Cybercriminal Group Alleges FBI Data Breach, Claims Stolen Personnel Info
A cybercriminal group claims to have stolen FBI personnel and applicant data, raising concerns over cybersecurity vulnerabilities.
POLICY WIRE — Washington, D.C. — A prominent cybercriminal collective has asserted that it infiltrated the Federal Bureau of Investigation (FBI) and obtained sensitive data related to employees and job applicants.
The group, known as ShinyHunters, shared details on dark web forums and with multiple media outlets, stating it accessed between 2 to 3 terabytes of information tied to FBI and Justice Department staff. The hackers allege they exploited a newly discovered vulnerability in Oracle PeopleSoft, an HR management system.
RansomLook, a public source tracking ransomware leaks, has archived two statements attributed to ShinyHunters regarding the alleged breach. On Tuesday, the group addressed FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, claiming, ‘We have compromised the FBI.’ They indicated access to personal data for nearly all agents and job candidates, citing affected systems including criminal justice, human resources, and Medlink.
📄 POLICY WIRE WHITEPAPER PUBLISHED: PAKISTAN’S NATIONAL SECURITY POLICY PRIORITIES
On Tuesday, the FBI careers website displayed a message stating, ‘Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.’ The agency has not confirmed the breach but acknowledged awareness of the claims and is conducting an investigation. A later statement from Wednesday noted the FBI is actively examining the matter and collaborating with third-party providers to address any risks.
In its post, ShinyHunters criticized an FBI FLASH report from Q2 2026, disputing the bureau’s portrayal of the group’s activities. The hackers denied financial motives and rejected labels such as ransom or extortion. Earlier this year, Google documented ShinyHunters exploiting a different Oracle PeopleSoft zero-day vulnerability.
The FBI has faced multiple cyber incidents this year, including a March incident involving unauthorized access to a system storing law enforcement-sensitive data and a separate attack targeting Director Patel’s email account. ShinyHunters, active since at least 2020, is seen by researchers as a dynamic network of threat actors rather than a single entity.
Reporting by Policy-Wire (PW)




