ShinyHunters alleges FBI hack, stealing personal data of agents and applicants

ShinyHunters, a known cybercriminal group, claims to have breached the FBI and stolen sensitive data on thousands of agents and job applicants. The hackers posted the claim on their dark web leak site and provided a sample to 404 Media, which verified some names, addresses, and phone numbers. The group says the hack is not financially motivated and demands the FBI remove a report they dispute, while the stolen data could pose a counterintelligence threat.
The breach reportedly unfolded through two connected intrusions. ShinyHunters first compromised an Oracle PeopleSoft server, a platform commonly used for human resources and recruitment functions, then moved laterally into an Amazon-hosted government cloud environment containing applicant and agent records. The group claims to have extracted terabytes of data.
This incident marks the second known compromise of FBI systems this year. Earlier, unidentified hackers accessed a system managing real-time wiretaps and foreign intelligence warrants. Separately, FBI director Kash Patel's personal email was breached by an Iran-linked group. ShinyHunters also defaced the FBI's jobs portal, which displayed a maintenance notice at the time of reporting.
The alleged breach could have significant national security implications. If the stolen data is verified and includes personal information on FBI agents and applicants, foreign intelligence services may attempt to use it for coercion or recruitment efforts. Affected individuals and their families could face heightened surveillance or targeting. The incident may also erode public confidence in federal cybersecurity practices, particularly given this is the second reported FBI system compromise this year. The hackers' stated non-financial motive suggests the data may be weaponized for reputational or operational purposes.