ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
ShinyHunters claims it breached FBI systems via a PeopleSoft zero-day, stealing 2-3 TB of agent and applicant data, and defaced fbijobs.gov.
ShinyHunters claims to have compromised FBI Criminal Justice, HR, and Medlink services and stolen 2-3 TB of data covering nearly all FBI agents and job applicants, allegedly by exploiting an Oracle PeopleSoft zero-day tracked as CVE-2026-35273. The group defaced a fbijobs.gov subdomain with a seizure message and gave the FBI one week to retract a May FLASH report alleging harassment and swatting tactics. A data sample of 5,000 FBI employees shared with 404 Media, including names, phone numbers and addresses, appeared at least partially authentic. The FBI said it is investigating the claims against FBIjobs.gov.
- ShinyHunters claims theft of 2-3 TB of FBI data on agents and applicants via PeopleSoft zero-day CVE-2026-35273
- Defaced fbijobs.gov subdomain displays seizure message and one-week retraction demand
- Sample of 5,000 employee records reviewed by 404 Media appears at least partially authentic
- FBI confirms it is investigating unauthorized activity affecting FBIjobs.gov
Vulnerabilities mentionedAll →
- CVE-2026-352739.89%Unauthenticated Takeover Flaw in Oracle PeopleSoft Enterprise PeopleToolspublished · Oracle PeopleSoft Enterprise PeopleTools (Updates Environment Management component) KEV ransomware
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
Full article405 words · extracted from securityweek.com · click to collapse
The notorious cybercrime and extortion group ShinyHunters claims it breached FBI systems and accessed sensitive information.
The hackers claim to have compromised Criminal Justice, HR, and Medlink services, and say they now possess data on nearly all FBI agents and job applicants.
To demonstrate their claims, they defaced a subdomain on the FBI’s jobs website, fbijobs.gov, posting the message “This site has been seized by ShinyHunters”. The targeted domain is currently down for maintenance.
In a lengthy statement on its website, ShinyHunters said it was responding to an FBI FLASH report from May that made what it called false allegations against the group. They gave the FBI one week to correct or remove the report.
The group specifically disputed claims in the FBI report that they exaggerate their access to pressure victims into paying, use harassment tactics such as swatting or threats to victims’ families, and falsely claim to possess compromising photos or videos. ShinyHunters insisted its threats are genuine, denied ever conducting swatting or contacting victims’ families, and denied being “sextortionists”.
The group also denied any affiliation with The Com, calling it a fabricated narrative pushed by the cybersecurity industry, and framed its statement as an exercise of First Amendment rights rather than an act of ransom, coercion, or extortion.
Advertisement. Scroll to continue reading.
FBI investigating ShinyHunters’ claims
In a statement to the media, the FBI said it is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” The agency has not shared any additional information.
ShinyHunters provided 404 Media with a sample of the stolen data allegedly representing the personal information of 5,000 FBI employees, including names, phone numbers, and home addresses.
404 Media and others who reviewed the sample reported that at least some of the data appears authentic, but the origin of the data has yet to be confirmed.
The hackers told 404 Media that they exploited a zero-day vulnerability in Oracle’s PeopleSoft product to breach FBI systems, from which they allegedly stole 2-3 TB of information.
The cybersecurity community confirmed in June that ShinyHunters had been exploiting a PeopleSoft zero-day to steal data from organizations. It’s unclear whether the cybercrime group found a new zero-day or targeted the FBI through the same vulnerability, tracked as CVE-2026-35273.
Related: BigCommerce Data Stolen via Ribon Apps Hack
Related: CrowdSec Confirms Source Code Stolen in Supply Chain Attack
Related: McKesson Confirms Data Breach as Attacker Deadline Looms