ShinyHunters claims breach exposing FBI agent home addresses and roles

By The Conservative Desk (/journals/conservative-desk)
The FBI’s jobs portal at apply.fbijobs.gov carried a banner that read, “This site has been seized by ShinyHunters.” The phrasing copied the seizure notices the bureau itself posts when it takes down criminal sites. Below that line the group added a longer claim: “All FBI data was compromised including PII/PHI on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.” The banner closed with “Thank you for your attention to this matter.”
A criminal group had just posted a public claim on the government’s own hiring door that it held the private lives of federal agents.
A ShinyHunters representative handed Joseph Cox at 404 Media a sample of roughly 5,000 records. “We hacked the FBI. We hold data on all FBI employees and applicants,” the representative said. The rows carried names, home addresses, phone numbers, dates of birth, and in places the details of spouses. 404 Media became the first outlet to report the breach after examining that file. Staff there ran some of the phone numbers through the OSINT Industries tool, an open-source platform that cross-checks public records. The numbers matched people who shared the same names listed in the sample. Several of those numbers linked to Justice Department personnel. Charlotte Hazard of the National News Desk noted the same day that a ShinyHunters representative had told 404 Media the group held names, addresses, and phone numbers on FBI employees. The sample remained the first concrete measure of what the group said it possessed.
ShinyHunters told Lawrence Abrams of BleepingComputer that the attack took place Monday night. The group claimed initial access through an unpatched Oracle PeopleSoft zero-day, a previously unknown software flaw that granted remote code execution—the power to run arbitrary commands on the compromised system. PeopleSoft is the Oracle-owned human-resources and recruiting suite used to store applicant and employee data. From that entry the attackers said they moved laterally into AWS GovCloud services, the Amazon cloud platform built to hold sensitive United States government information, naming three of them: Criminal Justice, Human Resources, and Medlink. Between two and three terabytes of data were allegedly stolen. Abrams received the technical account along with a screenshot of the defaced apply.fbijobs.gov path. In parallel, Alex Lekander of CyberInsider reported the same PeopleSoft entry, the remote code execution claim, and the lateral move into the named GovCloud systems. One screenshot shared with CyberInsider showed a page at apply.fbijobs.gov under the /PSEMHUB/ path displaying what appeared to be system information, which the group called its way in. Neither outlet verified the zero-day itself.
The group claims data on about 38,000 FBI personnel and applicants. The alleged material includes names, addresses, phone numbers, dates of birth, Social Security numbers, spouse information, emergency contacts, and medical information. Reuters matched details of at least nine individuals, and later more than twenty-two, via credit-bureau records and previously breached data preserved by District 4 Labs. The matches did not prove FBI origin. Reuters could not establish where the data had come from, or whether it had been stolen from the bureau’s internal systems as the group claimed. Attempts to reach the people whose details sat in the sample were unsuccessful.
The data allegedly names 14 China-unit staffers, 9 Russia-role staffers, 3 Iran- or Hezbollah-focused staffers, 18 in intercept or surveillance roles, and 11 in human-intelligence roles. Home addresses, and emergency contacts attached to those assignments would hand any hostile service or violent crew a working list of who inside the bureau works the hardest targets and where their families live. That is the national-sovereignty stake inside a personnel spreadsheet. It is also the public-safety stake for every agent whose spouse now appear beside a work role the bureau does not advertise.
ShinyHunters gave BleepingComputer two sample records it said came from the intrusion. One allegedly held information associated with an FBI special agent. The other was allegedly tied to Kash Patel. BleepingComputer declined to publish either record and did not independently verify their authenticity or source.
In the interview with 404 Media the ShinyHunters representative set out the motive in plain terms. “What we plan to do is not something I'd call extortion, maybe coercion,” the representative said. The same voice added that the operation was “not financially motivated.” ShinyHunters then published a lengthy statement on its dark-web leak site. The group framed the breach as retaliation for the FBI’s May 2026 FLASH report, which had described the group’s methods and advised targets not to make payments. Lev Shevtsov, summarizing the account for UA.News, recorded that May-report motive as the stated reason for the attack. Zack Whittaker of TechCrunch noted the same non-financial claim. The statement gave the bureau one week to correct or remove the report. The group declined to say whether it would dump the data if the demand were ignored.
Ashley Belanger of Ars Technica reported the one-week demand directed at the bureau over the May advisory. Joe Tidy of the BBC wrote that the group claims private data on around 38,000 people, including every agent’s name, role, badge number, home address, phone numbers, and spouse information, and that the BBC had reviewed a small portion that appeared to be genuine. Tzippy Shmilovitz of Ynet reported that two people familiar with the breach said investigators believe the group’s claims are credible and that the incident represents a significant counterintelligence failure. “The situation is very serious,” one source told Politico, as carried in that account.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said. After discovery, the FBI jobs site went offline. The Special Agent Applicant Portal went offline with it. Apply.fbijobs.gov stopped returning its ordinary pages and displayed service notices instead. One notice stated that apply.fbijobs.gov and the Special Agent Applicant Portal were currently unavailable. Other notices announced scheduled maintenance. ShinyHunters told BleepingComputer that the FBI became aware of the intrusion on Tuesday and immediately took the affected systems offline, with access across multiple networks terminated at once. “They literally pulled the plug on everything,” ShinyHunters said.
Taxpayers already paid for PeopleSoft and for AWS GovCloud. Those platforms exist so the government can hire agents, run background checks, and hold medical and human-resources files without scattering them across the open internet. A recruiting portal that can be reached by a claimed zero-day, followed by lateral movement into Criminal Justice, HR, and Medlink systems, is a failure at a core function only the federal government performs. Limited government is not an argument for thin defenses around the people sworn to enforce the law. The rule of law depends on agents who can work China cases, Russia cases, intercept work, and human intelligence without finding their home addresses and spouses in a criminal sample. Free enterprise did not put those names on a dark-web clock; a government system that was supposed to keep them did.
Reuters still could not establish that the data came from inside the bureau. The jobs portal remains down. The one-week deadline ShinyHunters set for retraction of the May FLASH report is the next fact on the calendar.



