ShinyHunters Claims FBI Breach Exposed Data of All Employees and Applicants
ShinyHunters claims it stole FBI employee and applicant data via an unverified PeopleSoft zero-day; the FBI is investigating.
ShinyHunters claims it breached FBI-linked systems and stole personal data on nearly all employees and applicants, including names, addresses, phone numbers, dates of birth, and spouse details. The group showed a sample of about 5,000 purported personnel records; some matched public records, but that does not confirm an FBI origin or the full claim. It alleged an unverified Oracle PeopleSoft zero-day and later access to an Amazon-hosted government cloud, plus defacement of FBIjobs.gov. The FBI says it is investigating unauthorized activity on that site and has not verified the theft, its scope, or the entry method.
- ShinyHunters claims personal data on nearly all FBI employees and applicants.
- A sample of about 5,000 records was only partly matched to public data.
- Alleged access used an unverified PeopleSoft zero-day and a government cloud system.
- FBI says it is investigating FBIjobs.gov activity but has not confirmed theft.
- The group also claimed it defaced the FBI recruitment website.
Full article527 words · extracted from gbhackers.com · click to collapse
The cybercriminal group ShinyHunters has claimed to have breached systems linked to the FBI, obtaining highly sensitive information on “almost all” FBI employees and applicants.
The FBI has confirmed that it is investigating claims of unauthorized activity affecting FBIjobs.gov but has not verified the alleged theft, its extent, or the attackers’ claimed entry method.
ShinyHunters told 404 Media it has personal data on FBI personnel and applicants, including names, home addresses, phone numbers, dates of birth, and information about employees’ spouses.
The group provided a sample containing records for approximately 5,000 individuals purported to be FBI personnel; 404 Media noted that some of this information appeared to match public records.
However, this limited validation does not independently confirm that the data originated from FBI systems or support the group’s broader claim of accessing every employee and applicant record.
ShinyHunters Claims FBI Breach
Reports suggest ShinyHunters initially accessed the system through an unidentified zero-day vulnerability in Oracle PeopleSoft, an enterprise platform commonly used for human resources and recruitment workflows.
The group allegedly moved from a PeopleSoft environment to an Amazon-hosted government cloud system containing personnel and applicant data. However, neither the FBI nor Oracle has publicly verified this claim of exploitation.
The alleged breach coincided with disruptions to the FBI’s recruitment portal. ShinyHunters also claimed responsibility for defacing the FBI jobs site, saying the group had “seized” the service and alleging the compromise of personally identifiable information (PII) and protected health information related to current and former personnel, as well as applicants.
If validated, this incident could pose significant counterintelligence and personal safety risks. A consolidated dataset containing agent identities, private contact information, family relationships, and employment details could facilitate:
- Targeted phishing, impersonation, and credential-harvesting attacks against FBI staff.
- Doxxing, harassment, stalking, or threats directed at agents and their families.
- Social engineering operations aimed at gaining access to FBI or Department of Justice systems.
- Foreign intelligence collection on personnel, operational roles, and recruitment activities.
- Extortion attempts against employees, applicants, or their relatives.
The risk is heightened because leaked identity data can be correlated with previously exposed telecommunications, financial, social media, and data broker information to build detailed target profiles.
The FBI has acknowledged “claims regarding unauthorized activity affecting FBIjobs.gov” and is investigating. This statement confirms that the bureau is looking into the reported activity.
However, it does not validate ShinyHunters’ assertions of a network-wide breach, access to AWS GovCloud environments, or the exfiltration of employee and applicant records.
ShinyHunters has been associated with large-scale data theft and extortion, making its claims significant. Nevertheless, incident responders and affected individuals should treat the alleged dataset as unverified until the FBI provides further technical findings or breach notification details.
Organizations operating PeopleSoft or similar HR platforms should review their internet-facing assets, apply vendor security updates, rotate potentially exposed credentials, audit privileged access, and monitor for unusual data exports, identity provider changes, and suspicious cloud access patterns.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.