ShinyHunters Claims FBI Hack, Cites Personal Grievance Over Alleged Harassment Tactics
The notorious ShinyHunters group claims to have breached the FBI's jobs website, exfiltrated terabytes of employee data, and is demanding the agency retract statements accusing them of harassment.

The cybercriminal group ShinyHunters has claimed responsibility for a significant breach targeting the FBI's jobs website, asserting that the attack was not financially motivated but rather a response to alleged false statements made by the FBI regarding the group's tactics. A spokesperson for ShinyHunters stated that the primary objective was to compel the FBI to retract or correct statements made in a May 15th bulletin, which accused the group of using "harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting."
According to the group's claims, the intrusion was facilitated by exploiting a zero-day vulnerability in Oracle's PeopleSoft software, which allowed for remote code execution (RCE) on the compromised servers. Following the initial compromise, ShinyHunters reportedly defaced the FBI jobs webpage with a "This site has been seized by ShinyHunters" banner. At the time of reporting, the website was displayed as "currently down for maintenance."
Beyond defacing the website, ShinyHunters alleges that it successfully moved laterally from the compromised site to the FBI's managed servers within the AWS GovCloud environment. From these servers, the group claims to have exfiltrated a substantial amount of data, estimated to be between 2 to 3 terabytes, belonging to current, former, and prospective FBI employees. The spokesperson indicated that the stolen data encompasses information on "all FBI employees and applicants."
The compromised systems, as per ShinyHunters' assertions, include critical functions such as human resources, MedLink, and Criminal Justice Information Services (CJIS). Neither Oracle nor Amazon Web Services (AWS) immediately responded to inquiries regarding the alleged zero-day vulnerability or the data theft.
This incident marks a departure from ShinyHunters' typical modus operandi, which usually involves demanding multi-million dollar ransoms in exchange for not leaking stolen data. In this instance, the group explicitly stated that no ransom payment is being sought. Their demand is solely focused on the retraction of the FBI's previous statements, which ShinyHunters claims are untrue and damaging.
The FBI bulletin that ShinyHunters seeks to have retracted was issued shortly after the group claimed a breach of the ed-tech company Instructure's Canvas platform, which allegedly impacted hundreds of millions of students, teachers, and staff. The bulletin also warned that extortionists might falsely claim to possess sensitive or compromising information that does not exist.
ShinyHunters' spokesperson expressed a personal motivation behind the attack, stating, "I have been doing my very best to combat these allegations. And this is the best way to do it." This suggests a direct confrontation with the FBI's characterization of their operations, moving beyond purely financial motives to address reputational damage.
The implications of this breach, if confirmed, are significant, potentially exposing sensitive employee and applicant data within a major US law enforcement agency. The group's unusual motive and direct challenge to official statements highlight a new dimension in cybercriminal motivations and operational strategies.