Wednesday, September 23, 2026
WECUNews
Tech & AI

Hackers Say They Broke Into the FBI. They Don't Want Ransom. They Want an Apology

A hacking group claims it stole terabytes of data on FBI agents and job applicants, not for ransom, but to force the bureau to walk back a warning about them.

By Lynn Matthews - September 23, 2026
Hackers Say They Broke Into the FBI. They Don't Want Ransom. They Want an Apology

What Happened

ShinyHunters claims it gained access to FBI systems Monday night, then posted its claims publicly to its dark-web leak site and, per CyberScoop, temporarily defaced the FBI's jobs website the following day. FBIjobs.gov went offline Tuesday afternoon and remained unavailable as of Wednesday morning, a separate step from the initial access the group claims it had the night before. The group says it exploited a vulnerability in Oracle's PeopleSoft platform, the system the FBI uses for HR and job applications, though it remains unconfirmed whether that was a genuine new zero-day or the same critical, already-known flaw the group is documented to have used in a separate, earlier campaign this year. That earlier flaw, CVE-2026-35273, is a PeopleSoft remote-code-execution vulnerability that requires no login credentials to exploit, rated a near-maximum 9.8 out of 10 in severity. Oracle patched it on June 10, 2026. Mandiant attributed active exploitation of that flaw to ShinyHunters against more than 100 organizations, most of them colleges and universities, in a campaign running from May 27 to June 9, with CISA separately confirming the vulnerability was under active exploitation and adding it to its Known Exploited Vulnerabilities catalog, CISA's role was confirming the flaw's exploitation, not attributing it to ShinyHunters specifically. That PeopleSoft campaign came after, and is separate from, the FBI's May 15 warning, which followed an earlier ShinyHunters attack on Instructure/Canvas; the two are sequential incidents in the same broader ShinyHunters education-sector activity that year, not the same campaign. If the FBI breach turns out to use that same, already-patched PeopleSoft flaw, it would mean the bureau went unpatched against a publicly known critical vulnerability for more than three months, but that link is not established, only possible. From there, ShinyHunters claims it pivoted, per TechCrunch's reporting, into an Amazon-hosted government cloud system storing agent and applicant records.

An FBI spokesperson gave this response, quoted by both Axios and CyberScoop: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." That's an acknowledgment that something happened, not a confirmation of the hackers' claims about what was taken or how much.

What the Hackers Say They Took

ShinyHunters claims it obtained between two and three terabytes of data, pulled from the FBI's HR systems and a service called Medlink, including names, agent status, emails, phone numbers, home addresses, and in some cases information about spouses and siblings, along with Social Security numbers, covering what the group describes as "almost all" current and former FBI agents and people who've applied for a job with the bureau. As proof, the group handed a sample of roughly 5,000 records to the outlet 404 Media. Cybersecurity researchers who reviewed that sample appear to confirm the attack itself is legitimate, per Axios, though Axios is explicit that it has not been able to corroborate that the stolen data itself is legitimate or recent, only that the underlying attack appears real. None of the specific figures above, the data volume, the Social Security numbers, the "almost all agents" claim, have been confirmed by the FBI. They are the hackers' account of what they took, not an established fact.

If the claims hold up, the stakes are real. Cybersecurity analyst Dan Calderone told Nextgov that FBI personnel data of this kind could be weaponized well beyond the bureau itself: "foreign intelligence services would love to have it," and, more immediately, FBI agents and their spouses "could have their home addresses posted publicly within a week if this threat is followed through."

Why They Say They're Doing This

This is where the story gets stranger than a typical extortion attempt. ShinyHunters is demanding the FBI retract or amend a Public Service Announcement, issued via IC3 on May 15, 2026, following an earlier ShinyHunters attack on Instructure, the company behind Canvas, a widely used central hub for K-12 and university coursework, exams and communication. That Instructure/Canvas incident predates and is distinct from the separate PeopleSoft campaign detailed above, which ran from late May into June. That May 15 bulletin, per Nextgov's reporting, described ShinyHunters' harassment tactics, including threatening communications, swatting (making false emergency calls to send police to someone's home), and exaggerating the group's access to personal information. ShinyHunters says the bulletin made "substantial false allegations" about its tactics, and in its own words, "We want the FBI to correct or retract their statements." The group's statement was addressed directly to FBI Cyber Division Assistant Director Brett Leatherman and FBI Director Kash Patel, with a one-week deadline attached, per CyberScoop's reporting.

Whether that stated motive is the real one, or cover for a more conventional extortion play, is not something any outlet has been able to verify independently. Nextgov notes cybersecurity experts view the group's denials, of harassment tactics and of financial motivation alike, skeptically. It's the hackers' framing of their own actions, presented as fact by them, not confirmed by investigators.

Not the First Time This Year

If confirmed, this would mark another blow to FBI cybersecurity following a genuinely rough 2026. TechCrunch notes the bureau has already dealt with an earlier, confirmed intrusion into wiretap and surveillance systems this year, a breach of actual FBI infrastructure. Separately, and not the same incident, Director Kash Patel's personal Gmail account was also compromised earlier this year, an episode the FBI described as historical and said contained no government data, not a breach of an agency network. Conflating the two would overstate what's actually been confirmed, but taken together they still point to a pattern worth watching at an agency whose entire function depends on protecting sensitive information.

How Investigators Actually Track a Group Like This

It's fair to ask how a group can breach the FBI itself and seemingly walk away clean. The limits are real: these crews are loosely organized, made up largely of young, technically skilled people spread across multiple countries, and past law-enforcement action against this loose collective has generally caught affiliates rather than core leadership, with the group continuing to operate afterward regardless. With that limit up front, "nothing can be done" still overstates it. These investigations are slow and mostly invisible, not nonexistent.

Hacking groups tend to reuse tools, infrastructure, and habits across multiple attacks, and that repetition is what eventually links one breach to another. Investigators cluster these crews by reused infrastructure, leak-site branding, and consistent exploit choices, here, the PeopleSoft vulnerability, rather than any single behavioral tell, since tactics like phone-based social engineering are documented across several overlapping crews in this space, not uniquely ShinyHunters.

That approach has produced real arrests before. Sébastien Raoult, a French national tied directly to ShinyHunters, was arrested in Morocco in 2022, extradited to the United States, and sentenced in January 2024 to three years in prison and $5 million in restitution. Four more affiliates using aliases including "ShinyHunters" were arrested across France in June 2025. Separately, individuals tied to the broader Scattered Spider collective this group has worked alongside have also faced arrest and prosecution, including four charged in the UK in mid-2025, per Krebs on Security's reporting.

None of that means an arrest here is likely or imminent, for the reasons above. But it does mean the process is real, just measured in months and years rather than headlines.

What's Still Unconfirmed

To be clear about where the reporting actually stands as of this writing: the FBI has confirmed it's investigating a security incident affecting its jobs website, and outside researchers say a sample of leaked data looks legitimate. What remains unconfirmed by the FBI or any independent party is the full scope of the breach, the specific categories and volume of data taken, whether Social Security numbers are genuinely included, and whether ShinyHunters' stated motive is the true one. This article will be updated as the FBI's investigation produces more than a one-line statement.

 

Sources & References:

ABC 3340: High-profile hacking group claims it hacked the FBI and stole data on employees

Axios: FBI investigates claim notorious hacking group stole employee data

CyberScoop: ShinyHunters claims attack on FBI exposes almost all agents

TechCrunch: Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data

Politico: ShinyHunters FBI cyber hack

Centre Daily Times: ShinyHunters FBI hack coverage

Nextgov/FCW: ShinyHunters claims FBI data theft, demands bureau retract cyber warning

Oracle Security Alert: CVE-2026-35273

Cybersecurity Dive: ShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoft

Huntress Threat Library: ShinyHunters Threat Actor Profile

Krebs on Security: UK Charges Four in 'Scattered Spider' Ransom Group

 

Have a correction or tip? See our corrections policy or contact the newsroom.

Comments

to join the discussion.

Loading comments...