ShinyHunters Allegedly Claims Breach of FBI Jobs Site and Stolen Agents’ Data
ShinyHunters claims it breached FBI jobs systems, defaced the portal, and stole personnel records; the FBI is investigating.
The FBI said it is investigating claims of unauthorized activity affecting FBIjobs.gov after apply.fbijobs.gov briefly showed a ShinyHunters seizure notice and the bureau took the jobs application service and Special Agent Applicant Portal offline. ShinyHunters told reporters it exploited an undisclosed unauthenticated remote-code-execution flaw in Oracle PeopleSoft, moved into FBI-managed AWS GovCloud, and downloaded two to three terabytes, including HR and medical-related data. A sample of 5,000 purported employee records included names, addresses, phone numbers, Social Security numbers, assignments, dates of birth, and relative details; Reuters partially matched at least 10 cases, but neither Reuters nor 404 Media proved the sample came from FBI systems. Oracle, AWS, and the FBI have not validated that account, and the wider breach remains unproven.
- Jobs portal briefly showed a ShinyHunters seizure notice; FBI took it offline.
- Group alleges unauthenticated PeopleSoft RCE and 2–3 TB theft from AWS GovCloud.
- Sample of 5,000 records includes SSNs, addresses, assignments, and family details.
- Partial media checks did not prove the sample came from FBI systems.
- Oracle, AWS, and the FBI have not confirmed the intrusion method.
Full article616 words · extracted from cybersecuritynews.com · click to collapse
The FBI is investigating alleged unauthorized activity affecting its recruitment infrastructure after the ShinyHunters cybercrime group claimed it breached FBI systems, defaced the bureau’s jobs portal, and stole sensitive records belonging to employees and applicants. The incident places the data-extortion operation in direct confrontation with the federal agency responsible for investigating cybercrime.
The intrusion reportedly began Monday night and became visible when apply.fbijobs.gov briefly displayed a counterfeit seizure notice reading, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”
The page claimed personally identifiable information and protected health information concerning current and former FBI personnel and job applicants had been compromised. The FBI later took the application service and Special Agent Applicant Portal offline.
ShinyHunters Allegedly Breach Claim
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said. That statement confirms an inquiry and activity affecting the jobs domain, but it does not verify ShinyHunters’ claims about access to internal FBI networks, the quantity of data allegedly removed, or the intrusion method.
ShinyHunters told reporters it exploited an undisclosed Oracle PeopleSoft vulnerability that allegedly enabled remote code execution without authentication. According to the group, attackers then moved laterally into FBI-managed AWS GovCloud infrastructure and downloaded between two and three terabytes of information.
It also claimed access to human resources, Medlink, Criminal Justice, and other services. Oracle, AWS, and the FBI have not validated that technical account.
To support its allegations, the group supplied journalists with a sample of 5,000 purported FBI employee records. The material reportedly included names, home addresses, phone numbers, Social Security numbers, assignments, dates of birth, and details about spouses or other relatives.
Reuters partially matched information in at least 10 cases, while 404 Media linked several phone numbers to people bearing the listed names and to Justice Department personnel. Neither outlet could establish that the sample originated from compromised FBI systems.
The alleged exposure creates risks extending far beyond identity theft. Residential addresses, family relationships, assignments, medical details, and applicant background information could support doxxing, harassment, impersonation, social engineering, blackmail, or targeting by hostile intelligence services. Former FBI official Cynthia Kaiser warned that stolen personnel information can continue enabling harassment years after its disclosure.
ShinyHunters described the operation as nonfinancial and framed it as retaliation for an FBI cyber alert published in May. That advisory characterized the group’s reported tactics, including data theft, extortion, threatening communications, harassment, and pressure on victims not to resist payment demands. The attackers accused the bureau of making false statements and reportedly gave officials one week to correct or remove the document.
Despite the visible website defacement and limited validation of sample records, the central allegation remains unproven. A defaced internet-facing portal demonstrates unauthorized control of that web environment, but it does not itself prove access to wider FBI systems or confirm terabytes of exfiltration.
Investigators will need to review PeopleSoft logs, cloud audit trails, authentication events, lateral-movement evidence, and outbound data transfers to determine the incident’s real scope.
Until the FBI completes that assessment, affected employees, former personnel, applicants, and relatives should treat follow-on phishing, impersonation, account-recovery attempts, and unusual credit activity as credible risks.
Organizations using PeopleSoft should also monitor for anomalous administrative access and promptly apply applicable Oracle security updates, while avoiding unsupported assumptions that the alleged FBI entry vector is confirmed.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.