{"id":3091,"date":"2026-09-23T07:21:17","date_gmt":"2026-09-23T07:21:17","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3091"},"modified":"2026-09-23T07:21:17","modified_gmt":"2026-09-23T07:21:17","slug":"shinyhunters-claims-fbi-breach-says-it-stole-data-on-agents-and-job-applicants","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3091","title":{"rendered":"ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 23, 2026<\/span><\/span><span class=\"p-tags\">Data Breach \/ Cybercrime<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBUSHHkVbK1vPy2WO_E9jEZ2NEd8UcPTpCFgCYTkbSPiSzDEpXRe6HRXan3z9Xg1huRk3-47hZbveFeG06vkRhAmGuL73zdPFjQEkVb6LISZIcHpPugYCMKQPtsEIihip_T7F1GWczJNWNTikwbM-SzC_UNeQsUjrg6AIeHYBwOnpOUlSOWyimHb07TzWz\/s1700-nu-rw-lo-l85-e365\/shinyhunters.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.<\/p>\n<p>\u00abWe have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,\u00bb the group <a href=\"https:\/\/www.ransomlook.io\/group\/shinyhunters\" target=\"_blank\">said<\/a> in a statement posted on their dark web site. \u00abWhether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.\u00bb<\/p>\n<p>The development was <a href=\"https:\/\/www.404media.co\/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees\/\" target=\"_blank\">first reported<\/a> by 404 Media. ShinyHunters said the FBI was targeted in response to a <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260515\" target=\"_blank\">May 2026 public service announcement<\/a> (PSA) that detailed the threat actor&#8217;s targeting of Canvas, an online Learning Management System (LMS), while urging victims not to pay.<\/p>\n<p>The attackers, in their own counter PSA, described them as \u00absubstantial false allegations,\u00bb adding, \u00abwe were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to &#8216;disrupt&#8217; our operations, an effort that ultimately proved unsuccessful.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The group has also rejected claims that it&#8217;s part of The Com decentralized collective, calling it a \u00abpropaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalizing this nonsense.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>A ShinyHunters spokesperson told The Register that the group exploited a new Oracle PeopleSoft zero-day vulnerability to gain remote code execution and deface the FBI&#8217;s jobs site with a \u00abThis site has been seized by ShinyHunters\u00bb banner. <a href=\"https:\/\/apply.fbijobs.gov\/\" target=\"_blank\">Visiting the site<\/a> now reads: \u00abScheduled Maintenance Underway. We&#8217;re Sniffing Out Site Updates for You!\u00bb<\/p>\n<p>There are currently no details of a PeopleSoft pre-authenticated RCE zero-day. However, ShinyHunters weaponized a similar flaw (CVE-2026-35273) in June 2026 to break into enterprise networks and extort victims.<\/p>\n<p>In a statement <a href=\"https:\/\/www.reuters.com\/world\/shinyhunters-hackers-say-they-breached-federal-bureau-investigation-no-immediate-2026-09-22\/\" target=\"_blank\">shared<\/a> with Reuters, the FBI said it&#8217;s \u00abaware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.\u00bb<\/p>\n<p>The disclosure comes after the high-profile hacking group hijacked the dark web leak site of the Clop (aka Cl0p) ransomware crew.<\/p>\n<p>\u00abIF YOU WANT TO SAVE YOUR BRAND AND NOT DIE BY MY HANDS: [&#8230;] let&#8217;s see how rich you really are,\u00bb the notice read. \u00ab2.333% of my net worth is a 8 figure amount, I hope you can pay that much because that is the demand, negotiable. Get your bosses in front of the white board in the war room. Clock is ticking moron. Kindly excuse our unprofessionalism.\u00bb<\/p>\n<p>\u00abShinyHunters; claim of an FBI breach is an unusually provocative move in the ongoing contest between law enforcement and cybercrime groups and should absolutely be taken seriously,\u00bb Etay Maor, VP of threat intelligence at Cato Networks, said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abWe have seen threat actors target businesses countless times, and nation states or nation-state-connected groups have compromised law-enforcement organizations before\u2014the 2015 OPM breach remains the most notable example\u2014but a cybercrime brand publicly claiming an FBI compromise is different.\u00bb<\/p>\n<p>\u00abOne small operational clue is the September 23 timestamp on the group&#8217;s post, while the news emerged on September 22 in the U.S. If that timestamp reflects the group&#8217;s real operating environment, it points toward activity in Asia. It is not a definitive attribution, but it is a detail investigators will examine alongside the technical evidence.\u00bb<\/p>\n<p>Maor also described ShinyHunters as a resilient criminal brand that has managed to outlast takedowns, arrests, and forum seizures by evolving its methods and attracting new operators, suggesting it&#8217;s more than a \u00abfixed set of people or infrastructure.\u00bb<\/p>\n<p>\u00abIts recent playbook has emphasized abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens, rather than simply breaking through a technical perimeter. That is the larger lesson here: organizations, including public-sector agencies, need to protect the identity and third-party trust relationships that attackers increasingly exploit.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 23, 2026Data Breach \/ Cybercrime The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3092,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[335,3512,278,1291,38,252,152,1615,36],"class_list":["post-3091","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-agents","tag-applicants","tag-breach","tag-claims","tag-data","tag-fbi","tag-job","tag-shinyhunters","tag-stole"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3091"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3091\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3092"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}