conv.

All stories
SecurityMoving now · day 5

ShinyHunters hackers claim breach of FBI, stealing data on agents and applicants

The FBI says it is investigating a criminal hacking group's claim to have stolen "very sensitive data" on thousands of agents and job applicants and defaced its jobs website.

What to know

  • ShinyHunters claims to hold 2-3TB of data on nearly all FBI agents and job applicants, including home addresses, phone numbers, and spouse information.
  • The FBI has confirmed it is investigating but has not verified the scope or authenticity of the stolen data.
  • The group says its motive is not financial extortion but forcing removal of a report it claims contains false allegations about it.
  • Security researchers warn the breach carries counterintelligence risk, as foreign agencies or criminals could use the data to identify, track, or coerce FBI agents and their families; it follows an earlier 2026 breach of an FBI wiretap-warrant system and a hack of Director Kash Patel's personal email.

The dispute Some commenters push back on the fatalism, arguing security quality varies by organization rather than being universally impossible: 'the fatalism is understandable, but "no one can keep a database safe" isn't quite right. Some organizations do a better job than others.' (Transformanshen, Hacker News, #2155319965) · positions read across 96 posts and comments

most voices

No large database can realistically be kept secure; breaches like this are now inevitable and unremarkable.

  • “It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.”

    coldpie · Hacker News ↗
some voices

This reflects a broader failure of US institutions to invest seriously in cybersecurity defense.

  • “America is at war and losing comically. Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.”

    bearjaws · Hacker News ↗
some voices

Mocking FBI/administration leadership over the breach's optics and timing.

  • “I see Kash is doing a great job.”

    altnoaa.bsky.social · Bluesky ↗
some voices

The real fix is not collecting or retaining sensitive data in the first place.

  • “The only safe data is data not collected, directly followed by data that is only stored on paper.”

    niemandhier · Hacker News ↗

ShinyHunters Hacking group behind the claimed breachFBI Targeted agencyKash PatelKash Patel FBI DirectorJoseph Cox / 404 Media Reporters who first obtained hacker sample data

ShinyHunters hackers claim breach of FBI, stealing data on agents and applicants
404media.co

How it unfolded 7 developments, newest first · click a bar or a number to jump articlesvideospostscomments

Peak 67 pieces in one hour at Yesterday, 2 PM; 312 pieces over 5 days (153 articles · 4 videos · 117 posts · 38 comments) Sep 19, 9 AM — 1 piece · 1 post — Mastodon 1Sep 19, 10 AM — quietSep 19, 11 AM — quietSep 19, 12 PM — quietSep 19, 1 PM — quietSep 19, 2 PM — quietSep 19, 3 PM — 1 piece · 1 post — Mastodon 1Sep 19, 4 PM — 1 piece · 1 post — Hacker News 1Sep 19, 5 PM — quietSep 19, 6 PM — quietSep 19, 7 PM — quietSep 19, 8 PM — quietSep 19, 9 PM — quietSep 19, 10 PM — quietSep 19, 11 PM — quietSep 20, 12 AM — quietSep 20, 1 AM — quietSep 20, 2 AM — quietSep 20, 3 AM — quietSep 20, 4 AM — quietSep 20, 5 AM — quietSep 20, 6 AM — 1 piece · 1 post — Mastodon 1Sep 20, 7 AM — quietSep 20, 8 AM — 1 piece · 1 post — Mastodon 1Sep 20, 9 AM — quietSep 20, 10 AM — quietSep 20, 11 AM — quietSep 20, 12 PM — quietSep 20, 1 PM — quietSep 20, 2 PM — quietSep 20, 3 PM — quietSep 20, 4 PM — quietSep 20, 5 PM — quietSep 20, 6 PM — quietSep 20, 7 PM — quietSep 20, 8 PM — quietSep 20, 9 PM — quietSep 20, 10 PM — 1 piece · 1 post — Mastodon 1Sep 20, 11 PM — quietSep 21, 12 AM — quietSep 21, 1 AM — quietSep 21, 2 AM — quietSep 21, 3 AM — quietSep 21, 4 AM — 1 piece · 1 post — X 1Sep 21, 5 AM — 1 piece · 1 post — Mastodon 1Sep 21, 6 AM — quietSep 21, 7 AM — quietSep 21, 8 AM — 2 pieces · 1 article · 1 post — Mastodon 1, Newswires 1Sep 21, 9 AM — 2 pieces · 1 article · 1 post — Mastodon 1, Newswires 1Sep 21, 10 AM — quietSep 21, 11 AM — 1 piece · 1 post — Mastodon 1Sep 21, 12 PM — 12 pieces · 11 articles · 1 post — Newswires 11, Mastodon 1Sep 21, 1 PM — quietSep 21, 2 PM — 1 piece · 1 post — Mastodon 1Sep 21, 3 PM — 1 piece · 1 article — Newswires 1Sep 21, 4 PM — quietSep 21, 5 PM — quietSep 21, 6 PM — quietSep 21, 7 PM — quietSep 21, 8 PM — 1 piece · 1 post — Hacker News 1Sep 21, 9 PM — quietSep 21, 10 PM — quietSep 21, 11 PM — quietYesterday, 12 AM — quietYesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — 1 piece · 1 post — Mastodon 1Yesterday, 4 AM — 1 piece · 1 post — Mastodon 1Yesterday, 5 AM — quietYesterday, 6 AM — quietYesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — quietYesterday, 10 AM — quietYesterday, 11 AM — 9 pieces · 9 articles — Newswires 9Yesterday, 12 PM — 4 pieces · 2 articles · 2 posts — Mastodon 2, Reddit 1, Newswires 1Yesterday, 1 PM — 17 pieces · 11 articles · 5 posts · 1 comment — Newswires 6, Google News 5, Mastodon 4, +1 moreYesterday, 2 PM — 67 pieces · 43 articles · 23 posts · 1 comment — Newswires 40, Mastodon 17, X 3, +4 moreYesterday, 3 PM — 4 pieces · 1 article · 3 posts — Mastodon 2, Hacker News 1, Newswires 1Yesterday, 4 PM — 14 pieces · 2 articles · 5 posts · 7 comments — Hacker News 7, Mastodon 5, Newswires 2Yesterday, 5 PM — 18 pieces · 5 articles · 7 posts · 6 comments — Hacker News 6, Mastodon 6, Newswires 5, +1 moreYesterday, 6 PM — 8 pieces · 2 articles · 2 posts · 4 comments — Hacker News 4, Newswires 2, Bluesky 1, +1 moreYesterday, 7 PM — 9 pieces · 1 article · 1 video · 5 posts · 2 comments — Mastodon 5, Hacker News 2, Newswires 1, +1 moreYesterday, 8 PM — 7 pieces · 1 video · 2 posts · 4 comments — Hacker News 4, Mastodon 2, YouTube 1Yesterday, 9 PM — 6 pieces · 1 article · 4 posts · 1 comment — Mastodon 3, Bluesky 1, Reddit 1, +1 moreYesterday, 10 PM — 4 pieces · 1 post · 3 comments — Hacker News 3, Reddit 1Yesterday, 11 PM — 4 pieces · 1 article · 1 post · 2 comments — Hacker News 2, Bluesky 1, Newswires 1Today, 12 AM — 2 pieces · 1 post · 1 comment — Bluesky 1, Reddit 1Today, 1 AM — 1 piece · 1 comment — Hacker News 1Today, 2 AM — 4 pieces · 2 articles · 2 posts — Newswires 2, Bluesky 1, Mastodon 1Today, 3 AM — quietToday, 4 AM — 4 pieces · 1 article · 2 posts · 1 comment — Hacker News 2, Mastodon 1, Newswires 1Today, 5 AM — quietToday, 6 AM — 3 pieces · 1 post · 2 comments — Reddit 3Today, 7 AM — 3 pieces · 3 posts — Mastodon 3Today, 8 AM — 2 pieces · 2 posts — Mastodon 2Today, 9 AM — 2 pieces · 2 posts — Bluesky 1, Mastodon 1Today, 10 AM — 8 pieces · 6 articles · 1 post · 1 comment — Newswires 6, Hacker News 1, Mastodon 1Today, 11 AM — 20 pieces · 18 articles · 2 posts — Newswires 18, Mastodon 2Today, 12 PM — 7 pieces · 4 articles · 2 posts · 1 comment — Newswires 3, Bluesky 1, Google News 1, +2 moreToday, 1 PM — 10 pieces · 5 articles · 1 video · 4 posts — Newswires 5, Mastodon 2, Bluesky 1, +2 moreToday, 2 PM — 6 pieces · 3 articles · 3 posts — Newswires 3, Mastodon 2, Bluesky 1Today, 3 PM — 19 pieces · 14 articles · 1 video · 4 posts — Newswires 14, Mastodon 2, X 2, +1 moreToday, 4 PM — 4 pieces · 1 article · 3 posts — Bluesky 1, Hacker News 1, Reddit 1, +1 moreToday, 5 PM — 8 pieces · 5 articles · 3 posts — Newswires 4, Mastodon 3, Google News 1Today, 6 PM — 3 pieces · 1 article · 2 posts — Mastodon 2, Newswires 1Today, 7 PM — 1 piece · 1 post — Mastodon 1Today, 8 PM — 1 piece · 1 post — Mastodon 1Today, 9 PM — quietToday, 10 PM — 3 pieces · 1 article · 2 posts — Mastodon 2, Newswires 1 12–456–7
Sep 20Sep 21yesterdaytodaynow · 11:14 PM ET
  1. 7

    FBI confirms it is investigating theft of 'very sensitive data'

    The FBI formally said Wednesday it is investigating the criminal hacking group's claims that it stole 'very sensitive data' belonging to thousands of agents and applicants and compromised the bureau's jobs website; the story was picked up by AP, PBS NewsHour, Al Jazeera, the Guardian and others.

    “very sensitive data…”
    — FBI (describing hackers' claims)
    1. first by PBS NewsHour, 5h ago · also Philadelphia Inquirer, Federal News Network, KSTP-TV, Boston Globe, Hindustan Times

      1 more headline
    2. first by PBS NewsHour, 4h ago

    • rowat_c@mastodon.social

      In its message, # ShinyHunters said it would give the bureau one week to correct or remove what it said were false allegations contained in an # FBI public advisory from May that described the organization as a “#cybercriminal group specializing in large-scale data breaches and extortion.” https:// apnews.com/article/fbi-crimina…

      rowat_c@mastodon.socialMastodon2h agoview on Mastodon ↗
    2 more of the top 3 · 3 posts in this stretch
    • us@pubeurope.com

      https://www. europesays.com/thestates/9938/ FBI investigates hackers’ claim to have stolen sensitive employee data, compromised jobs website | National News # alabama # crime # cybercrime # FbiCriminalHackingGroupJobsWebsiteBeach # GeneralNews # Hacking # InformationSecurity # technology # USNews # WashingtonNews

      us@pubeurope.comMastodon3h agoview on Mastodon ↗
    • sambowne@infosec.exchange

      EXCLUSIVE: Hacked FBI data has sensitive information about employees’ intelligence roles https://www. reuters.com/world/hacked-fbi-d ata-has-sensitive-information-about-employees-intelligence-roles-2026-09-23/

      sambowne@infosec.exchangeMastodon18m agoview on Mastodon ↗
    all of them →
  2. 6

    Reports detail scale2-3TB of data, thousands of records

    Coverage converged on the scale of the alleged theft — roughly 2-3TB of data covering thousands of agents and applicants — with outlets noting the group's stated goal was not financial extortion this time.

    “I see Kash is doing a great job.”
    — @altnoaa.bsky.social, Bluesky user · source
    • gate15.bsky.social

      Today in the SUN we feature an article from @reuters.com on ShinyHunters hackers saying they breached the FBI Read more below: www.reuters.com/world/shinyh... #cybersecurity @andyjabbour.bsky.social

      gate15.bsky.socialBluesky10h ago3▲view on Bluesky ↗
    2 more of the top 3 · 14 posts in this stretch
    • KrissyKat@hoosier.social

      "There has been a breach and all of the FBI employment records have been stolen. Please accept this one year complimentary credit monitoring service. Thanks, Kash." https://www. washingtonpost.com/national-se curity/2026/09/23/hacking-group-claims-have-stolen-thousands-fbi-employee-records/ # news # tech # technology

      KrissyKat@hoosier.socialMastodon8h ago1▲view on Mastodon ↗
    • ShinyHunters posted a letter to Kash Patel and FBI Cyber's Brett Leatherman on its leak site. It claims it breached FBI systems (CJ, HR, Medlink) and holds data on nearly every agent and job applicant, and gives the FBI a week to pull its Q2 2026 FLASH report on the group.

      @ransom_dbX7h agoview on X ↗
    all of them →
  3. 5

    ShinyHunters insists the hack is 'not financially motivated'

    The group told reporters it was not seeking a ransom but rather demanding the FBI remove a report it says contains false allegations about ShinyHunters, calling its intended action 'coercion' rather than extortion.

    “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job.”
    — ShinyHunters, Dark web leak site post · source
    1. first by Cyber Daily, 1d ago

    • zackwhittaker@mastodon.social

      FBI tells me it's "aware of claims" of a hack affecting its jobs site and is "currently investigating.” ShinyHunters, meanwhile, tell me that they are confident that they have data "on mostly all of FBI" and a substantial amount of applicants' data. More: https:// techcrunch.com/2026/09/22/hack…

      zackwhittaker@mastodon.socialMastodon15h ago156▲view on Mastodon ↗
    2 more of the top 3 · 18 posts in this stretch
    • Not just government employees, employees of government contractors who held or applied for security clearances. I’ve never worked for the government but the CCP got my SF-86. My employer’s infosec group told us they believe that the same group was also responsible for the Mariott data breach in the same timeframe and that it was believed to be…

      buildsjetsHacker News1d agoview on Hacker News ↗
    • I hate they’ve done this. Couldn’t they do something productive and positive by releasing the Epstein files with only victim names redacted?

      Alarmed_Expression77r/technology22h agoview on r/technology ↗
    all of them →
  4. 4

    Reuters reports hackers' claim, no immediate FBI comment

    Reuters picked up the ShinyHunters claim that they breached the Bureau, noting the FBI had not immediately commented on the specifics beyond acknowledging the investigation.

    1. first by TechRadar, 1d ago · also Silicon Republic, Beehaw, HN Best, HN Frontpage, 404 Media, Mashable +6

      6 more headlines
    2. first by Security Affairs, 1d ago · also The Register, CyberInsider, 404 Media, BleepingComputer, GovExec, Nextgov/FCW +1

      5 more headlines
    2 more claims →
    • BrentD@techhub.social

      Hackers have apparently breached FBI systems and have extracted personal data “on all FBI employees and applicants.” The data reportedly includes FBI agents’ names, home addresses, phone number, and information on their spouse. 404 Media reports having direct contact with a representative of the hackers known as "ShinyHunters". https://www…

      BrentD@techhub.socialMastodon1d ago1▲view on Mastodon ↗
    2 more of the top 3 · 42 posts in this stretch
    • Yes, huge amounts of your medical information is for sale. In 2024, Change Healthcare (CHC) was hacked and held ransom. The hackers were in the system for over a week before everything was pulled offline.CHC is the largest claims clearinghouse in the US; about 100m people's insurance claims go through there each year.The hackers asked for a ransom…

      tyreHacker News1d agoview on Hacker News ↗
    • New: hackers say they have data on all FBI employees and spouses. I got a sample of 5,000 alleged employees, including name, physical address, phone number, and in some cases spouses. Could be a massive national security and counterintelligence risk

      @josephfcoxX1d agoview on X ↗
    all of them →
  5. 3

    TechCrunch details breach path and FBI's initial response

    TechCrunch reported the hackers breached an Oracle PeopleSoft server used for HR/job applications, then pivoted into an Amazon-hosted government cloud; the FBI said it was 'aware of claims' and investigating, while the jobs site and agent applicant portal were defaced and shown as down for maintenance.

    “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
    — FBI spokesperson
    1. first by Digit, 1d ago · also The Hacker News, Cyber Security News, KEYT-TV, Hackread

      4 more headlines
    2. first by The Record, 12h ago

    2 more claims →
    • zackwhittaker@mastodon.social

      "We're sniffing out site updates for you!" is definitely one way to say "we were hacked and thousands of FBI agents and applicants had their information stolen." Those federal puppers are fucking adorable though. https://www. 404media.co/we-hacked-the-fbi- hackers-say-they-have-data-on-all-fbi-employees/

      zackwhittaker@mastodon.socialMastodon1d ago95▲view on Mastodon ↗
    2 more of the top 3 · 9 posts in this stretch
    • mayamedia.bsky.social

      This is massive, China & Russia must be laughing hysterically, & Kash Patel should not have a job by the end of today. And Trump's meeting with the Chinese tomorrow. 😂😂 Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

      mayamedia.bsky.socialBluesky1d ago5▲view on Bluesky ↗
    • Thats a major attack on the US.If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?

      smalltorchHacker News1d agoview on Hacker News ↗
    all of them →
  6. 2

    ShinyHunters claims it stole data on 'all FBI employees and applicants'

    A representative of the hacking group told 404 Media it had breached multiple FBI-related services and obtained agents' names, home addresses, phone numbers, and information on their spouses, based on a sample of 5,000 alleged agent records.

    “We hacked the FBI. We hold data on all FBI employees and applicants,…”
    — ShinyHunters representative
    1. first by Axios, 11h ago · also Fox News, Guardian, Globe and Mail, Bloomberg, Associated Press, Orlando Sentinel +4

      7 more headlines
    2. first by The Hindu, 20h ago · also Daily Maverick, Channel News Asia, Reuters

    11 more claims →
    • lauren@mastodon.laurenweinstein.org

      BREAKING: Hackers say they have [personal] data on all FBI employees https://www. 404media.co/we-hacked-the-fbi- hackers-say-they-have-data-on-all-fbi-employees/

      lauren@mastodon.laurenweinstein.orgMastodon1d ago36▲view on Mastodon ↗
    2 more of the top 3 · 3 posts in this stretch
    • Hackread@mstdn.social

      Clop has resurfaced on its own onion site with a message for ShinyHunters after the group hijacked its leak site and demanded an eight-figure payment, interest and a public apology. Listen/Read: https:// hackread.com/clop-ransomware-r esponds-shinyhunters-demands/ # Cybersecurity # Clop # ShinyHunters # Ransomware # Cybercrime # DarkWeb

      Hackread@mstdn.socialMastodon2d agoview on Mastodon ↗
    • euroinfosec@infosec.exchange

      Cyber extortion war: ShinyHunters holds rival Cl0p to ransom https://www. databreachtoday.com/blogs/cybe r-extortion-war-shinyhunters-holds-rival-clop-to-ransom-p-4192

      euroinfosec@infosec.exchangeMastodon1d agoview on Mastodon ↗
    all of them →
  7. 1 day quiet
  8. 1

    ShinyHunters breaches rival ransomware gang Clop's leak site

    Days before the FBI claims surfaced, ShinyHunters said it hijacked the dark-web leak site of the Clop ransomware group, exploiting a software vulnerability to take control of much of its infrastructure and demanding money Clop made from its Oracle EBS hacking campaign.

    1. 3 outlets first by BleepingComputer, 2d ago · also Infosecurity, TechRadar · read ↗

    2. first by Hackread, 2d ago · also RuntimeWire

      1 more headline
    3 more claims →
    • campuscodi@mastodon.social

      ShinyHunters breached Cl0p and is demanding all the money Cl0-p made from the Oracle EBS hacking campaign

      campuscodi@mastodon.socialMastodon3d ago24▲view on Mastodon ↗
    2 more of the top 3 · 7 posts in this stretch
    • One of the world’s biggest hacking groups just got hacked by another hacking group 😵‍💫 ShinyHunters says it broke into rival cybercrime gang cl0p’s dark-web site, exploited a software vulnerability and took control of much of its infrastructure. ShinyHunters wasn’t exactly

      @MarioNawfalX2d ago14▲view on X ↗
    • dannyjpalmer

      he ShinyHunters hacking and extortion gang has claimed a cyber-attack against a fellow cybercriminal outfit, the Clop ransomware group. 👀 https://www. infosecurity-magazine.com/news /shinyhunters-claim-hack-of-clop/ # infosec

      dannyjpalmerMastodon2d ago8▲view on Mastodon ↗
    all of them →

Also covered reported alongside — the timeline has no entry for these yet

  1. first by Reuters, 11h ago · also Engadget

    1 more headline
  2. first by NYT Politics, 10h ago · also NYT

  3. first by ITPro, 2d ago · also Dark Reading

    1 more headline
  4. first by Cyber Daily, 2d ago · also PCMag

    1 more headline

and 2 smaller pieces

What people are saying 10 voices from 4 sites · best of 96 · verbatim

Still unanswered
  • How was several terabytes of data reportedly exfiltrated without triggering alarms, given the time such a transfer would take?
  • What will ShinyHunters do with the data if the FBI does not comply with its demand to remove the disputed report?
  • How many agents and applicants are actually affected, and has any of the data been verified beyond the initial 5,000-record sample?