ShinyHunters hackers claim breach of FBI, stealing data on agents and applicants
The FBI says it is investigating a criminal hacking group's claim to have stolen "very sensitive data" on thousands of agents and job applicants and defaced its jobs website.
What to know
- ShinyHunters claims to hold 2-3TB of data on nearly all FBI agents and job applicants, including home addresses, phone numbers, and spouse information.
- The FBI has confirmed it is investigating but has not verified the scope or authenticity of the stolen data.
- The group says its motive is not financial extortion but forcing removal of a report it claims contains false allegations about it.
- Security researchers warn the breach carries counterintelligence risk, as foreign agencies or criminals could use the data to identify, track, or coerce FBI agents and their families; it follows an earlier 2026 breach of an FBI wiretap-warrant system and a hack of Director Kash Patel's personal email.
The dispute Some commenters push back on the fatalism, arguing security quality varies by organization rather than being universally impossible: 'the fatalism is understandable, but "no one can keep a database safe" isn't quite right. Some organizations do a better job than others.' (Transformanshen, Hacker News, #2155319965) · positions read across 95 posts and comments
No large database can realistically be kept secure; breaches like this are now inevitable and unremarkable.
-
“It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.”
coldpie · Hacker News ↗
This reflects a broader failure of US institutions to invest seriously in cybersecurity defense.
-
“America is at war and losing comically. Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.”
bearjaws · Hacker News ↗
Mocking FBI/administration leadership over the breach's optics and timing.
-
“I see Kash is doing a great job.”
altnoaa.bsky.social · Bluesky ↗
The real fix is not collecting or retaining sensitive data in the first place.
-
“The only safe data is data not collected, directly followed by data that is only stored on paper.”
niemandhier · Hacker News ↗
ShinyHunters Hacking group behind the claimed breachFBI Targeted agency
Kash Patel FBI DirectorJoseph Cox / 404 Media Reporters who first obtained hacker sample data
How it unfolded 7 developments, newest first · click a bar or a number to jump articlesvideospostscomments
-
7
FBI confirms it is investigating theft of 'very sensitive data'
The FBI formally said Wednesday it is investigating the criminal hacking group's claims that it stole 'very sensitive data' belonging to thousands of agents and applicants and compromised the bureau's jobs website; the story was picked up by AP, PBS NewsHour, Al Jazeera, the Guardian and others.
“very sensitive data…”
— FBI (describing hackers' claims) -
first by PBS NewsHour, 4h ago · also Philadelphia Inquirer, Federal News Network, KSTP-TV, Boston Globe, Hindustan Times
1 more headline
- FBI investigates hackers' claim to have stolen sensitive employee data, compromised jobs website Philadelphia Inquirer · 4h ago
-
R
In its message, # ShinyHunters said it would give the bureau one week to correct or remove what it said were false allegations contained in an # FBI public advisory from May that described the organization as a “#cybercriminal group specializing in large-scale data breaches and extortion.” https:// apnews.com/article/fbi-crimina…
1 more of the top 2 · 2 posts in this stretch
-
U
https://www. europesays.com/thestates/9938/ FBI investigates hackers’ claim to have stolen sensitive employee data, compromised jobs website | National News # alabama # crime # cybercrime # FbiCriminalHackingGroupJobsWebsiteBeach # GeneralNews # Hacking # InformationSecurity # technology # USNews # WashingtonNews
-
-
6
Reports detail scale2-3TB of data, thousands of records
Coverage converged on the scale of the alleged theft — roughly 2-3TB of data covering thousands of agents and applicants — with outlets noting the group's stated goal was not financial extortion this time.
“I see Kash is doing a great job.”
— @altnoaa.bsky.social, Bluesky user · source -
K
"There has been a breach and all of the FBI employment records have been stolen. Please accept this one year complimentary credit monitoring service. Thanks, Kash." https://www. washingtonpost.com/national-se curity/2026/09/23/hacking-group-claims-have-stolen-thousands-fbi-employee-records/ # news # tech # technology
2 more of the top 3 · 14 posts in this stretch
-
J
Data stolen from the FBI provides sensitive assignment descriptions for named employees, exposing members of the "China criminal enterprise unit” & “Russia Operations Section" One ex-employee described it as a foreign intel "goldmine" ✏️ @reuters.com
-
ShinyHunters posted a letter to Kash Patel and FBI Cyber's Brett Leatherman on its leak site. It claims it breached FBI systems (CJ, HR, Medlink) and holds data on nearly every agent and job applicant, and gives the FBI a week to pull its Q2 2026 FLASH report on the group.
-
-
5
ShinyHunters insists the hack is 'not financially motivated'
The group told reporters it was not seeking a ransom but rather demanding the FBI remove a report it says contains false allegations about ShinyHunters, calling its intended action 'coercion' rather than extortion.
“sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.”
— ShinyHunters, Dark web leak site post · source -
first by Cyber Daily, 1d ago
-
Z
FBI tells me it's "aware of claims" of a hack affecting its jobs site and is "currently investigating.” ShinyHunters, meanwhile, tell me that they are confident that they have data "on mostly all of FBI" and a substantial amount of applicants' data. More: https:// techcrunch.com/2026/09/22/hack…
2 more of the top 3 · 18 posts in this stretch
-
Not just government employees, employees of government contractors who held or applied for security clearances. I’ve never worked for the government but the CCP got my SF-86. My employer’s infosec group told us they believe that the same group was also responsible for the Mariott data breach in the same timeframe and that it was believed to be…
-
I hate they’ve done this. Couldn’t they do something productive and positive by releasing the Epstein files with only victim names redacted?
-
-
4
Reuters reports hackers' claim, no immediate FBI comment
Reuters picked up the ShinyHunters claim that they breached the Bureau, noting the FBI had not immediately commented on the specifics beyond acknowledging the investigation.
-
first by TechRadar, 1d ago · also Silicon Republic, Beehaw, HN Best, HN Frontpage, 404 Media, Mashable +6
6 more headlines
- ShinyHunters says it breached the FBI, stole employee data Silicon Republic · 1d ago
- ShinyHunters Says It Breached FBI, Stole All Staff Data NewsMax.com · 1d ago
- ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees Beehaw · 1d ago
- ShinyHunters claims it stole FBI employee data. Here’s what we know. Mashable · 1d ago
- Hacker group ShinyHunters claims massive breach of FBI employee data Washington Times · 1d ago
- ShinyHunters hackers say they breached FBI, stole data on bureau employees Straits Times · 1d ago
-
first by Security Affairs, 1d ago · also The Register, CyberInsider, 404 Media, BleepingComputer, GovExec, Nextgov/FCW +1
5 more headlines
- ShinyHunters claims FBI hack: ‘This is NOT financially motivated’ The Register · 1d ago
- ShinyHunters claims FBI breach via new Oracle PeopleSoft zero-day CyberInsider · 1d ago
- ShinyHunters claims it used an Oracle PeopleSoft zero-day to hack FBI-related services and steal employee and applicant data; it also defaced the FBI jobs site 404 Media · 1d ago
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Mastodon · 1d ago
- ShinyHunters claims FBI data theft, demands bureau retract cyber warning GovExec · 1d ago
-
B
Hackers have apparently breached FBI systems and have extracted personal data “on all FBI employees and applicants.” The data reportedly includes FBI agents’ names, home addresses, phone number, and information on their spouse. 404 Media reports having direct contact with a representative of the hackers known as "ShinyHunters". https://www…
2 more of the top 3 · 42 posts in this stretch
-
Yes, huge amounts of your medical information is for sale. In 2024, Change Healthcare (CHC) was hacked and held ransom. The hackers were in the system for over a week before everything was pulled offline.CHC is the largest claims clearinghouse in the US; about 100m people's insurance claims go through there each year.The hackers asked for a ransom…
-
New: hackers say they have data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk
-
-
3
TechCrunch details breach path and FBI's initial response
TechCrunch reported the hackers breached an Oracle PeopleSoft server used for HR/job applications, then pivoted into an Amazon-hosted government cloud; the FBI said it was 'aware of claims' and investigating, while the jobs site and agent applicant portal were defaced and shown as down for maintenance.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
— FBI spokesperson -
first by Digit, 1d ago · also The Hacker News, Cyber Security News, KEYT-TV, Hackread
4 more headlines
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants The Hacker News · 1d ago
- ShinyHunters Allegedly Claims Breach of FBI Jobs Site and Stolen Agents' Data Cyber Security News · 1d ago
- FBI investigating apparent breach after hackers claim to have stolen thousands of federal agents' data KEYT-TV · 1d ago
- ShinyHunters Hacks FBI Jobs Portal, Claims It Stole Agents' Data Hackread · 1d ago
-
first by The Record, 12h ago
-
Z
"We're sniffing out site updates for you!" is definitely one way to say "we were hacked and thousands of FBI agents and applicants had their information stolen." Those federal puppers are fucking adorable though. https://www. 404media.co/we-hacked-the-fbi- hackers-say-they-have-data-on-all-fbi-employees/
2 more of the top 3 · 9 posts in this stretch
-
M
This is massive, China & Russia must be laughing hysterically, & Kash Patel should not have a job by the end of today. And Trump's meeting with the Chinese tomorrow. 😂😂 Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
-
Thats a major attack on the US.If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
-
-
2
ShinyHunters claims it stole data on 'all FBI employees and applicants'
A representative of the hacking group told 404 Media it had breached multiple FBI-related services and obtained agents' names, home addresses, phone numbers, and information on their spouses, based on a sample of 5,000 alleged agent records.
“We hacked the FBI. We hold data on all FBI employees and applicants,…”
— ShinyHunters representative -
first by Axios, 10h ago · also Fox News, Guardian, Globe and Mail, Bloomberg, Associated Press, Orlando Sentinel +4
7 more headlines
- FBI investigates after ShinyHunters hackers claim theft of agents' personal data Fox News · 10h ago
- FBI investigates breach of jobs website as hackers claim ‘very sensitive data’ stolen Guardian · 9h ago
- FBI investigates hackers’ claim to have stolen sensitive employee data Globe and Mail · 7h ago
- FBI Investigating Hackers' Claims of Stealing Employee Data Bloomberg · 6h ago
- FBI Investigates Hackers' Claim of Major Data Breach NewsMax.com · 6h ago
- FBI investigates apparent breach of its jobs website. Hackers claim to have sensitive employee data Associated Press · 6h ago
- FBI says investigating breach of ‘very sensitive’ data by hackers Al Jazeera · 5h ago
-
first by The Hindu, 19h ago · also Daily Maverick, Channel News Asia, Reuters
-
L
BREAKING: Hackers say they have [personal] data on all FBI employees https://www. 404media.co/we-hacked-the-fbi- hackers-say-they-have-data-on-all-fbi-employees/
2 more of the top 3 · 3 posts in this stretch
-
H
Clop has resurfaced on its own onion site with a message for ShinyHunters after the group hijacked its leak site and demanded an eight-figure payment, interest and a public apology. Listen/Read: https:// hackread.com/clop-ransomware-r esponds-shinyhunters-demands/ # Cybersecurity # Clop # ShinyHunters # Ransomware # Cybercrime # DarkWeb
-
E
Cyber extortion war: ShinyHunters holds rival Cl0p to ransom https://www. databreachtoday.com/blogs/cybe r-extortion-war-shinyhunters-holds-rival-clop-to-ransom-p-4192
-
- 1 day quiet
-
1
ShinyHunters breaches rival ransomware gang Clop's leak site
Days before the FBI claims surfaced, ShinyHunters said it hijacked the dark-web leak site of the Clop ransomware group, exploiting a software vulnerability to take control of much of its infrastructure and demanding money Clop made from its Oracle EBS hacking campaign.
-
3 outlets first by BleepingComputer, 2d ago · also Infosecurity, TechRadar · read ↗
-
first by Hackread, 2d ago · also RuntimeWire
1 more headline
- ShinyHunters hijacks Cl0p's leak site and demands an eight-figure payment RuntimeWire · 2d ago
-
C
ShinyHunters breached Cl0p and is demanding all the money Cl0-p made from the Oracle EBS hacking campaign
2 more of the top 3 · 7 posts in this stretch
-
One of the world’s biggest hacking groups just got hacked by another hacking group 😵💫 ShinyHunters says it broke into rival cybercrime gang cl0p’s dark-web site, exploited a software vulnerability and took control of much of its infrastructure. ShinyHunters wasn’t exactly
-
D
he ShinyHunters hacking and extortion gang has claimed a cyber-attack against a fellow cybercriminal outfit, the Clop ransomware group. 👀 https://www. infosecurity-magazine.com/news /shinyhunters-claim-hack-of-clop/ # infosec
-
Also covered reported alongside — the timeline has no entry for these yet
-
first by Reuters, 10h ago · also Engadget
1 more headline
-
first by NYT Politics, 9h ago · also NYT
-
first by ITPro, 2d ago · also Dark Reading
1 more headline
- ShinyHunters Hacked Clop. Now What About Clop's Victims? Dark Reading · 2d ago
-
first by Cyber Daily, 2d ago · also PCMag
1 more headline
and 2 smaller pieces
What people are saying 10 voices from 4 sites · best of 95 · verbatim
- How was several terabytes of data reportedly exfiltrated without triggering alarms, given the time such a transfer would take?
- What will ShinyHunters do with the data if the FBI does not comply with its demand to remove the disputed report?
- How many agents and applicants are actually affected, and has any of the data been verified beyond the initial 5,000-record sample?
- Today
-
G
Today in the SUN we feature an article from @reuters.com on ShinyHunters hackers saying they breached the FBI Read more below: www.reuters.com/world/shinyh... #cybersecurity @andyjabbour.bsky.social
-
Kash Patel is a degenerate moron appointed to his position to weaken our country in service to the Antichrist.
-
I'm curios to see how this plays out. Probably not that explosively, but would be nice to find some juicy details.
- Yesterday
-
The GOP mantra since the late '70s has basically been "Government is incredibly inefficient and broken, elect us so we can show you"
-
Maybe we should just give up on custodial trust re: people we don't know.If somebody wants data about me, they can write the query, I'll approve it, and it can hit a server designated by me and run by somebody I know personally.It's not just a privacy/security concern. People who get too close to large piles of sensitive data tend to start…
-
White-hat and grey-hat hackers need to be able to perform penetration testing without permission. Nobody is able to build secure systems. The best we can hope for is that the good guys find the vulnerabilities first and report them responsibly.This would be a huge inconvenience for companies and government organizations, so it probably won't…
-
It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do…
-
At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.China hacked 22.1 million records of US government employees:
-
I have dug into some of the sample with open source info and previously compromised data. It shows people in this FBI breach are U.S DOJ personnel
-
‼️ ShinyHunters has shared a message on their pay or leak portal to Director Brett Leatherman of the FBI Cyber Division and Director Kash Patel of the FBI:



