Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    September 24, 2026

    A week of AI coding cut a quantum-safe bitcoin transaction estimate from $320 to $66

    September 24, 2026

    Distant time crystals can somehow fall into the same rhythm

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
    • A week of AI coding cut a quantum-safe bitcoin transaction estimate from $320 to $66
    • Distant time crystals can somehow fall into the same rhythm
    • Anthrax suspected in 46 hippo deaths in Zambia amid potential spillover to humans
    • Go-ahead for DNO’s North Sea drilling ops with Odfjell Drilling-managed rig
    • Guest opinion: Voters must stand up to leaders who act above the law
    • The Guardian view on vocational GCSEs: why now? | Editorial
    • Senate Republicans block Democratic effort to end US war with Iran | US Senate
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 23, 2026Data Breach / Cybercrime

    The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.

    “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” the group said in a statement posted on their dark web site. “Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.”

    The development was first reported by 404 Media. ShinyHunters said the FBI was targeted in response to a May 2026 public service announcement (PSA) that detailed the threat actor’s targeting of Canvas, an online Learning Management System (LMS), while urging victims not to pay.

    The attackers, in their own counter PSA, described them as “substantial false allegations,” adding, “we were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to ‘disrupt’ our operations, an effort that ultimately proved unsuccessful.”

    Cybersecurity

    The group has also rejected claims that it’s part of The Com decentralized collective, calling it a “propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalizing this nonsense.”

    A ShinyHunters spokesperson told The Register that the group exploited a new Oracle PeopleSoft zero-day vulnerability to gain remote code execution and deface the FBI’s jobs site with a “This site has been seized by ShinyHunters” banner. Visiting the site now reads: “Scheduled Maintenance Underway. We’re Sniffing Out Site Updates for You!”

    There are currently no details of a PeopleSoft pre-authenticated RCE zero-day. However, ShinyHunters weaponized a similar flaw (CVE-2026-35273) in June 2026 to break into enterprise networks and extort victims.

    In a statement shared with Reuters, the FBI said it’s “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”

    The disclosure comes after the high-profile hacking group hijacked the dark web leak site of the Clop (aka Cl0p) ransomware crew.

    “IF YOU WANT TO SAVE YOUR BRAND AND NOT DIE BY MY HANDS: […] let’s see how rich you really are,” the notice read. “2.333% of my net worth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism.”

    “ShinyHunters; claim of an FBI breach is an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups and should absolutely be taken seriously,” Etay Maor, VP of threat intelligence at Cato Networks, said.

    Cybersecurity

    “We have seen threat actors target businesses countless times, and nation states or nation-state-connected groups have compromised law-enforcement organizations before—the 2015 OPM breach remains the most notable example—but a cybercrime brand publicly claiming an FBI compromise is different.”

    “One small operational clue is the September 23 timestamp on the group’s post, while the news emerged on September 22 in the U.S. If that timestamp reflects the group’s real operating environment, it points toward activity in Asia. It is not a definitive attribution, but it is a detail investigators will examine alongside the technical evidence.”

    Maor also described ShinyHunters as a resilient criminal brand that has managed to outlast takedowns, arrests, and forum seizures by evolving its methods and attracting new operators, suggesting it’s more than a “fixed set of people or infrastructure.”

    “Its recent playbook has emphasized abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter. That is the larger lesson here: organizations, including public-sector agencies, need to protect the identity and third-party trust relationships that attackers increasingly exploit.”

    Agents Applicants breach claims data FBI job ShinyHunters stole
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    Island Raises $400 Million at $6.4 Billion Valuation

    AI-Powered Campaign Targets Hundreds of Online Retailers

    Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    September 24, 2026

    A week of AI coding cut a quantum-safe bitcoin transaction estimate from $320 to $66

    September 24, 2026

    Distant time crystals can somehow fall into the same rhythm

    September 24, 2026

    Anthrax suspected in 46 hippo deaths in Zambia amid potential spillover to humans

    September 24, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    September 24, 2026

    A week of AI coding cut a quantum-safe bitcoin transaction estimate from $320 to $66

    September 24, 2026

    Distant time crystals can somehow fall into the same rhythm

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.