post. The group claimed it stole terabytes of information – including names, home addresses and phone numbers – and reportedly released a sample of the purported data and a screenshot of a defaced FBI recruitment website [1]. An FBI spokesperson told 404 Media the bureau was "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating," according to the report [2]. The FBIjobs.gov website and the special-agent applicant portal were temporarily unavailable on Tuesday, officials said. ShinyHunters is described as a prolific hacking and extortion group linked to large-scale data thefts targeting major companies and government organizations. The FBI itself warned about the group in May, issuing a cybersecurity advisory that accused hackers associated with ShinyHunters of using threats, harassment and, in some instances, swatting to target victims [3]. The group's claims remain unverified by independent sources, and the FBI has not confirmed the breach or the scale of the alleged data theft.

Alleged Breach Details

ShinyHunters said the intrusion began with the compromise of an Oracle PeopleSoft server, which runs software commonly used by human resources departments, according to the group's account. The hackers claimed they then moved into an Amazon-hosted government cloud environment containing FBI personnel and applicant data [1]. Neither the FBI nor the companies involved have publicly confirmed that account. The group said the attack was "not financially motivated" and demanded that the FBI remove a cybersecurity advisory published in May that ShinyHunters says contains false allegations about it. ShinyHunters has not said what it plans to do with the purportedly stolen information if the FBI refuses its demand. Reuters reported it was able to find apparent matches for some individuals in a sample of the data but could not establish that the information had actually been taken from FBI systems [3]. The group's claims remain unverified by independent sources, and the FBI has not confirmed the breach or the scale of the alleged data theft.

Verification and Attribution

The FBI has not confirmed the breach or the scale of the alleged data theft, and the group's claims remain unverified by independent sources. Reuters reported it was able to find apparent matches for some individuals in a sample of the data but could not establish that the information had actually been taken from FBI systems [3]. The group has previously been linked to high-profile breaches, including an April data breach of Instructure, the maker of the Canvas school information portal. In this incident, the group claimed to have stolen student and staff data of a total 275 million people [4]. The FBI said it is investigating unauthorized activity affecting FBIjobs.gov, according to the spokesperson's statement to 404 Media, and no further public confirmation has been issued [2]. Officials have not confirmed whether the claimed data came from FBI systems, and the investigation remains active.

Hackers' Demand and FBI Advisory

The FBI's May advisory represents a rare public warning about a specific cybercriminal group. The bureau stated that hackers associated with ShinyHunters have employed intimidation tactics, including swatting, against victims. Swatting involves making false emergency reports to prompt a heavily armed police response at a target's location, a tactic that has resulted in injuries and deaths [2]. The group's demand that the FBI retract its advisory indicates an attempt to use the purported data as leverage. Cybersecurity analysts note that such demands are unusual for financially motivated groups, though ShinyHunters has previously engaged in extortion campaigns. The group has not provided evidence to support its claim that the advisory contains false allegations [3].

Ongoing Investigation

The FBI said it is investigating unauthorized activity affecting FBIjobs.gov, according to the spokesperson's statement to 404 Media, and no further public confirmation has been issued [2]. Officials have not confirmed whether the claimed data came from FBI systems, and the investigation remains active. The incident follows a series of high-profile data breaches this year – including a cyberattack on the Bureau of Alcohol, Tobacco, Firearms and Explosives that was declared a "major incident" [5] – and an Iran-linked breach of FBI Director Kash Patel's personal emails [6]. The FBI has not provided a timeline for the investigation. [1] As the probe continues, the authenticity of ShinyHunters' claims and the potential exposure of FBI personnel data remain unresolved.

References

  1. TechCrunch. "Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data". TechCrunch. September 22, 2026.
  2. NTD. "ShinyHunters Hackers Say They Breached FBI, Stole Data on Bureau Employees". NTD. September 23, 2026.
  3. The Epoch Times. "FBI Investigates Alleged Breach of its Own Applicant Portal". The Epoch Times. September 23, 2026.
  4. TechCrunch. "Instructure strikes deal with hackers who breached it twice". TechCrunch. May 12, 2026.
  5. TechCrunch. "ATF declares 'major incident' as ransomware gang claims hack". TechCrunch. August 27, 2026.
  6. NaturalNews.com. "Iran-linked hackers breach FBI Director Kash Patel's personal emails, release decade-old photos and documents". NaturalNews.com. March 31, 2026.

Explainer Infographic

Mastodon
    Parler
     Gab