FBI Headquarters showing security breach

ShinyHunters Hacks the FBI in a Security Breach Exposing Personal Information of 38,000 People

The Federal Bureau of Investigation (FBI) has launched a probe into a security breach after the prolific hacking group ShinyHunters claimed to have exfiltrated sensitive personal information.

According to the group, the data breach affected current and former staff members, as well as everyone who had applied for a job at the bureau.

“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” ShinyHunters stated.

Security breach at the FBI exposes sensitive personal information

The security breach exposed the victims’ names, addresses, Social Security Numbers, phone numbers, badge numbers, roles, and, in some cases, their family members’ names. The leaked data also included job assignments, including sensitive operations against Chinese and Russian spies and drug cartels.

Meanwhile, the FBI has confirmed it was aware of the hacking group’s claims and has launched an investigation. It was also working to determine if the security breach affected other systems or third parties.

“We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the FBI stated.

ShinyHunters said it targeted the FBI over a public service alert that described the group as a “cyber criminal group specializing in large-scale data breaches and extortion.” It also indicated that the group’s tactics include the use of “real or exaggerated claims of access to sensitive or personal information” to force victims into paying the ransom.

Consequently, the FBI urged victims not to pay the ransom, which could undermine the hacking group’s ability to profit from cybercrime.

However, the group claims the description was misleading and offensive. Thus, it threatened to publish the stolen personal data unless the FBI corrected what it described as a mischaracterization.

“The FBI hasn’t confirmed anything yet, but if this holds up, it doesn’t look like the ShinyHunters we’ve been seeing all year,” said Denis Calderone, CTO, Suzu Labs. “Their model has always been breach, extort, then settle or leak, and that only works when the victim can pay. The FBI isn’t going to pay, and it isn’t going to pull an advisory because a criminal group demanded it. Not sure what’s going to happen in a week, but I seriously doubt the FBI will act on this threat.”

The group has also offered to share samples of the stolen data with journalists as proof. Experts who analyzed the leaked records said they looked legitimate. If true, the data breach could affect over 38,000 individuals, the entire FBI workforce.

Meanwhile, the affected FBI job site was temporarily taken offline, though it was unclear whether the security breach had caused the shutdown. So far, the FBI has not determined how the attackers gained access or the extent of the cyber intrusion.

However, ShinyHunters says the security breach stemmed from a vulnerability in Oracle PeopleSoft software before pivoting to AWS GovCloud infrastructure.

“If you run PeopleSoft, don’t wait for a patch,” added Calderone. “Get it off the public internet wherever you can, put what has to stay public behind a WAF, and make sure admin components like the /PSEMHUB/ path in their screenshot aren’t reachable from outside.”

“Hunt for the June indicators and for SSH attempts against the psoft and oracle accounts. Then ask yourself what your applicant portal can reach. At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud,” noted Calderone.

At the time of publication, the FBI had not released additional details regarding the alleged security breach but advised its staff to take extra steps to protect their personal information.

“ShinyHunters has spent the last week picking fights,” continued Calderone. “On Friday they took over Cl0p’s leak site and put up a ‘seized by ShinyHunters’ banner, and by Tuesday the same banner was on the FBI’s jobs portal. Both were framed as payback, one for threats from a rival gang and one for an FBI advisory that told victims not to pay them.”

The FBI has a history of data breaches

The FBI has experienced security breaches in the past. In February 2026, the agency detected and terminated suspicious activity on its network that targeted its surveillance tool, the Digital Collection System.

In the same year, pro-Iranian hackers breached FBI Director Kash Patel’s email account and leaked his pictures and personal documents. However, the agency downplayed the security breach, claiming it involved historical data and had not exposed any classified information.

In 2022, an unauthorized entity breached the FBI’s InfraGard portal, a collaboration platform for protecting U.S. critical infrastructure, and exfiltrated the contact information of more than 80,000 members. FBI’s LEEP email server also experienced a security breach in 2021 that enabled attackers to send scam emails using a government domain.