ShinyHunters Claims an FBI Breach. Only Part of That Claim Checks Out.
The hacking group says it holds two to three terabytes of FBI personnel data and wants the bureau to retract a warning about its own conduct, not a payment. The FBI has confirmed the jobs site was hit. Nothing else.
By Mara Voss, Technology
· 3 min read · Updated

Key Takeaways
- •ShinyHunters claims it stole two to three terabytes of FBI personnel data by breaching an Oracle PeopleSoft server and pivoting into an Amazon-hosted government cloud.
- •404 Media verified a 5,000-record sample against public data and found it accurate, the only independent confirmation so far.
- •The FBI's September 22, 2026 statement confirmed only that FBIjobs.gov was affected and that it is investigating, not the volume or scope ShinyHunters claims.
- •ShinyHunters is demanding the FBI retract a May 15, 2026 warning about the group's harassment and swatting tactics within one week, rather than asking for payment.
- •ShinyHunters has claimed credit for breaches at Instructure, Salesforce, Snowflake, and McKesson earlier in 2026, according to the security firm Halcyon.
On September 22, 2026, a hacking group called ShinyHunters sent a message to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman: "We hacked the FBI. We hold data on all FBI employees and applicants." The FBI's public statement that day confirmed one piece of that: FBIjobs.gov was affected and the bureau is investigating. It did not confirm the scope, the volume, or the word all.
The short answer
ShinyHunters claims it took two to three terabytes of data on current, former, and prospective FBI employees, including names, home addresses, phone numbers, and spouse information, after breaching an Oracle PeopleSoft server and pivoting into an Amazon-hosted government cloud. Outside verification so far covers a 5,000-record sample that 404 Media checked against public records and found accurate. The FBI has not confirmed the total volume.
What's confirmed, what isn't
404 Media, the outlet ShinyHunters contacted first, reviewed a sample of 5,000 employee records and matched the names, addresses, and phone numbers against public data. That sample checked out. The FBI's statement stopped well short of backing the rest: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." No mention of terabytes. No mention of almost all agents. No confirmation, and no denial, of the PeopleSoft-to-AWS pivot ShinyHunters described to reporters. The FBI's job application portal, meanwhile, greeted visitors with a plain notice reading "currently down for maintenance," the same defacement ShinyHunters says it left behind.
2 to 3 terabytes
data ShinyHunters claims to have taken
The FBI's public statement confirms a breach affecting FBIjobs.gov. It does not confirm a volume.
A breach demand that isn't about money
The unusual part of ShinyHunters' message is what it's asking for. Most extortion groups want payment, or set a deadline before they publish data. ShinyHunters wants the FBI to retract a May 15, 2026 public service announcement that described the group's tactics, including harassment of victims' families and swatting, and gave the bureau one week to do it. The group says the hack was not financially motivated.
“Foreign intelligence services would love to have it.”
Calderone was skeptical of the non-financial framing. If ShinyHunters follows through, he said, agents' home addresses could be posted publicly within a week. A stated grievance and a threat to publish federal employees' home addresses are not mutually exclusive, and nothing in ShinyHunters' message rules out both being true at once.
A group with a track record, in both directions
ShinyHunters has claimed credit for breaches at Instructure, Salesforce, Snowflake, and McKesson earlier in 2026, a run that has made cybersecurity firms take its claims seriously. Cynthia Kaiser, an analyst at the security firm Halcyon, said the FBI targeting shows a lack of discipline that historically has led to takedowns. Analysts at Flashpoint noted the attack adds to the group's credibility as a threat, while also flagging that ShinyHunters has historically been hyperbolic about the criticality of the data it steals.
For now, the gap between what's confirmed and what's claimed is the story. A defaced jobs portal and a checked sample of 5,000 records are real. Two to three terabytes covering almost all FBI personnel is still ShinyHunters' number, not the FBI's. If the bureau's investigation lands closer to the hackers' version than its own one-line statement, the exposure isn't reputational. It's a list of home addresses attached to federal badges.
- ShinyHunters
- FBI data breach
- cybersecurity
- data extortion
- FBIjobs.gov
Sources
- 01'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees, 404 Media404media.co
- 02ShinyHunters claims FBI data theft, demands bureau retract cyber warning, Nextgov/FCWnextgov.com
- 03Hacking group ShinyHunters claims it breached the FBI, stole agents' and applicants' data, TechCrunchtechcrunch.com
- 04ShinyHunters claims attack on FBI exposes almost all agents, CyberScoopcyberscoop.com
Corrections
No corrections have been made to this article.
About the reporter
Technology Reporter, Trestlewire
I spent seven years as a product manager at a mid-size SaaS company before I ever wrote a sentence for pay, which means I have sat through more roadmap reviews than most people would tolerate in a lifetime. I watched a scheduling feature get rebranded three times before it shipped, and I watched a launch date slide past four straight quarters while the slide deck stayed exactly the same. That is where the question I still ask every day came from: does this actually ship, or is it a demo.
Read full bio and all stories →