On 22 September they posted a message on their dark-web site saying they had broken into the bureau’s jobs portal and walked away with sensitive data on almost every current agent, former agent, and job applicant. Names, home addresses, phone numbers, spouse details, some medical information. They even defaced the site for a bit with a banner that read “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”

This one is not about money. The group says it is payback for a May FBI advisory that called out their tactics. They gave the bureau one week to take the report down or “correct” it. That deadline is still running as of now. The claim is serious enough that the FBI has confirmed it is investigating. Several news outlets that saw sample data say parts of it check out against public records.
Who these people actually are
ShinyHunters have been around since around 2019–2020. They started as a data-theft crew that steals large piles of personal information and then demands payment or they leak it. Nothing fancy about the name. It comes from Pokémon, the shiny rare versions of the creatures. Over the years they have hit big names in retail and telecom. Education too. The method stays more or less the same: find a weak door, take everything that is not locked down, then put the victim on a public clock.
They got louder this year. In April and May they hit Instructure, the company behind Canvas, the online learning system used by thousands of schools and universities. They claimed roughly 3.5 terabytes of data covering hundreds of millions of student and staff records across nearly 9,000 institutions. Schools had systems go down during exam season. Some campuses had to postpone finals or shift everything offline for a few days. Instructure eventually paid or reached some deal to stop the leak. The group later bragged about it as proof that their threats were real.
Then in late May and June they switched to a different trick. They found a zero-day in Oracle PeopleSoft, the big HR and student-administration software that a lot of universities still run. Google’s Mandiant team later confirmed the group had been exploiting it from 27 May through 9 June. More than 100 organisations got hit, most of them universities. The flaw let them run code without even logging in. Oracle rushed out an emergency patch on 10 June, but by then the damage was already done. Some of the stolen student records, including addresses and financial aid details, started appearing on leak sites.
Same group. Same pattern of going after widely used enterprise software, grabbing everything they can, and then making noise. The FBI hit is just the latest, and the first time they have gone after a major US law-enforcement agency this openly. That shift matters. Going after schools is one kind of risk. Going after the people who investigate cybercrime is another.
How they say the FBI breach happened
According to ShinyHunters, they found another zero-day in Oracle PeopleSoft on Monday night, 21 September.They used it against the FBI jobs portal, apply.fbijobs.gov. From there they moved sideways into systems sitting in Amazon’s GovCloud, the government version of AWS.
They claim the haul was two to three terabytes. That includes data from the jobs site itself, HR systems, something called MedLink that holds medical records, and parts of the criminal justice information systems. The group says the records cover almost every current FBI agent, former agents, and people who ever applied for a job there. Sample data they shared with reporters included names, home addresses, phone numbers, Social Security numbers in some cases, spouse details, and notes on what kind of work certain agents did. China counterintelligence work, Russia cases, cartels, that sort of thing.
They also briefly defaced the jobs site with their own banner before it went offline. The FBI has confirmed it is investigating “unauthorized activity” on FBIJobs.gov but has not yet said whether the full claim is true or how deep the access went. As of Thursday the portal was still down. People who tried to apply for Special Agent jobs or check application status just got an error page.
The demand is simple and public. The group addressed a message to FBI Director Kash Patel and the cyber division’s Brett Leatherman. They want the May advisory about ShinyHunters taken down or rewritten within one week. They keep repeating that this particular job is not about money. In their words, the FBI had spread “substantial false allegations” and they were “severely offended.”
I spent a while trying to figure out how much of the technical claim is new and how much is just them reusing the same PeopleSoft trick from June. The group insists this is a fresh zero-day they found only days earlier. Outside researchers have not confirmed a second PeopleSoft flaw yet. That part is still open.
Why this one feels different
Most of the time ShinyHunters just wants a payout. This time they keep saying the opposite. The May FBI advisory had accused them of exaggerating what they steal. It also said they harass victims and their families, and sometimes make threats that sound like swatting or worse. The group took it personally. Their public post calls the report “disinformation.” So the whole operation is framed as reputation repair, not a ransom note.
That does not make the data less dangerous if it is real. Home addresses and family details on thousands of agents create an obvious physical security problem. Foreign intelligence services would pay serious money for a clean list of who works China cases or Russia cases. Street-level criminal groups could use the same files to intimidate or track people. Reuters and 404 Media both checked samples against public records and older breaches and found matches, including some details that appeared to line up with Director Kash Patel himself. That is enough to make people inside the bureau nervous.
The group has not leaked anything yet. They are holding the files while the one-week clock runs. Whether they actually delete the data if the FBI changes the advisory is another question. Groups like this rarely walk away clean. They usually keep copies. Sometimes they sell the same data later to other buyers. Sometimes they just sit on it until it becomes useful again.
One thing that still confuses me is the timing. The advisory came out in May. The group waited until late September to hit back. Maybe they needed a clean entry point. Maybe they just got annoyed enough after other public mentions. Either way, the public nature of the demand is unusual for them. Most of their previous jobs stayed quieter until the ransom clock started.
This is not a one-off
Government targets have been getting hit harder and more often. In the first half of 2026 alone, Comparitech researchers logged roughly one ransomware or data-theft attack on a government body every single day. That is up from the second half of 2025. Local councils, state agencies, even federal systems keep showing up on leak sites. Some of those incidents stayed small. Others forced agencies offline for days and exposed citizen records by the tens of thousands.
Part of the problem is the software stack. Agencies still run the same big enterprise tools that everyone else does. PeopleSoft, various cloud HR portals, older case-management systems. When a zero-day appears in one of those platforms, the attackers do not need a special government exploit. They just scan the internet, find the exposed instances, and walk in. ShinyHunters already proved that with universities in June. Hitting the FBI jobs portal was the same playbook, just a higher-profile victim.
Another part is simple volume. Criminal groups now treat data theft as a reliable business. They steal first, then decide later whether to demand money, sell the files, or just hold them. Law-enforcement agencies sit on exactly the kind of personal and operational data that is valuable to both criminals and foreign spies. That makes them attractive even when the motive is partly ego, like this latest ShinyHunters job.
The FBI is still trying to work out whether the breach stopped at the jobs portal or reached deeper systems. Until that is clear, every agent whose home address might be sitting in a criminal group’s hands has a new problem. And the one-week deadline the group set is still counting down.
The pattern is not slowing down. Groups like ShinyHunters keep finding the same soft spots in widely used software, and government systems are still running a lot of it. This FBI claim may turn out smaller than the group is advertising, or it may turn out exactly as bad as they say. Either way, the fact that they felt confident enough to go public and set a public deadline tells you how little fear these crews currently have.
If the data is real, the damage is already done the moment it left the network. Addresses and family details do not become safe again just because a report gets rewritten. And if the FBI refuses to pull the advisory, we will find out soon enough what “further consequences” actually means in ShinyHunters’ language.
For now the portal is still down, the investigation is ongoing, and the clock the group set is still ticking. That is the whole situation as of this week.