ShinyHunters Claims It Broke Into the FBI

The group behind some of the largest data thefts of the decade says it has a new target. On September 22, the hacking collective ShinyHunters claimed it broke into the Federal Bureau of Investigation and took data on its agents and job applicants.

The claim, posted on the group’s dark-web leak site, asserts the hackers stole “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.” If true, the breach would rank among the most damaging government data leaks of the year.

The allegation has not been verified. The FBI did not immediately respond to requests for comment, and Reuters reported it could not establish where the data came from. But the independent outlet 404 Media said it reviewed a sample of names, home addresses and phone numbers of agents and their spouses and matched part of it against public records.

According to 404 Media, the hackers breached an Oracle PeopleSoft server, software widely used by human-resources and recruiting teams to store applicant data, then moved into an Amazon-hosted government cloud holding the agents’ and applicants’ records. The group said it took terabytes of information.

ShinyHunters has offered a motive that reads as a grievance. The group said it targeted the FBI in response to a public service announcement from the bureau’s internet-crime unit that it says contains false claims about the group. It did not say what it would do with the data if the bureau did not withdraw the notice.

The stakes go beyond embarrassment. If agents’ identities and home addresses are in criminal hands, the information could be used to coerce or extort officers and their families, a counterintelligence risk that security officials have long treated as the most dangerous kind of leak. The FBI’s special-agent applicant portal was reported to be down the same day.

ShinyHunters has been active since 2020 and has claimed responsibility for dozens of breaches. Prosecutors say the group has hit Microsoft, AT&T and more than 60 other companies, stealing customer records and selling or leaking them online.

The group’s signature came in 2024, when it claimed to have taken 560 million Ticketmaster customer records, a breach linked to a broader campaign against customers of the cloud data firm Snowflake. That campaign compromised roughly 165 accounts and exposed data from AT&T, Santander and others.

The Snowflake episode revealed how the group works. Investigators said the hackers obtained credentials stolen by infostealer malware, often from third-party contractors, and used them to move into cloud accounts that had weak or absent multi-factor authentication. The pattern was persistence rather than exotic technique.

The group’s business model is just as methodical. ShinyHunters typically announces a theft on a data-leak site, posts a sample to prove it holds the records, then either sells the data or demands payment to destroy it. In the Ticketmaster case it offered the records in a one-time sale for $500,000. The economics are crude but effective: the cost of a breach is low, and the value of stolen identity data stays high for years.

Law enforcement has made arrests. A French citizen, Sebastien Raoult, was sentenced to three years in prison and ordered to pay more than $5 million in restitution for his role in ShinyHunters. Two other men, Connor Moucka of Canada and John Binns of Turkey, were indicted in the Snowflake campaign. The group has continued to operate despite the prosecutions.

If the claim holds up, the exposure would differ from the group’s corporate targets. The records of FBI agents and applicants are valuable to foreign intelligence services, which could use home addresses and family details to identify and pressure officers. The 2015 breach of the Office of Personnel Management, which compromised background-check files on millions of current and former federal employees, showed how long that kind of damage lingers. Security officials still describe it as the worst breach of U.S. government personnel data on record.

The claimed FBI intrusion, if confirmed, would be an escalation of a different kind. ShinyHunters has mostly gone after companies, harvesting customer records it could sell. A breach of a law-enforcement agency touches identities that cannot be replaced and officers who cannot simply change their names.

The claim itself is a kind of weapon. Hackers sometimes assert access they do not have, hoping to pressure a target into paying or negotiating. The FBI’s silence, and the partial verification reported by 404 Media, leave the bureau facing a question it cannot yet answer publicly: whether its own people are now on the list.

Until the bureau confirms or denies the breach, the incident sits in a familiar limbo. A group with a long record of real thefts has made an extraordinary claim against an institution that rarely acknowledges its own compromises. The data, if it exists, will eventually speak for itself.

Related Posts

  • September 23, 2026
  • 13 views
Hack VC’s Former Partner Found Dead in the California Desert

Hsin-Ju Chuang spent nearly a decade inside the crypto industry’s fastest-growing companies, including a stretch running growth at Solana. In the final weeks of her life, she had turned against…

  • September 23, 2026
  • 12 views
Microsoft and Partners Take Down Fraud Service Tied to 12,000 Accounts

The criminals behind the platform did not need to write their own code. For a subscription fee, “EvilTokens” sold them the tools to break into Microsoft accounts, a service built…