The digital extortion group known as ShinyHunters said Tuesday that it breached the Federal Bureau of Investigation and stole data on almost all FBI agents and people who applied for jobs with the agency.
The group said it targeted the FBI in response to a May 2026 agency announcement that detailed its methods and advised victims not to pay its ransom demands. ShinyHunters said it exploited a zero-day vulnerability in Oracle PeopleSoft, accessed AWS GovCloud servers and downloaded two to three terabytes of data.
The group provided a screenshot of a vandalized FBI job site and information on roughly 5,000 agents that it described as a sample of the overall stolen data set. The site displayed a message saying the FBI jobs site and “Special Agent Applicant Portal” were “currently unavailable.” The group’s message claimed it had obtained personal and health information on current and former employees and applicants, and ended with the sign-off, “Thank you for your attention to this matter,” mimicking President Trump’s typical social media sign-off. In at least 10 cases, including FBI Director Kash Patel, details appeared to match, although Reuters could not establish where the data came from or whether it had actually been stolen from FBI internal systems as claimed.
The sample appeared to include agents’ names, home addresses, Social Security numbers, assignments and, in some cases, family members’ names. The data could have serious counterintelligence implications. Hackers in the same criminal network have previously used stolen phone records to track and harass FBI agents investigating them, and the stolen data could also be valuable to foreign intelligence services.
ShinyHunters said the attack was not financially motivated, describing its plans as “coercion” rather than extortion. The group has recently claimed or been linked to attacks involving Rockstar Games, education platform Canvas and AI company Anthropic.












