ShinyHunters Says It Breached FBI Portal, Stole Agent Data

ShinyHunters Says It Breached FBI Portal, Stole Agent Data

ShinyHunters claims it compromised FBI systems and stole data on agents and job applicants, citing a new zero-day in a widely used human resources management su…

The ShinyHunters FBI breach claim surfaced on Tuesday when the cyber extortion group stated it had compromised the U.S. Federal Bureau of Investigation and stolen data on current and former employees. In a message posted to its dark web leak site, a hidden website where criminal groups publish stolen data to pressure victims, the group said it held "very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." It listed compromised services including Criminal Justice (CJ), HR, and Medlink, according to reporting by 404 Media and The Hacker News.

The group framed the action as retaliation for a May 2026 public service announcement from the FBI that described ShinyHunters' targeting of Canvas, an online learning management system used by organizations for training and education, and urged victims not to pay ransoms. ShinyHunters called the FBI's announcement "substantial false allegations" and said it was disappointed that an agency would spread disinformation to disrupt its operations. It also rejected reports linking it to The Com, a decentralized collective, calling that a "propaganda" narrative from the information security industry.

A ShinyHunters spokesperson told The Register that the group exploited a new zero-day vulnerability in a widely used human resources management suite, a security flaw unknown to the software maker with no official fix yet, to gain remote code execution, an attack that lets an intruder run their own commands on a vulnerable server, and deface the FBI jobs website with a banner reading "This site has been seized by ShinyHunters." At the time of reporting, the site showed a maintenance message: "Scheduled Maintenance Underway. We're Sniffing Out Site Updates for You!" There are currently no public details of a pre-authenticated remote code execution zero-day affecting the human resources management suite, but ShinyHunters previously weaponized a similar flaw, CVE-2026-35273, in June 2026 to break into enterprise networks and extort victims. The human resources management suite is a set of business software used by organizations for human resources and other back-office tasks.

The FBI told Reuters it is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." The claim came shortly after ShinyHunters hijacked the dark web leak site of the Clop ransomware crew, malicious software that locks or threatens to publish data unless a payment is made, and replaced it with an extortion notice demanding a payment. That notice included lines such as "2.333% of my net worth is a 8 figure amount" and "Clock is ticking moron," a sign of the group's aggressive public posture.

The defacement of a public jobs portal illustrates a broader risk for any organization that runs web applications: a single unpatched flaw can give an attacker a foothold that leads to sensitive personnel records. Even if the victim is a law enforcement agency, the same logic applies to corporate HR portals, customer databases, and content management systems.

Etay Maor, VP of threat intelligence at Cato Networks, called the claim "an unusually provocative move" and said it should be taken seriously. He noted that while threat actors commonly target businesses, and nation states have compromised law enforcement before, a cybercrime brand publicly claiming an FBI compromise is different. Maor also pointed to a timestamp detail: the group's post showed September 23, while news emerged in the U.S. on September 22, which could point toward activity in Asia, though he stressed it is not definitive attribution.

Maor described ShinyHunters as a resilient criminal brand that has outlasted takedowns, arrests, and forum seizures by evolving methods and attracting new operators. Its recent playbook, he said, emphasizes abusing trusted identity paths through help-desk social engineering, malicious OAuth applications, and stolen SaaS integration tokens rather than simply breaking through a technical perimeter. OAuth is a standard way for apps to ask permission to access an account without sharing the password, and a SaaS integration token is a digital key that lets one online service connect to another on a user's behalf. That lesson applies beyond public-sector agencies: organizations, including website owners and businesses, need to protect identity and third-party trust relationships.

For teams that want to review the kind of trusted access paths ShinyHunters now abuses, AEU-I, AEU Group's security-first IT and consulting practice, helps organizations assess infrastructure and identity configurations.

How to Protect Yourself

  1. If your organization uses a widely used human resources management suite, ask your IT team or vendor whether the latest security patches are installed, and do not delay applying them.
  2. Turn on multi-factor authentication for every account that supports it, especially email and any admin or HR system, so a stolen password alone is not enough.
  3. Be suspicious of unexpected requests from help desks or support channels asking you to approve a login or change a setting; verify the request by calling a known number before acting.
  4. Review the third-party apps and services that have permission to access your work accounts and remove any you do not recognize.
  5. If you see a website you manage showing an unexpected maintenance page or a seized banner, take it offline and contact your hosting provider or security team immediately.
  6. Avoid paying extortion demands and report any threat to law enforcement; preserving logs and not altering evidence helps investigators.

Vulnerabilities & Fixes

  • CVE-2026-35273 CVE-2026-35273 is a remote code execution vulnerability in the widely used human resources management suite that ShinyHunters said it exploited in June 2026 to break into enterprise networks; the source does not mention a patch or mitigation. View the fix & details →

Terms Explained

  • zero-day vulnerability A security flaw that is unknown to the software maker and has no official fix yet.
  • remote code execution A type of attack that lets someone run their own commands on a computer or server from afar.
  • human resources management suite A set of business software used by organizations for human resources and other back-office tasks.
  • dark web leak site A hidden website where criminal groups publish stolen data to pressure victims.
  • ransomware Malicious software that locks or threatens to publish data unless a payment is made.
  • OAuth A standard way for apps to ask permission to access your account without sharing your password.
  • SaaS integration token A digital key that lets one online service connect to another on your behalf; if stolen, attackers can use that connection.

Related AEU services

  • AEU-I IT and security consulting