ShinyHunters, a data theft and extortion group known for stealing sensitive information from millions of cancer patients, students, and Carnival cruisers, claims it hacked the FBI to set the record straight.
In an interview with The Register, a ShinyHunters spokesperson stated the breach was 'fundamentally a public relations and marketing initiative for our business.' The group said it wanted to contest allegations in an FBI FLASH bulletin that accused ShinyHunters of using harassment tactics such as threatening texts and swatting. 'We demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers,' the spokesperson said.
The breach reportedly exploited an Oracle PeopleSoft zero-day vulnerability in the FBIJobs.gov portal, which remains offline. The group claims it then accessed managed servers on AWS GovCloud and stole 'thousands of personnel files' of current, former, and prospective FBI employees. Sample files reviewed by journalists contained agents' home addresses, phone numbers, Social Security numbers, job titles, and emergency contact information.
The FBI confirmed the incident to The Register. 'While the point of breach is still undetermined – whether a third-party or the FBI's enterprise – we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,' an FBI spokesperson said.
ShinyHunters insisted the hack was not about money; no extortion demand was made. Instead, they framed the breach as a demonstration of credibility for 'future corporate partners' – a term security observers note refers to the organizations the group typically extorts.