
ShinyHunters claims theft of 2TB of FBI records and leaks sample of 5,000 personnel files
Extortion group ShinyHunters took the FBIjobs.gov recruitment portal offline and released personal records of 5,000 employees, demanding that the FBI retract a May 2026 security advisory.
Breach claims and recruitment portal outage
The cybercriminal extortion group ShinyHunters announced on 22 September 2026 that it penetrated internal systems of the Federal Bureau of Investigation and extracted two terabytes of personnel data. The group defaced the official recruitment portal, FBIjobs.gov, replacing the landing interface with ASCII group branding and an announcement that the site was seized. By Tuesday afternoon, both the primary jobs portal and the Special Agent Applicant Portal went offline with system unavailable notices. ShinyHunters stated to reporters that the intrusion exploited a zero-day vulnerability in Oracle PeopleSoft, enabling remote code execution across systems supporting human resources, MedLink, and Criminal Justice Information Services.
Verification of leaked personnel records
To substantiate the breach, ShinyHunters provided a sample dataset of approximately 5,000 personnel files to the outlet 404 Media. The leaked files contained names, home addresses, phone numbers, email addresses, dates of birth, Social Security numbers, duty assignments, and spouse details. Journalistic reviews matched listed phone numbers to active United States Department of Justice employees. Cross-referencing against credit bureau files and dark-web repositories maintained by District 4 Labs confirmed matches in at least 10 cases, including the personal file of FBI Director Kash Patel. The bureau employs approximately 38,000 individuals across its divisions.
- China-linked hackers breach FBI wiretap management network
- FBI publishes bulletin detailing ShinyHunters extortion methods and swatting allegations
- ShinyHunters defaces FBIjobs.gov and releases 5,000-record personnel sample
- FBI confirms active investigation into unauthorized portal activity
Dispute over May extortion bulletin
ShinyHunters stated that the operation was not financially motivated and did not demand ransom payments. The group said the intrusion responded to a security advisory published by the FBI on 15 May 2026, following a cyberattack on Instructure and its Canvas learning system. In that notice, the FBI warned that the group uses swatting, threatening text messages, and phone calls to intimidate victims. ShinyHunters contested the claims, asserting that the bureau misattributed actions by other hackers to their group and demanding a formal retraction.
We want the FBI to correct or retract their statements they made, which included substantial false allegations.
Counterintelligence risks and federal response
The FBI National Press Office acknowledged the disruption and confirmed an active inquiry into unauthorized activity on the portal.
The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.
Security analysts warned that the release of residential addresses and Social Security numbers poses severe counterintelligence risks, exposing agents and their families to foreign intelligence services and criminal networks. Allan Liska, an intelligence analyst at Recorded Future, noted the permanent distribution risks of leaked data.
The data is out there and has likely been repeatedly downloaded and passed around to other threat actors.
The incident follows a breach in April 2026, when hackers linked to China accessed an FBI wiretap administration system. Former federal cyber division official Cynthia Kaiser noted that intrusions targeting the bureau typically lead federal authorities to deploy additional investigative resources to track down the attackers.

