Tuesday, September 22, 2026
Tech Beat
Sep 22, 2026, 6:40 PMCybersecurity

ShinyHunters Claims FBI Breach Exposed Agents and Applicants

ShinyHunters claims it stole terabytes of FBI agent and applicant data, exposing families to extortion and coercion risks after a PeopleSoft and cloud breach.

Listen to this briefingAudio briefing

Summary

On September 22, 2026, ShinyHunters claimed it breached the FBI and stole terabytes of sensitive data covering thousands of people, including almost all agents and FBI job applicants. A sample contained agents’ and spouses’ names, home addresses and phone numbers, with some entries matching public records. The group allegedly entered through an Oracle PeopleSoft human resources server, then breached an Amazon-hosted government cloud containing agent and applicant records.

ShinyHunters said the attack was not financially motivated and demanded removal of an FBI report it says makes false allegations, but did not disclose what it would do if the agency refused. The FBI jobs site was reportedly defaced, while that site and the special agent applicant portal displayed maintenance notices. Neither side provided further comment. The data could help hackers or foreign spies coerce agents and families. This is the second known FBI system breach in 2026, after unidentified hackers accessed a system managing real-time wiretaps and foreign intelligence-gathering warrants, potentially exposing surveillance targets. Separately, Iran-backed Handala hacked and leaked FBI director Kash Patel’s personal email after U.S.-led strikes against Iran.

Positives

  • Some names, home addresses and phone numbers in the sample matched public records, providing partial evidence for assessing the claim.
  • The FBI jobs site and special agent applicant portal displayed maintenance notices after the reported defacement, leaving both recruitment interfaces offline.
  • ShinyHunters disclosed no financial ransom or plan to release the terabytes of data if the FBI rejects its demand.

Risks & concerns

  • Terabytes of allegedly stolen data cover thousands of people, including almost all FBI agents, job applicants and some agents’ spouses.
  • Names, home addresses and phone numbers could enable hackers or foreign spies to coerce agents and their families.
  • An Oracle PeopleSoft breach allegedly enabled access to an Amazon-hosted government cloud containing personnel and applicant records.
  • The FBI jobs site was reportedly defaced, while two recruitment portals became unavailable.
  • A second known FBI system breach in 2026 compounds concerns raised by earlier access to wiretap and foreign intelligence warrant systems.
  • Iran-backed Handala separately hacked and leaked FBI director Kash Patel’s personal email after U.S.-led strikes against Iran.
Primary sourceTechCrunchhttps://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecuritySep 22

SpyCloud Finds Stolen Passwords Expose 1,787 US Water Organizations

CybersecuritySep 21

Meta Muse Zero-Day Lets Any Mac App Hijack the AI Assistant

CybersecuritySep 18

FBI, Coast Guard Board Two Hacked US-Bound Oil Tankers