Home Government

ShinyHunters, the Hacking Group the FBI Warned About in May, Says It Stole Data on Nearly Every FBI Agent

"Do not send payment or respond to their demands." The FBI, about ShinyHunters, May 15, 2026.

A laptop screen glowing red with a glitched table of personnel records and ID photos, an FBI badge on the desk and the FBI headquarters building outside a rainy window

“Do not send payment or respond to their demands.” The FBI, about ShinyHunters, May 15, 2026.

A hacking group says it broke into the FBI on Monday night and walked out with two to three terabytes of records on current and former agents, their spouses and everyone who ever applied for a job there. Its one demand is that the FBI take back what it said about them.

The FBI now has to decide whether to follow its own advice.


Here is what is claimed, and what is confirmed.

ShinyHunters says it used a previously unknown flaw in Oracle PeopleSoft, the HR software behind the bureau’s hiring system. It says it reached the FBI jobs portal, an Amazon-hosted government cloud and a PeopleSoft server. It claims names, home addresses, phone numbers and spouses’ details, plus medical and background information, according to BleepingComputer.

What the FBI has said is one sentence. It is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” The jobs site is down for maintenance.

The size of the haul is not verified. But the sample is not nothing. The group handed 404 Media records on 5,000 people it says are agents, and TechCrunch reported that 404 Media matched parts of them against public records.


Now the part that should worry everyone, and that the coverage mentions only as background.

The demand is not money. ShinyHunters says the hack is “not financially motivated.” It wants the FBI to withdraw or correct a May alert about the group, and it has given the bureau a week.

So we read the alert. The May 15 public service announcement calls ShinyHunters a group “specializing in large-scale data breaches and extortion.” It tells victims not to pay and not to respond. And it says the group harasses victims and their families with threatening calls and texts, “and in some cases, swatting.”

Swatting means calling in a fake emergency so armed police show up at someone’s door.

The group the FBI says swats people now says it holds the home addresses of FBI agents and their spouses.

That is the story. It is not an embarrassing IT failure. It is a physical safety problem for thousands of families, and it came with a political ask attached.


There is a joke in here somewhere. The FBI’s own advice to victims now describes the FBI. Somebody at the bureau is reading a PSA written for a mid-sized retailer and realizing it is about them.

The joke stops there. The bureau cannot pay a ransom that is not money, and it cannot comply without teaching every extortion crew on earth how the FBI can be moved. Pull the alert and the lesson is that federal law enforcement edits its warnings under pressure.

It should not pull it. It also should not do what it is doing now, which is saying almost nothing.


This is also not the first time this year.

In February, hackers reached the FBI’s system for managing court-authorized wiretaps and foreign intelligence warrants. That system could reveal who the bureau is watching. US investigators reportedly suspected Chinese state hackers. That breach came in through a vendor. This one, if the claim holds, came in through commercial software that many large employers run.

Which raises the question nobody has answered. If a PeopleSoft zero-day got into the FBI on Monday, who else runs PeopleSoft? Universities, state governments and big companies use it for payroll and HR. Oracle had not commented on the claim when BleepingComputer published.


What should happen next is not complicated.

Tell the people. Every current agent, every former employee and every applicant whose file may be in that system should hear from the FBI directly, not from a news site. When the Office of Personnel Management lost background-check files in 2015, the notifications took months. Families living with a swatting risk cannot wait months.

Warn everyone else. If the flaw is real, the Cybersecurity and Infrastructure Security Agency and Oracle need to say so publicly, today, so other PeopleSoft customers can check their own logs.

And keep the alert up. The only thing worse than a hacking crew holding agents’ home addresses is a hacking crew that has learned the FBI can be made to back down.

ABC News, September 23, 2026: sources say the FBI is investigating a possible breach of its job application website.

The deadline ShinyHunters set runs out next week. What the FBI says between now and then will matter more than what it says after.