Estimated reading time: 5 minutes · Last updated:
The FBI is investigating an allegation that a criminal group calling itself ShinyHunters accessed sensitive information tied to its recruitment portal, FBIJobs.gov, and released what a representative described as about 5,000 records. The bureau said it had not yet determined the "point of breach" and that it was working with third-party providers that support the portal. ShinyHunters told FBI Director Kash Patel and assistant cyber-division director Brett Leatherman they were giving the bureau seven days to remove a May advisory that described the group as a threat actor. This account was first reported by The Associated Press.
We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,
ShinyHunters (message directed to FBI Director Kash Patel and Brett Leatherman)
Key takeaways
- ShinyHunters claimed it stole sensitive information and shared a sample of about 5,000 FBI employee and applicant records, according to 404 Media.
- The FBI said it is aware of the claim, has not determined the point of breach, and is investigating with third-party providers that support FBIJobs.gov.
- ShinyHunters said it would give the FBI one week to remove a May advisory that labeled the group a threat actor.
- As of the report, the FBIJobs.gov portal remained offline while the agency investigated the alleged compromise.
Table of contents
- Key takeaways
- What ShinyHunters claims and how it communicated the demand
- What the FBI has said and the investigation's immediate priorities
- How the demand tracks with ShinyHunters’ past disruptive behaviour
- Practical implications for personnel security and recruitment
- How the case could evolve
- What to be careful about
- Frequently asked questions
What ShinyHunters claims and how it communicated the demand
ShinyHunters posted a message directed at FBI leadership that said, in its words, "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." The group told the bureau it was offended by a May public advisory that described ShinyHunters as a data-extortion threat actor and demanded the advisory be removed within one week. The group's message, as published, explicitly framed the demand as a reputational grievance rather than a ransom demand.
404 Media reported that someone claiming to represent ShinyHunters posted an apparent subset of records covering roughly 5,000 people. The outlet said the sample included names, addresses, telephone numbers and some spouse information, although independent verification of the sample's provenance and scope had not been completed at the time of the bureau's statement.
What the FBI has said and the investigation's immediate priorities
The FBI issued a statement saying it was "aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information," and that the agency had not yet identified the "point of breach." The bureau said it was investigating and working closely with third-party providers that support the jobs portal to mitigate risk and that the site was offline during that work.
Investigators will need to determine whether any vulnerability was on an FBI-managed system or in supporting third-party software. 404 Media reported the group claimed to have exploited an apparent vulnerability in Oracle PeopleSoft, a widely used human resources platform, but the FBI has not confirmed that vector. Establishing the technical entry point is the priority for containment and for notifying individuals whose data may be affected.
How the demand tracks with ShinyHunters’ past disruptive behaviour
Cybersecurity lawyer Miriam Wugmeister, who tracks groups such as ShinyHunters, said the group's previous operations make its claim plausible. She pointed to the group's role in a spring hack of Canvas that disrupted thousands of schools and prompted an FBI advisory, and said that pattern — public claims, samples of data and disruptive disclosures — fits the behaviour described in this case.
The group's own message denies financial motives and frames the action as a protest against government characterisation. The May advisory the group challenges described ShinyHunters as a threat actor that often uses claims of access to prompt payment or to harass victims. Whether this instance is a reputational protest or an extortion attempt will hinge on what additional proof the group posts and whether it seeks payment or other concessions.
Practical implications for personnel security and recruitment
If the sample is authentic and includes officers' contact and spouse information, the disclosure has operational and personal-security consequences beyond data privacy. Experts cited in the reporting warned that compromised identities can lead to extortion, swatting or harassment directed at agents or their families. The presence of spouse data in the sample raised particular concern about collateral risk to family members.
The outage of FBIJobs.gov also interrupts the bureau's recruitment pipeline at a moment when public-sector hiring is competitive. Restoring the portal securely and informing any potentially affected applicants will be immediate operational tasks for the bureau and its vendors, alongside the forensic investigation required to validate the claims and scope of exposed records.
| Item | Source/Reporter | Claimed detail |
|---|---|---|
| Sample of records | 404 Media | About 5,000 records (names, addresses, phones, spouse info) |
| Point of breach | ShinyHunters (claim) | Apparent Oracle PeopleSoft vulnerability (unverified) |
| Demand to FBI | ShinyHunters (message) | Remove May advisory within one week |
| FBI status | The FBI (statement) | Investigating; point of breach undetermined; FBIJobs.gov offline |
How the case could evolve
The case for
- Forensic analysis identifies a vendor misconfiguration and the vendor issues a patch quickly, allowing the FBI to restore FBIJobs.gov and limit exposed records.
- ShinyHunters posts no additional proof after the one-week deadline, reducing the likelihood of broad disclosure and giving the FBI time to notify any affected individuals.
The case against
- Further samples are published that verify personal details for agents and applicants, increasing the risk of targeted harassment or extortion against families.
- The investigation finds a systemic PeopleSoft vulnerability in third-party infrastructure that requires extended remediation and prolongs the portal outage.
What to be careful about
- Exposure of spouse and family details increases risk of doxxing, extortion and swatting against agents and their relatives.
- A successful exploitation of Oracle PeopleSoft or another vendor product would amplify the incident beyond recruitment records to other systems using the same software.
- Extended downtime of FBIJobs.gov disrupts recruitment and background-check workflows, delaying hires and creating administrative backlogs.
- Public trust in the bureau's handling of sensitive personnel information could erode if verification and notification are slow or incomplete.
The bottom line
The situation remains fluid: a hacking group has publicly claimed a large exposure and shared a sample that reporting said covered about 5,000 people, while the FBI has opened an investigation and taken its recruitment portal offline. The technical source of any breach must be established before the bureau can confirm scope, notify affected individuals, and remediate systems. For now the key questions are whether further proof appears before the group's self-imposed deadline and whether forensic work will tie the claimed records to a vendor product such as Oracle PeopleSoft or to FBI-managed infrastructure.
What to watch
- Watch whether ShinyHunters posts additional proof or a new message by 30 September 2026, the one-week deadline it set on 23 September 2026.
- Watch for an FBI public update on the investigation; no public date for a status update has been set.
- Watch for vendor advisories from Oracle or any named third-party provider that supports FBIJobs.gov; no specific date has been announced.
Frequently asked questions
Has the FBI confirmed that employee data was stolen?
No. The FBI said it was "aware" of the claim and is investigating but had not determined the "point of breach." Reporting by 404 Media said a ShinyHunters representative provided a sample of about 5,000 records, but the bureau had not independently confirmed that sample when it issued its statement.
What did ShinyHunters demand from the FBI?
ShinyHunters told FBI leadership it wanted a May advisory that labeled the group a threat actor removed and set a one-week deadline after its Sept. 23 message; the group said the action was not financially motivated.
Did the incident involve Oracle PeopleSoft as reported?
404 Media reported that the ShinyHunters representative claimed an apparent vulnerability in Oracle PeopleSoft was used, but the FBI has said it has not determined whether the breach point involved a third party or an FBI enterprise system.
Related reading