ShinyHunters claims FBI breach exposed employees and applicants
A 5,000-record sample contained names, addresses, phone numbers and spouse details, while the full scope remains unverified.
By Ryan Merket · Published
Primary source: 404 Media
Why it matters
Accurate home, family and contact records could expose FBI personnel to physical threats, targeted harassment, impersonation and foreign intelligence collection.

ShinyHunters claims it breached FBI recruiting and personnel systems on September 21st, stealing employee and applicant records before defacing an agency jobs portal the next day.
The hacking group told 404 Media that its haul included names, home addresses, phone numbers, birth dates and information about FBI employees' spouses. ShinyHunters provided the publication with a sample containing 5,000 alleged employee records and claimed it had obtained data covering every FBI employee and applicant.
The FBI says it employs approximately 38,000 people. The sample therefore represents only a fraction of the workforce and cannot substantiate ShinyHunters' claim that it obtained records on everyone. The amount, provenance and age of the alleged data also have not been independently established.
404 Media checked some phone numbers from the sample through an open-source intelligence service and found that they corresponded to people with the names listed in the file. That supports the accuracy of at least some identifying information in the sample. It does not establish that the records came directly from the FBI or confirm the claimed scope of the intrusion.
The jobs portal was defaced
ShinyHunters also defaced the FBI's applicant website on September 22nd with a notice saying the site had been seized by the group. The message claimed that personnel and health information belonging to current and former employees had been compromised, along with applicant records.
The FBI applicant portal subsequently displayed a notice that it and the Special Agent Applicant Portal were unavailable, according to 404 Media. Other pages on the broader FBI Jobs website remained indexed with active job listings and September 22nd deadlines.
ShinyHunters told 404 Media that it entered through an unidentified zero-day vulnerability in Oracle PeopleSoft, then reached servers hosted in AWS GovCloud. The group claimed it exfiltrated between two and three terabytes of data. Each part of that account remains an attacker assertion.
Oracle disclosed a critical PeopleSoft PeopleTools vulnerability on June 10th. CVE-2026-35273 could be exploited remotely without authentication and could allow remote code execution. ShinyHunters did not identify the vulnerability it allegedly used, and Oracle's advisory does not connect CVE-2026-35273 to the claimed FBI intrusion.
The reference to AWS GovCloud does not establish that Amazon Web Services itself was breached. AWS describes GovCloud as isolated regions designed for sensitive government workloads, while its documentation places responsibility for application access and customer content controls on the customer. On ShinyHunters' account, access began through the FBI's PeopleSoft environment before the hackers reached cloud-hosted data.
Personnel records create an operational threat
The most immediate risk extends beyond account fraud. Home addresses, family connections and personal phone numbers can help criminals identify, locate and pressure agents involved in investigations. The same records could support targeted phishing, impersonation or intelligence collection against FBI personnel and applicants.
The FBI itself warned in May that ShinyHunters uses threatening calls, messages and harassment against victims and their families, including swatting. That warning also cautioned that attackers operating under the ShinyHunters name may make exaggerated claims to pressure targets into paying.
ShinyHunters typically couples data theft with extortion. In this case, its representative told 404 Media that the operation was not financially motivated and described the group's intended next step as "maybe coercion." The group has not publicly demonstrated possession of the two to three terabytes it claims to have taken.
The 5,000-record sample and the jobs-site defacement make the incident more substantial than an unsupported message on an extortion page. They still fall short of proving ShinyHunters' central assertion: that it holds personnel and applicant data spanning the FBI's entire workforce and recruiting pipeline.