Hacker Group ShinyHunters Claims FBI Breach as 5,000-Record Sample Raises Fears for Agents' Families
A sample reportedly containing 5,000 employee records was shared with 404 Media, while the FBI jobs website displayed a ShinyHunters message and applicant portals went offline

On Tuesday, hacker group ShinyHunters claimed it breached FBI-related services in the US and stole personal data on employees and applicants. It supplied 404 Media with a sample appearing to contain 5,000 employee records, some with spouse details, raising fears for agents' families.
A ShinyHunters message appeared on the FBI jobs website and its application portals became unavailable. The group claims to hold records on every employee and applicant, but the scope and origin of the alleged theft remain unverified.
ShinyHunters Sample Puts Personal Details in Focus
The group's representative claimed it held data on 'all FBI employees and applicants'. The material allegedly included names, home addresses, phone numbers and information about spouses.
The sample supplied to the publication appeared to list addresses, dates of birth and phone numbers for 5,000 employees, with spouse details in some entries. It cannot establish the group's much broader claim.
To test a portion of the file, 404 Media entered some phone numbers into OSINT Industries, an open-source intelligence service. They matched people bearing the names in the sample.
Searches through Darkside, a compromised-data tool made by cybersecurity company District 4 Labs, also associated some numbers with US Department of Justice personnel. Those checks support parts of the sample, but they do not establish when the records were obtained, how many people are affected or whether FBI systems were breached.
An address and a spouse's details could expose a family to unwanted contact if the records are authentic. The publication has previously reported that criminals in the same ecosystem as ShinyHunters used stolen phone records to track, intimidate and harass FBI agents investigating them.
It also raised the possibility that foreign intelligence agencies could use personnel data. There is no evidence in the report that this alleged cache has been used for either purpose.
ShinyHunters Describes Its Alleged Route Into FBI Systems
On Tuesday, the FBI jobs site displayed 'this site has been seized by ShinyHunters', echoing language used in law enforcement takedown notices. At the time of the report, the site instead said that apply.fbijobs.gov and the Special Agent Applicant Portal were unavailable.
The defacement and outage are observable events, though neither alone confirms the claimed data theft.
The defacement asserted that information on current and former employees and all applicants had been compromised, including personally identifiable and protected health information. The notice offered no evidence to verify the full scope of that assertion. The FBI did not immediately respond to the publication's request for comment.
Asked how it had gained access, the group's representative alleged that ShinyHunters exploited a previously unknown flaw in Oracle's PeopleSoft software, reached AWS GovCloud servers and downloaded between two and three terabytes of data.
Those technical claims have not been independently verified in the report. The representative said the intrusion took place on Monday night.
ShinyHunters typically tries to obtain payment by threatening to release stolen material, according to the report. Asked whether it intended to extort the FBI, the representative described its plan as 'not something I'd call extortion, maybe coercion' and added, 'This is not financially motivated'.
© Copyright IBTimes 2026. All rights reserved.

























