On the night of Monday, September 21, 2026, the FBI's job application portal stopped recruiting. In place of vacancy listings, visitors found a seizure banner, an Umbreon Pokémon logo, and a taunt: "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS. rooting your systems since '19 ;)" (BleepingComputer). The defacement was the announcement. ShinyHunters, an extortion crew that has spent years extracting data from cloud platforms, healthcare organizations, universities, and retailers, was claiming a break-in at the agency whose agents investigate data extortion for a living (CyberScoop).
By the end of the week, samples of what the crew says it took were circulating among journalists and security researchers: roughly 5,000 records carrying FBI employees' names, home addresses, phone numbers, dates of birth, Social Security numbers, badge numbers, job titles, assigned field offices, and details about spouses and siblings (Lawfare; The Register; Nextgov/FCW; BBC News). The BBC reviewed files that looked like fitness-for-work medical examinations, complete with blood and urine test results and doctors' notes (BBC News).
The demand was the strange part. ShinyHunters says it is not asking the FBI for money. It wants a document retracted: a public advisory, published in May, that described the group's harassment tactics and warned victims that its claims might be exaggerated. The crew set a one-week deadline, and on September 28, BBC News reported it was threatening to publish the stolen databases within four days (BBC News; CyberScoop).
If the samples are genuine, and several checks suggest at least parts of them are, the breach touches thousands of current and former agents, job applicants, and employees in some of the bureau's most sensitive assignments, from human intelligence to the unit that builds its hacking tools. The FBI has acknowledged a claimed compromise of the FBIJobs.gov portal, and says the point of entry, whether at a third-party provider or inside the bureau's own enterprise, is still undetermined (The Register). What makes this more than another data leak is the direction of the pressure. A financially driven cybercrime crew appears to be using stolen state data to bend the state's own public statements. That is new ground, and it lands on a counterintelligence problem the United States has never fully solved.
What the crew says it took, and what checks out
ShinyHunters' own words, posted on its leak site in a message addressed to FBI Director Kash Patel and Brett Leatherman, assistant director of the bureau's Cyber Division, were direct: "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job" (Lawfare; CyberScoop). The group claims between 2TB and 3TB of data, drawn from FBI Criminal Justice, human resources, and a service it called Medlink, and stored in FBI-managed AWS GovCloud infrastructure (BleepingComputer).
Those are claims, not findings. The FBI has not confirmed the scale or authenticity of the haul. What reporting has established so far is narrower but substantial. The roughly 5,000-entry sample sent to news outlets included names, home addresses, phone numbers, dates of birth, badge numbers, job titles, assigned field offices, Social Security numbers, email addresses, and emergency contact information, along with details about spouses and siblings (Lawfare; Nextgov/FCW; The Register; BBC News). 404 Media, which first reported the breach, put some of the entries through open-source intelligence tools and found that some of the information checked out (Lawfare; BleepingComputer). The BBC described the samples it saw, including records of senior officials such as deputy directors, as appearing genuine (BBC News).

The medical material is the most intimate layer. BBC News viewed stolen fitness-for-work examinations containing blood and urine test results and doctors' notes on conditions including allergies and high cholesterol, material the broadcaster reported relates to thousands of special agents (BBC News). One record the group shared with BleepingComputer allegedly contained information associated with Director Patel himself; the outlet has not verified it (BleepingComputer).
Skepticism is warranted, and not only because the FBI has said little. Flashpoint analysts noted that "ShinyHunters has in the past been hyperbolic about the criticality of the data they've accessed," even while describing the group as "a legitimate threat" (CyberScoop). The FBI's own May advisory warned that the group's claims might be exaggerated (Lawfare). The irony is hard to miss: a crew famous for overstating what it holds produced a sample that, so far, holds up. Cynthia Kaiser, a former deputy assistant director in the FBI's Cyber Division now at Halcyon, told the BBC that ShinyHunters appear to have already lost control of some of the data, which is circulating in online groups of cyber researchers (BBC News).
How the group claims it got in
ShinyHunters told BleepingComputer the initial break came through a previously unknown remote code execution flaw in Oracle PeopleSoft, exploited Monday night on the FBI's application portal, followed by lateral movement into FBI-managed AWS GovCloud servers (BleepingComputer). The outlet could not independently verify the zero-day, the lateral movement, or the data volume, and said it contacted Oracle and Google Cloud's Mandiant team about the claimed flaw (BleepingComputer). Neither Amazon nor Oracle responded to requests for comment from Nextgov/FCW (Nextgov/FCW). BleepingComputer also noted this would not be the first time ShinyHunters has been linked to exploitation of a previously unknown Oracle vulnerability (BleepingComputer).
The FBI's response, at least by the crew's account, was swift: "They literally pulled the plug on everything" (BleepingComputer). The application portal and the Special Agent Application Portal were still unavailable days later (CyberScoop; The Register).
The FBI's official position leaves the mechanics open. On September 22 it said it was investigating "unauthorized activity affecting FBIjobs.gov" (CyberScoop). Three days later, a spokesperson told The Register the bureau is "actively and aggressively investigating" and that "the point of breach is still undetermined," including whether it was "a third-party or the FBI's enterprise," while working closely with the third-party providers that support FBIJobs.gov (The Register). That phrasing matters. A public-facing jobs portal is the kind of system that touches the outside world by design, and it is run with commercial partners. Denis Calderone, CTO at Suzu Labs, put the defensive lesson bluntly: "At the FBI, a website built for strangers to upload resumes allegedly led straight into GovCloud." His advice to other organizations running PeopleSoft was to get it off the public internet where possible, place what must stay public behind a web application firewall, and make sure administrative components such as the /PSEMHUB/ path shown in the crew's screenshot are not externally reachable (Security Magazine).
Every public account so far describes an external attack. No reporting has pointed to an insider, and no evidence of one has surfaced publicly. But until the bureau determines the entry point, the difference between a flaw in a vendor's system and a flaw in the bureau's own remains unresolved (The Register).
A demand for a retraction, not a ransom

The grievance dates to May 15, when the FBI published a public service announcement describing ShinyHunters' methods (Nextgov/FCW). The advisory followed the crew's breach of Instructure's Canvas, an education platform used by thousands of U.S. institutions, after which the group claimed data tied to hundreds of millions of students, teachers, and staff (CyberScoop; The Register; Nextgov/FCW). The bulletin said ShinyHunters uses "harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting," and that the criminals "may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist" (The Register). It also associated the crew with The Com, a loose cybercrime community tied to breaches and cryptocurrency theft (BleepingComputer).
ShinyHunters answered with its own "PSA" on its leak site, addressed to Patel and Leatherman, denying affiliation with The Com, denying swatting, and denying that it falsely claims compromising material (CyberScoop; BleepingComputer). Then it gave the bureau a week to correct or withdraw the report, insisting the demand was not extortion (BleepingComputer).
Speaking to The Register, a spokesperson for the crew was candid about the logic: "Our breach of the FBI was executed specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report," adding that "this was fundamentally a public relations and marketing initiative for our business." The same spokesperson described the operation as "protecting our business as any other business would do," and said demonstrating "technical superiority" positions the crew as "a professional and predictable entity" for what it called "future corporate partners" (The Register). Most people would call those partners victims.

Why would an extortion crew risk everything to kill an advisory? Because the advisory attacks its product. The crew's business is the credible threat: pay, or your data appears online. An FBI bulletin telling victims that the group exaggerates, harasses families, and may bluff about embarrassing material devalues every future threat it issues. Kevin Kirkwood, CISO at Exabeam, drew the line precisely: "The distinction is between correcting the record and coercing the author," and "demanding a retraction under pressure offers evidence of a desire to control the narrative, not proof that the narrative is false" (Security Magazine). Calderone, for his part, seriously doubts the FBI will act on the threat (Security Magazine).
Why the stolen files are a counterintelligence problem
To see the damage, follow what the data allows an adversary to do. First, identification: names resolve to home addresses, phone numbers, email accounts, and family members. Second, mapping: job titles and field office assignments reveal how the bureau organizes itself. Third, targeting: identified people with known roles can be phished, approached for recruitment, or assessed for blackmail, and medical records are classic coercion material. Fourth, physical risk: home addresses of agents who investigated you, combined with the swatting tactics the bureau's own advisory describes, create exposure no badge protects against.
The role data makes all of this worse. Reporting by Reuters, relayed by Lawfare, found job descriptions in the breached dataset spanning human intelligence, the running of human spies, "data intercept," "telecom intercept," and "clandestine technical operations," with portfolios covering Russia, China, Iran, Hezbollah, and critical infrastructure (Lawfare). Nextgov/FCW, citing two people familiar with the matter, reported that the exposed employees include analysts working on Russia, China, Hezbollah, and cartels, members of the FBI's Remote Operations Unit, which builds specialized tools to target computers and networks, and at least one person in the FISA Management Unit, which handles applications and renewals under the Foreign Intelligence Surveillance Act, the statute governing US foreign-intelligence surveillance (Nextgov/FCW). 404 Media's additional digging reportedly identified staff in the Major Cybercrime Unit and the Remote Operations Unit (Lawfare).
In plain terms, the crew appears to have obtained a partial map of the bureau's own spies and hackers, people who depend on anonymity to do their jobs. A former FBI agent put the stakes to the BBC in one line: "This is really bad for our undercover agents" (BBC News). The same former investigator described group discussions about "violence-as-a-service" attacks by young online gangs, and BBC noted that crews similar to ShinyHunters have been linked to swatting and even petrol bomb attacks on law enforcement officers (BBC News). Michael McPherson, a former agent now at ReliaQuest, called the breach "a security threat which cuts to the core of agent safety, particularly their families" (BBC News).
The applicant files extend the problem forward in time. People who applied to the FBI include future hires, some headed toward work on sanctions evasion, export controls, or foreign intelligence operations. A foreign service that holds the file could watch those careers for years, approaching people before they are trained to resist approaches (Lawfare).
This is why analysts reach for the Office of Personnel Management comparison. The 2015 OPM breach, attributed to Chinese state-linked intruders, exposed background-investigation files on more than 21 million people. Doc McConnell, a former cyber policy official at the White House and CISA, told Nextgov/FCW that OPM "resulted in a decade of credit monitoring for millions of affected individuals, and the full counterintelligence impact will likely never be known," and that this breach appears to contain similar data (Nextgov/FCW). The difference is that OPM was quiet espionage. ShinyHunters turned the theft into a public spectacle, which spreads the data further and faster, but both roads end in the same place: hostile services holding the workforce's files. And the FBI has had a year of it. In March, the pro-Iran group Handala published material from Director Patel's personal email account, and separately, a suspected China-linked intrusion into an FBI system exposed surveillance targets' phone numbers (Nextgov/FCW).
The motive is business, and the target is the state
Does this mark a turn in which criminal crews abandon money and start coercing governments? The evidence says something subtler, and the crew's own behavior supplies the corrective.

Days before ShinyHunters hit the FBI, it seized the leak site of rival ransomware crew Clop and posted a "seized by ShinyHunters" banner, with reporting that it demanded an eight-figure payment from Clop (Security Magazine). That is textbook financial extortion, carried out in the same stretch of days as an attack the crew insists was not about money. Calderone voices the obvious doubt: "I have a hard time believing terabytes of FBI personnel data just sit on a shelf." Foreign intelligence services would want it, and having the FBI on a resume makes every future demand more credible (Security Magazine). Kirkwood noted that a drive for revenge or publicity does not erase a history of financial extortion (Security Magazine).
So the shift is not from money to politics. It is an expansion of the battlefield. Government advisories now function as market forces in the extortion economy: an FBI warning that a crew exaggerates reduces what corporate victims will pay. ShinyHunters treated the warning itself as a threat to its revenue and attacked the institution that issued it, using stolen government data as the instrument. The state became a coercive target because the state shapes the criminal market's profitability. CyberScoop described the incident as the group's "most direct conflict yet" with the agents who investigate data extortion (CyberScoop).
Peer crews underscore how unusual that is. Ransomware groups have squeezed governments before, but as locked-out victims expected to pay. Lapsus$, the teenage-linked collective that hit major technology firms in 2022, also broke into Brazil's health ministry, though opportunistically rather than as a campaign to change government conduct. Scattered Spider, the crew behind the 2023 casino hacks and later retail attacks, is not known to have attempted anything comparable. On the public record, ShinyHunters is the first major extortion crew to point its machinery at a national-security agency and demand a retraction as the price of silence.
That claim to a first deserves its caveats. The crew's self-description is self-serving, the counterintelligence damage lands regardless of motive, and one loud incident does not establish a trend. But the form of the pressure is the story: stolen state files used as leverage against the state's own public statements. Whether the motive is grievance or marketing, the technique now exists, and it has already delivered the spectacle the crew said it wanted.
What the FBI can do, and what it cannot undo
The bureau's public posture has been restrained: investigate, coordinate with the third-party providers behind FBIJobs.gov, and keep the affected portals down (The Register; CyberScoop). Inside the bureau, according to a former FBI cyber investigator who spoke to the BBC, staff have been advised to sign up to DeleteMe, a service that helps remove personal information from data broker websites. He considered that response inadequate (BBC News). A former cyber agent told the BBC that FBI staff were furious about the "sloppy and lazy security failures" that allegedly enabled the breach, though the actual failure mode remains unverified (BBC News).
Enforcement is another matter. Kaiser told Nextgov/FCW that when a group directly targets the agency, "they should expect that the FBI is going to marshal additional resources to bring them more quickly to justice" (Nextgov/FCW). She told CyberScoop that targeting law enforcement in ways intended to publicly shame it has historically led to takedowns, takeovers, or defections (CyberScoop). The crew's history suggests the pressure can eventually land: a spokesperson told The Register that the group began as GnosticPlayers before rebranding in 2020, and that the majority of the original members have since been arrested (The Register). Asked by BleepingComputer whether the FBI attack would bring more heat, the crew's representative answered: "I don't care" (BleepingComputer). The friction is real. "The bureau doesn't know what to do with teenage cyber criminals," one former agent told the BBC, and crews composed of young actors scattered across jurisdictions have repeatedly outlasted the agencies chasing them (BBC News).
What no investigation can fix is circulation. "A lot of the damage may already be done, and as we have seen in past FBI data breaches, that information continues to circulate the dark web years later," Kaiser told the BBC (BBC News). With the FBI unlikely to retract anything, publication is the live question, and the crew's clock was running as this article went to press (BBC News).
What we still don't know

The unresolved list is long. The FBI has not confirmed the data's authenticity or the claimed two-to-three-terabyte scale. The PeopleSoft zero-day remains publicly unverified, even as ShinyHunters claims to be exploiting the same flaw against Fortune 500 companies, which would make every internet-facing PeopleSoft instance a standing question (BleepingComputer). The entry point, vendor or bureau, is officially undetermined (The Register). No public evidence shows a foreign intelligence service has obtained the data, but analysts describe foreign acquisition as a live risk rather than a hypothetical one (Security Magazine; Lawfare). Whether the crew publishes, and whether the bureau changes its advisory, should be settled within days.
The banner on the FBI's jobs portal, "rooting your systems since '19," was a taunt, but it was also an advertisement, and the crew has said as much. The operation was designed to prove capability to future extortion victims, and the proof is now in the hands of everyone from reporters to, plausibly, foreign services. The lasting lesson is not about one crew's grievance. It is that personnel files, medical records, and assignment histories now function as strategic assets: an extortion economy has discovered that a government's own warnings are market-moving instruments, and that the machinery built to squeeze corporations can be turned on the state that polices it. For every institution holding workforce data, the ShinyHunters breach changes the question. The files are not merely at risk of theft. They are, in the wrong hands, a weapon pointed back at their owner.
Sources
- Joe Tidy, "Inside the FBI hack: Agents fearful and angry after 'dangerous' data breach," BBC News, September 28, 2026. https://www.bbc.co.uk/news/articles/cm4gjjlgzdjgo
- Justin Sherman, "The FBI Data Breach Is a Counterintelligence Disaster," Lawfare, September 25, 2026. https://www.lawfaremedia.org/article/the-fbi-data-breach-is-a-counterintelligence-disaster
- Matt Kapko, "ShinyHunters claims attack on FBI exposes almost all agents," CyberScoop, September 22, 2026. https://cyberscoop.com/shinyhunters-claims-fbi-attack/
- Lawrence Abrams, "ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach," BleepingComputer, September 22, 2026. https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
- Jordyn Alger, "FBI Hacked, Employee Data Reportedly Exposed," Security Magazine, September 23, 2026. https://www.securitymagazine.com/articles/102594-fbi-hacked-employee-data-reportedly-exposed
- Jessica Lyons, "ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'," The Register, September 25, 2026. https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250
- David DiMolfetta, "Stolen FBI data reveals employees' roles in intelligence and surveillance," Nextgov/FCW, September 23, 2026. https://www.nextgov.com/cybersecurity/2026/09/stolen-fbi-data-reveals-employees-roles-intelligence-and-surveillance/416182/
Comments (7)
Continue exploring
Volt Typhoon and the Weaponization of the Local Tap
A water system can fail without a reservoir running dry. A treatment plant can remain physically intact while the computers that…
Mamdani's 9/11 Records Release: What New York Officials Knew About Ground Zero's Toxic Air
Twenty-five years after the attacks, Mayor Mamdani released 170,000 pages of NYC 9/11 records. Here is what they reveal about the…
The Army Is Turning Military Land Into an AI Compute Platform
Carlyle and CyrusOne won exclusive negotiations to build commercial hyperscale data centers on roughly 2,600 acres of Army land…
The framing of the retraction demand as 'strange' undersells it — for a crew whose business model depends on credibility, forcing a US agency to disavow its own advisory is probably worth more in future negotiations than any ransom payment would be.
The piece calls this 'new ground' for a financially motivated crew bending a state's public statements, but Scattered Spider and Lapsus$ have both pressured victims into altering communications and statements before — what specifically distinguishes ShinyHunters' approach as novel?
The PeopleSoft zero-day angle in the BleepingComputer reporting connects to what hit several state and university Oracle instances earlier this year. Both incidents followed the same pattern of moving from a known CRM or HR platform vulnerability into far more sensitive downstream records. It also tracks the MOVEit-style supply chain hits from 2023–24, where the breached party was rarely the one whose data ended up exposed. The FBI breach looks like the same playbook, just aimed at a target whose threat model supposedly included defending against exactly this.
Loved that the article flagged the job applicants as caught up in this too — people who applied, never got hired, and now have their SSNs and fitness-for-work medical exam results floating around with zero warning and no badge to show for it.
The 'What the crew says it took, and what checks out' section is the most useful part of this. It cleanly separates ShinyHunters' 2–3TB claim from the ~5,000-record sample journalists actually reviewed, and the OSINT work 404 Media did is what gives the rest of the article any weight. Without that breakdown the whole piece would just be repeating a leak-site boast. The detail about the medical material being tied to special agents specifically, not just administrative staff, is also where the counterintelligence risk stops being theoretical.
If the entry point is at a third-party vendor, the FBI will spend the first six months arguing over contractual forensic access clauses before any of the agents in that 5,000-record sample get a straight answer.
Can you do a follow-up on whether the FBI actually responds to the retraction demand before the four-day deadline hits? I'd love to know if there's any precedent for a federal agency publicly walking back an advisory under extortion pressure, or if they're just going to let the leak happen.