CSIDB logo
Incident

Federal Bureau of Investigation

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-22 20:38

Linked entities

Victim
Federal Bureau of Investigation
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers claiming to be from ShinyHunters said they breached multiple FBI-related services using a zero‑day exploit in Oracle PeopleSoft, accessed AWS GovCloud servers and exfiltrated between two and three terabytes of data that includes names, addresses, phone numbers, dates of birth and spouse information for current and former employees and applicants. They also defaced the agency's jobs website, posting a seizure notice and asserting that all agency data was compromised. The group said the breach was not financially motivated and described their intended action as coercion rather than extortion.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Monday night the hacking group ShinyHunters reportedly exploited a zero‑day vulnerability in Oracle’s PeopleSoft software to gain access to FBI‑related AWS GovCloud servers, from which they exfiltrated between two and three terabytes of data. The stolen information allegedly includes personally identifiable information and protected health information for current and former FBI employees as well as all job applicants, such as names, home addresses, phone numbers, dates of birth and details about spouses. ShinyHunters provided 404 Media with a sample file containing records for approximately 5,000 individuals, which the outlet verified by cross‑checking phone numbers through open‑source intelligence tools and the Darkside compromised‑data platform, confirming that the numbers matched individuals with the same names and some were linked to U.S. Department of Justice personnel. On Tuesday the group defaced the FBI jobs website, replacing its content with a message stating “this site has been seized by ShinyHunters” and claiming that all FBI data had been compromised, while the site subsequently displayed a notice that Apply.fbijobs.gov and the Special Agent Applicant Portal were unavailable.

The disclosure raised concerns about national security and counterintelligence risks, as the exposed data could be used by criminals to track, intimidate or harass FBI agents and their families, and could also be valuable to foreign intelligence services seeking insight into bureau operations. ShinyHunters told 404 Media that the breach was not financially motivated and that their intended actions were not extortion but possibly coercion, noting that they typically seek ransom payments from other victims but do not expect the FBI to comply. The group’s representative added that they possessed more data than the sample they shared and mocked the communication style of former President Trump’s Truth Social posts in their defacement message.

In response to the allegations, the FBI did not immediately issue a public comment when contacted by 404 Media, and the bureau’s jobs portal remained inaccessible at the time of the article’s publication. 404 Media offered a secure channel for individuals with further information to contact the reporter via Signal or email, and the article was later updated to incorporate additional details derived from previously compromised data. The report concluded with the representative’s invitation for anyone affiliated with the FBI to come forward with further insights using non‑work devices.

Sources

Sources available to members: 1 source.

CSIDB