A notorious hacking group, ShinyHunters, says it compromised systems at the U.S. Federal Bureau of Investigation, claiming possession of data related to virtually all FBI agents—both current and former—as well as individuals who applied for FBI jobs. The group further asserts that multiple FBI services were breached, including Human Resources, Criminal Justice, Medlink, among others. This came to light on September 23, 2026.
What ShinyHunters Claims
According to a statement posted by the group, they used a recent zero-day remote code execution flaw in Oracle PeopleSoft to gain access to FBI networks and deface the FBI jobs portal with a “This site has been seized by ShinyHunters” message. The attack allegedly hit systems including FBIjobs.gov.
ShinyHunters also mentioned that this breach was retaliation for a public service announcement in May 2026, in which the FBI warned against paying ransom to the group, citing its targeting of a learning management system named Canvas. ShinyHunters called the FBI’s statements misleading, accusing the agency of disseminating “substantial false allegations.”
Official Response & Context
The FBI acknowledged awareness of the claims, stating it is investigating possible unauthorized activity affecting FBIjobs.gov. There has been no confirmation yet from the agency that its broader internal systems or databases have been compromised.
No independent verification has surfaced confirming that data of agents or applicants were stolen, or that HR, Medlink, or Criminal Justice services were accessed. The alleged zero-day exploit hasn’t been publicly validated, though ShinyHunters has claimed it used a similar vulnerability in June 2026—CVE-2026-35273—to break into enterprise networks for extortion.
Why This Allegation Is Alarming
ShinyHunters is a well-known cybercrime brand that has consistently altered its operations after law enforcement pressure, relying not only on direct breaches but often on identity-based attacks like helpdesk social engineering or exploiting third-party integrations.
Security analysts warn this kind of claim against a high-profile law enforcement agency is rare—and inherently serious. For context, previous large-scale U.S. breaches involving federal law enforcement or affiliated personnel, like the massive OPM (Office of Personnel Management) breach of 2015, compromised millions of personnel records across government systems.
Etay Maor, Vice President of Threat Intelligence at Cato Networks, pointed out timing details—ShinyHunters’ post is timestamped September 23, while reports emerged earlier in the U.S. on September 22—which may suggest the group is operating from Asia. While this isn’t proof, it’s being scrutinized alongside the technical evidence.
At present, the FBI has not confirmed any data theft or system compromise beyond FBIjobs.gov, nor has the zero-day exploit or exfiltrated data been independently verified. The agency is still investigating.
This claim from ShinyHunters stands out not just for its scale but for what it signals about evolving tactics: public pressure, exploiting trusted identity paths, and attacking not just systems but reputations. How the FBI responds—technically, operationally, and in its disclosures—will set a marker for both government and enterprise cybersecurity practices. Things to watch for: forensic confirmation of breach scope, legal and diplomatic fallout, if any, and whether this leads to reinforcements of zero-trust and identity security across all high-risk institutions.