news.mlab.sh
Back to the feed
threat-intel

ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

CriticalCVSS 9.8
Summary

The notorious cybercrime group ShinyHunters claims they breached FBI systems and stole sensitive data, including information on nearly all FBI agents and job applicants. They are demanding the FBI retract a threat report and alleging it contains false accusations. Initial analysis suggests the data they provided is authentic, stemming from a PeopleSoft zero-day exploit.

The cybercrime group ShinyHunters is alleging a successful breach of FBI systems and demanding the retraction of a recent FBI threat report. They claim to have compromised Criminal Justice, HR, and Medlink services, and now possess data on nearly all FBI agents and job applicants. To demonstrate their claims, ShinyHunters defaced a subdomain on the FBI’s jobs website, fbijobs.gov, posting the message “This site has been seized by ShinyHunters”. The targeted domain is currently down for maintenance.

In a lengthy statement on its website, ShinyHunters said it was responding to an FBI FLASH report from May that made what it called false allegations against the group. They gave the FBI one week to correct or remove the report. The group specifically disputed claims in the FBI report that they exaggerate their access to pressure victims into paying, use harassment tactics such as swatting or threats to victims’ families, and falsely claim to possess compromising photos or videos. ShinyHunters insisted its threats are genuine, denied ever conducting swatting or contacting victims’ families, and denied being “sextortionists”.

The group also denied any affiliation with The Com, calling it a fabricated narrative pushed by the cybersecurity industry, and framed its statement as an exercise of First Amendment rights rather than an act of ransom, coercion, or extortion.

FBI investigating ShinyHunters’ claims. In a statement to the media, the FBI said it is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating”. The agency has not shared any additional information.

ShinyHunters provided 404 Media with a sample of the stolen data allegedly representing the personal information of 5,000 FBI employees, including names, phone numbers, and home addresses. 404 Media and others who reviewed the sample reported that at least some of the data appears authentic, but the origin of the data has yet to be confirmed. The hackers told 404 Media that they exploited a zero-day vulnerability in Oracle’s PeopleSoft product to breach FBI systems, from which they allegedly stole 2-3 TB of information.

The cybersecurity community confirmed in June that ShinyHunters had been exploiting a PeopleSoft zero-day to steal data from organizations. It’s unclear whether the cybercrime group found a new zero-day or targeted the FBI through the same vulnerability, tracked as CVE-2026-35273.

Read the full article at SecurityWeek