The FBI’s jobs portal displayed a fake seizure notice on Tuesday after ShinyHunters, a theft-and-extortion hacking crew the bureau warned companies about in May, replaced the applicant page with a banner declaring, “This site has been seized by ShinyHunters.” The group then claimed it had obtained FBI employees’ home addresses, phone numbers, and information about their families.
On its leak site and in messages to reporters, the group said it holds data “on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.” A representative told 404 Media, “We hacked the FBI. We hold data on all FBI employees and applicants.”
404 Media noted that criminals in the same ecosystem have previously used leaked phone records to track and harass the agents investigating them. Two people with knowledge of the incident told Politico that investigators are treating the group’s account as credible and as a significant counterintelligence failure. “It’s really bad,” one of them said.
ShinyHunters sent pieces of the alleged haul to multiple newsrooms, including 404 Media, Reuters, and BleepingComputer. The larger sample, reviewed by 404 Media and Reuters, appeared to cover about 5,000 alleged FBI employees, with rows listing addresses, phone numbers, dates of birth, and, in some cases, spouses. Outlets that examined the data said that parts of it look real, but none of it proves the bureau’s entire personnel system was emptied this week.
404 Media matched some sample phone numbers to the names sitting next to them and found other numbers already tied to U.S. Department of Justice personnel in a District 4 archive of older breaches. Reuters ran names, addresses, and Social Security numbers against credit-bureau records and that same archive and got at least 10 apparent hits, including FBI Director Kash Patel. A person familiar with the matter said some job descriptions lined up as well. Reuters still could not establish where the file was built, or whether it came from live FBI systems.
ShinyHunters PSA to the FBI https://t.co/lOm11yc0Ce pic.twitter.com/GMoahe2pWP
— vxdb (@vxdb) September 22, 2026
The FBI has said, “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” By Tuesday afternoon, the parody banner was gone, and Apply.fbijobs.gov and the Special Agent Applicant Portal were “currently unavailable.”
The site’s defacement message added “We have a lot more than we claim here,” and closed with “Thank you for your attention to this matter,” a nod to President Trump’s typical social media sign-off message. The group said the intrusion started Monday night.
The FBI is an unlikely ransom target, and when asked whether ShinyHunters would try to extort the bureau, its representative told 404 Media, “what we plan to do is not something I’d call extortion, maybe coercion.” They added, “This is not financially motivated.”
On its leak site, the group gave the FBI one week to correct or remove a May report that, in ShinyHunters’ telling, made “false allegations.”
ShinyHunters Say They Used a Zero-Day Bug
The ShinyHunters representative also told 404 Media the way in was a previously unknown bug in Oracle’s PeopleSoft software. From there, the group said, it reached Amazon’s GovCloud and pulled between 2 TB and 3 TB. It later told PCMag the jobs site was the entry point and that it was “able to laterally move to access different services and FBI databases. We downloaded all.”
None of that path has been confirmed by the FBI, Oracle, or Amazon. A Politico source said investigators had not verified the PeopleSoft story as of Tuesday. BleepingComputer reported a further claim that the group found a second PeopleSoft flaw and is already using it against other targets, including Fortune 500 companies. That is also unverified at this time.
The letter on the leak site is addressed to Patel and to Brett Leatherman, the assistant director of the FBI’s cyber division. ShinyHunters calls the document it wants killed a “2026 Quarter 2 FLASH report.” The public text that matches the grievance is a May 15 Public Service Announcement from the Internet Crime Complaint Center, issued after the group’s disruption of Instructure’s Canvas platform during finals week, in which it also claimed access to 275 million users’ data.
That advisory says ShinyHunters uses “real or exaggerated claims of access” to squeeze victims and that its actors “commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The group denies the swatting, any link to The Com, or holding embarrassing photos or videos for extortion. It told Axios that “low-skilled threat actors” have been borrowing the ShinyHunters name. It told The Register it wants the FBI “to correct or retract their statements they made, which included substantial false allegations.”
ShinyHunters has not said what it will do with the data it has if the bureau refuses.
Cynthia Kaiser, a former senior official in the FBI’s cyber division now at the security firm Halcyon, told Axios that when a group aims at the bureau itself, the FBI tends “to marshal additional resources to bring them more quickly to justice.” She also told Reuters why the file is the problem even if the motive is a press release. An older 2016 leak, she said, is still used to harass agents. “Once that information is stolen, it is used forever.”
Other prominent examples of ShinyHunters’ past work include dumping data from identity-protection firm Aura after the company declined to pay a ransom, advertising a purported file on 70 million AT&T subscribers, and an extortion scheme involving Pornhub Premium records.
Personal Data Is Leaking Everywhere
Massive personal data leaks are happening on a regular basis these days. Earlier this month, a dark-web shop put more than 153 million U.S. and Canadian driver’s license scans up for sale, including IDs tied to government officials. While many internet users don’t think twice about handing over personal information to third parties, a Polymarket bug reported this week showed how a Social Security number was enough for identity thieves to get into live accounts. That kind of exposure is especially dangerous for crypto users, as some criminals have pivoted from hacking exchanges over the internet to targeting people with physical attacks.