ShinyHunters Breaches FBI Jobs Portal, Stealing Data on Nearly All Agents
Updated
Updated · Fox News · Sep 23
ShinyHunters Breaches FBI Jobs Portal, Stealing Data on Nearly All Agents
3 articles · Updated · Fox News · Sep 23
Summary
FBIjobs.gov was taken offline Tuesday and remained down Wednesday as the FBI investigated a breach that ShinyHunters said exposed data on nearly all agents and job applicants.
A sample reviewed by Reuters showed names, home addresses, Social Security numbers, assignments and sometimes family members' names, raising identity-theft and national-security risks.
ShinyHunters said it targeted the bureau after the FBI's May 2026 warning about the group's extortion tactics urged victims not to pay ransom demands.
The group, active since at least 2019, has been tied to major breaches including Rockstar Games and a May attack on Canvas that disrupted U.S. schools.
How did a notorious hacking group manage to breach the FBI's highly secure recruitment portals?
Will the FBI bow to hacker demands and retract its cyber warning to prevent a massive data leak?
ShinyHunters’ 2026 FBI Breach: 3TB Data Theft, Agent Exposure, and the Collapse of Federal Digital Trust
Overview
On September 22, 2026, ShinyHunters exploited a critical flaw in Oracle PeopleSoft on FBIjobs.gov, using scanning tools to find the vulnerability and a crafted SSRF attack to gain command-line access. They found stored credentials and, due to poor network segmentation, moved into the FBI’s backend HR database on AWS GovCloud, exfiltrating terabytes of sensitive data. The breach exposed personal information of FBI personnel and their families, making them targets for retaliation and harassment. This incident, triggered by a prior FBI advisory, highlights how weaknesses in third-party software and network design can lead to severe operational and personal risks for government agencies.