The hacking collective ShinyHunters said it compromised multiple FBI-related services in an attack carried out on Monday night, according to a representative who spoke to 404 Media. The representative claimed the group exploited a zero-day vulnerability in Oracle’s PeopleSoft software to gain access to Amazon Web Services GovCloud servers, from which they downloaded between two and three terabytes of data.
“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative told 404 Media. The group also defaced the FBI’s federal jobs application website, posting a message that read “this site has been seized by ShinyHunters,” echoing the seizure notices the FBI itself places on taken-down websites. The defacement added that “All FBI data was compromised including PII/PHI on incumbent and former FBI employees and all applicant information.” The message ended with a mock of President Trump’s Truth Social style: “Thank you for your attention to this matter.”
As of late Tuesday, the FBI jobs website displayed a notice stating: “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.” The FBI did not immediately respond to a request for comment.
If confirmed, the breach would have severe national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used similar stolen data—including phone records—to track, intimidate, and harass FBI agents investigating them. The highly sensitive data could also be valuable to foreign intelligence agencies seeking to understand how the U.S. law enforcement and intelligence agency operates. 404 Media reviewed a sample file containing data on 5,000 alleged employees and used the open-source tool OSINT Industries to match some phone numbers to names in the sample.
ShinyHunters typically targets organizations and then attempts to extort them, though it is not yet clear if the group has made any specific demands.