Cybercrime group ShinyHunters has claimed responsibility for breaching multiple services linked to the Federal Bureau of Investigation and stealing personal data belonging to all current and former FBI employees, as well as job candidates.
The FBI confirmed that it is aware of the security claims and stated that an official investigation into the incident is currently underway.

A representative for ShinyHunters told technology news outlet 404 Media that the group obtained full names, home addresses, phone numbers, birth dates, and information regarding spouses for FBI agents. The hackers claimed to have compromised records covering all staff members and job applicants, estimating the total volume of stolen data at two to three terabytes.
To substantiate the breach, the hacking group provided journalists with a data sample containing information on approximately 5,000 employees. Outlet 404 Media verified a portion of the records using open-source intelligence tools from OSINT Industries and District 4's Darkside platform, confirming that several phone numbers matched the listed names and that some records belonged to U.S. Department of Justice personnel.
FBI Job Site Defaced and Taken Offline
Alongside the data theft, ShinyHunters compromised the official FBI recruitment portal, FBIjobs.gov. The hackers replaced the page with a parody of American law enforcement seizure notices, posting a message stating that the website had been seized by ShinyHunters.
Following the attack, the recruitment website became completely unavailable to the public, alongside the online portal used by candidates applying for special agent positions. The FBI told 404 Media that the agency is aware of reports regarding unauthorized activity affecting FBIjobs.gov and is investigating the matter.
Zero-Day Exploit and System Intrusion
According to statements made by the hackers, initial access to the networks was obtained through a zero-day vulnerability in Oracle PeopleSoft software. The group stated that it subsequently penetrated AWS GovCloud servers to extract several terabytes of sensitive administrative data.
Oracle PeopleSoft is an enterprise management software suite widely used by large corporations and government agencies to manage human resources and administrative operations. AWS GovCloud is an isolated cloud computing infrastructure operated by Amazon Web Services, designed specifically to host sensitive government workloads while meeting federal security and compliance standards. The Federal Bureau of Investigation serves as the principal domestic intelligence and security agency of the United States, operating under the jurisdiction of the Department of Justice.
Security Risks and Hacker Demands
The potential data leak is considered particularly sensitive due to the nature of the compromised records. The exposure of home addresses, personal contact details, and information about family members creates significant safety risks for law enforcement officers, including potential surveillance, harassment, and targeted physical attacks, while also offering high strategic value to foreign intelligence services.
While ShinyHunters typically uses stolen corporate data for financial extortion by threatening public disclosure, a spokesperson for the group stated that there was no financial motivation behind this intrusion. Instead, ShinyHunters demanded that the FBI correct or delete a previously published intelligence report detailing the group's activities within one week.
