Press play to start listening
ShinyHunters has claimed responsibility for compromising systems belonging to the U.S. Federal Bureau of Investigation (FBI), with the group defacing the official FBI job application portal and claiming it obtained sensitive information belonging to FBI personnel and people who applied for jobs at the agency.
Hackread.com observed the defacement on September 22, 2026, at apply.fbijobs.gov. Instead of the normal FBI application portal, the site displayed a page carrying the message, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS,” along with the group’s branding and a link to its dark web data leak site.
The defacement also contained a message claiming that FBI data had been compromised, including personally identifiable information (PII) and protected health information (PHI) involving current and former FBI employees, as well as information belonging to applicants.
ShinyHunters subsequently published a longer statement on its data leak site explaining why it says it targeted the FBI and providing additional claims about the extent of its access.
ShinyHunters Claims Multiple FBI Services Were Compromised
In the statement seen by Hackread.com, ShinyHunters claimed it holds sensitive information on “almost ALL FBI Agents” as well as people who submitted job applications to the bureau, including applicants for Special Agent and other positions.
The group also named several FBI services it claims were compromised, including Criminal Justice (CJ), HR and Medlink, adding “and more” without identifying the additional systems.
ShinyHunters did not provide a total number of records in the statement or explain there how each of the named systems was accessed.
The group’s statement was addressed to FBI Cyber Division Assistant Director Brett Leatherman and FBI Director Kash Patel. ShinyHunters said the action was connected to what it described as false allegations made about the group by the FBI during the second quarter of 2026.
ShinyHunters Claims PeopleSoft Zero-Day Led to FBI Access
ShinyHunters also provided additional details about how it says the FBI hack began, claiming that it exploited a previously unknown vulnerability in Oracle PeopleSoft. The group had previously exploited a separate PeopleSoft vulnerability to breach more than 100 organizations, with universities among its main targets.
The group says it discovered the zero-day on Monday night and used it against the FBI shortly afterward, gaining remote code execution on a server. ShinyHunters claims it then moved laterally into other FBI-managed infrastructure, including systems hosted in AWS GovCloud, before downloading between 2TB and 3TB of data.
The PeopleSoft connection is notable because the FBI describes apply.fbijobs.gov, the portal defaced by ShinyHunters, as its Oracle Application Portal. The FBI says the portal is used to create applicant profiles, submit job applications and required documents, and track applications.
ShinyHunters says the PeopleSoft vulnerability used in the attack remains a zero-day and has not released technical details about the flaw.
Dispute Centers on FBI Statements About ShinyHunters
ShinyHunters specifically objected to statements published by the FBI about its methods, including allegations concerning exaggerated claims of access, harassment of victims and their families, swatting, and claims involving sensitive or compromising information.
The language identified by ShinyHunters appears in an FBI Internet Crime Complaint Center (IC3) Public Service Announcement (PDF) published on May 15, 2026. The advisory, titled “ShinyHunters: Cyber Criminal Group Attacks Learning Management System” (PDF), describes ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion.
The FBI advisory states that threat actors can use real or exaggerated claims of access to pressure victims into paying. It also attributes harassment tactics, including threatening communications and, in some cases, swatting, to ShinyHunters members.
The advisory further warns that threat actors may falsely claim to possess compromising material. However, ShinyHunters disputes those descriptions.
In its statement, the group denied conducting swatting attacks against personnel at corporate victims or threatening family members of victim personnel. It also denied claiming to possess embarrassing photographs or videos and rejected any association with “The Com.”
The group further claimed that its FBI hack was not financially motivated.
FBI Given One Week Over Disputed Report
Rather than making a monetary demand, ShinyHunters said it was giving the FBI one week to correct or remove what it referred to as the bureau’s “2026 Quarter 2 FLASH report.”
The publicly available FBI document containing the statements quoted by ShinyHunters is identified by the FBI as Alert Number I-051526-PSA, dated May 15, 2026. It is presented on the IC3 website as a Public Service Announcement.
ShinyHunters said its actions were intended to demonstrate that its threats and access claims are genuine. The group described the incident as a response to what it considers misinformation about its operations.
The statement also accused unnamed journalists of contributing to what ShinyHunters considers inaccurate reporting about the group.
ShinyHunters Invites Journalists to Contact It
At the end of its statement, ShinyHunters explicitly invited journalists to contact the group to hear its account of events. Hackread.com has contacted ShinyHunters in response to that invitation and asked the group to explain its side of the incident.
Hackread.com has also asked how the group initially gained access to the FBI environment, which systems were compromised, approximately how many current and former FBI personnel and job applicants are represented in the data, and what level of access it obtained to the CJ, HR, and Medlink services named in its statement.
We also asked whether apply.fbijobs.gov itself was the source of the employee and applicant information and whether the FBI was specifically targeted because of the disputed report or ShinyHunters already had access before deciding to disclose the incident. This article will be updated if ShinyHunters responds.
FBI Jobs Portal Replaced With Maintenance Page
Following the ShinyHunters defacement, the affected FBI Jobs portal was changed.
Hackread.com subsequently observed the portal displaying an FBI-branded “Scheduled Maintenance Underway” page instead of the ShinyHunters content.
The page states:
“WE’RE SNIFFING OUT SITE UPDATES FOR YOU!”
It says the site is currently down for maintenance and will return, while directing visitors to the FBI Jobs home page and an FBI Jobs eligibility page. However, the maintenance page does not explain the downtime or mention the ShinyHunters incident.
ShinyHunters, FBI and Its Cybersecurity Issues
The FBI has faced other cybersecurity incidents involving systems and communities connected to the bureau. In December 2022, a hacker known as USDoD breached the FBI’s InfraGard information-sharing program and leaked a database containing information on more than 80,000 members.
Hackread.com reported at the time that the exposed records included names, usernames, email addresses, and other account information. USDoD was later arrested in Brazil in 2024, with Brazilian authorities linking the suspect to the InfraGard breach.
ShinyHunters itself has previously crossed paths with the FBI over Breach Forums. In May 2024, the FBI and international law enforcement partners seized domains associated with the cybercrime forum. A day later, ShinyHunters told Hackread.com that it had regained control of the forum’s clear-web domain through its registrar after authorities gained access to the forum’s infrastructure.
The latest FBI incident also comes days after ShinyHunters began another unusual confrontation. On September 19, Hackread.com reported that the group had taken over the dark web leak site of the Clop ransomware gang and issued an eight-figure payment demand.
Two days later, Clop regained the ability to publish on its onion address and posted a message asking ShinyHunters to make contact.


