ShinyHunters hackers claim to have stolen the personal data of “all” FBI employees and job applicants, in a breach that security experts warn poses a significant national security and counterintelligence risk.
The group reportedly gained access to the FBI’s recruitment website by exploiting a vulnerability in Oracle’s PeopleSoft product. According to the claims, ShinyHunters now holds sensitive information relating to both current bureau employees and individuals who applied for FBI positions. The same group was previously linked to a breach that disrupted software used by 9,000 schools during final exams in May.
FBI recruitment site taken offline
Following the incident, the FBI Jobs website was taken offline. The apply.fbijobs.gov page displayed a maintenance notice, while the main FBI Jobs home page returned a “503 Service Temporarily Unavailable” error. A separate page confirmed that the site and the Special Agent Application Portal were unavailable.
An FBI spokesperson said the bureau was aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal, along with an alleged impact to FBI employee personally identifiable information. The spokesperson added that the point of breach remained undetermined, whether through a third party or the FBI’s own enterprise, and that the bureau was actively investigating while working with third-party providers to mitigate risk.
A breach unlike typical extortion
ShinyHunters has been connected to numerous ransomware attacks, including a breach of 4.4 million TransUnion credit records and access to servers belonging to Rockstar Games, the developer of the Grand Theft Auto series. The group typically demands extortion payments to prevent it from leaking stolen data.
This attack, however, appears to differ in motive. The group reportedly wants the FBI to correct what it describes as false allegations in a Public Service Announcement issued about it. Reporting notes that ShinyHunters actors commonly use harassment strategies, including threatening text messages and phone calls to victims and their family members, and in some cases swatting.
In an email, a representative of the group stated that it was not extorting the FBI and that the action was not financially motivated, adding that its sole intention was to “set the record straight.”
The nature of the stolen material has raised concerns that extend well beyond corporate extortion. Analysts noted that the data presents significant national security and counterintelligence risks, and that it is now held not by a foreign intelligence agency but by a group of likely younger, English-speaking hackers. FBI Director Kash Patel testified during a Senate Judiciary Committee hearing on 15 September 2026.