A criminal extortion crew says it walked into the Bureau's HR and cloud systems through an unpatched Oracle flaw, and early verification suggests at least part of the haul is real.

Intelligence Lead

ShinyHunters, one of the most aggressive data-extortion groups operating today, claims to have stolen between two and three terabytes of FBI personnel data, including home addresses, phone numbers and spouse details for current and former employees and applicants. Independent checks by Reuters and 404 Media have matched a portion of a 5,000-record sample to real individuals. If the full claim holds, the most consequential beneficiary will not be the criminals who took the data but the foreign intelligence services able to acquire it.

Situation Report

On 22 September, ShinyHunters told BleepingComputer that it exploited a previously unknown remote code execution flaw in Oracle PeopleSoft on the night of 21 September, then moved laterally into FBI-managed AWS GovCloud infrastructure. The group claims to have compromised FBI Criminal Justice, HR and Medlink services. None of these technical claims has been independently verified.

The FBI confirmed it is investigating "claims regarding unauthorized activity affecting FBIjobs.gov" but has not confirmed a breach or data loss. ShinyHunters circulated a screenshot of apply.fbijobs.gov defaced with its logo and a message asserting that sensitive personal and health information on all employees and applicants had been taken. The group says the Bureau took affected systems offline within hours, and the jobs portal has since displayed a maintenance notice.

404 Media first reported the incident after receiving roughly 5,000 purported personnel records, and stated that some phone numbers matched Department of Justice personnel. Reuters separately ran names against credit bureau and previously breached data and found matching details in at least nine cases. BleepingComputer was shown two further sample records, one allegedly linked to a special agent involved in a prior BreachForums investigation and another allegedly associated with FBI Director Kash Patel. Their authenticity is unconfirmed.

The group has framed the operation as retaliation, not extortion. It has demanded that the FBI correct or withdraw a May 2026 FLASH report describing ShinyHunters tactics, including harassment of victims' relatives and swatting, and has given the Bureau one week. Asked whether it would publish the data if the FBI refused, the group declined to comment. It also claims it is now using the same PeopleSoft flaw against Fortune 500 companies.

Background & Context

ShinyHunters has a record of large-scale cloud and credential-driven data theft, and was part of the "Scattered Lapsus$ Hunters" alliance that leaked a proof-of-concept exploit tied to Clop's 2025 Oracle E-Business Suite campaign, an exploit Oracle later confirmed matched the one used in the attacks. Last week the group breached and defaced Clop's own leak site, signalling a willingness to pick fights with bigger players. Google's threat intelligence team has separately documented ShinyHunters exploiting Oracle products against the education sector this year.

The wider criminal ecosystem around the group has previously used breached telecoms data to track and intimidate FBI agents investigating them, according to 404 Media. That history matters: the claimed dataset is precisely the material required to locate investigators and their families physically.

Analysis & Assessment

SpyWitness assesses with moderate confidence that ShinyHunters obtained genuine FBI personnel records from at least one Bureau-linked system. The partial Reuters and 404 Media matches, the rapid offline response described by the group, and the FBI's specific reference to FBIjobs.gov all point in that direction. Available evidence does not yet support the claimed scale of two to three terabytes, the lateral movement into GovCloud, or the compromise of Criminal Justice systems. Criminal actors routinely inflate scope and blend older breach data into fresh samples to maximise pressure.

The counterintelligence exposure is the central issue. A consolidated file of names, home addresses, spouses and, reportedly, Social Security numbers for Bureau staff would be a high-value targeting asset for Chinese, Russian and Iranian services, all of which have invested heavily in bulk personal data since the 2015 OPM breach. Such material enables spotting and assessment of recruitment candidates, pretext approaches through family members, and identification of personnel assigned to counterintelligence and cyber squads. Whether or not ShinyHunters publishes, the probability that copies reach state buyers rises with every day the data sits outside Bureau control.

The one-week ultimatum also puts the FBI in a structurally weak position. Amending an official FLASH report under threat would reward coercion; refusing it risks publication. The likelier outcome is refusal paired with an intensified international effort to identify and arrest group members, which may itself trigger a leak.