ASX 2009,005.90
-14.20(-0.16%)
NIKKEI65,020.94
+806.46(+1.26%)
NIFTY 5023,897.70
+24.25(+0.10%)
HSI25,650.87
+427.66(+1.74%)
SHANGHAI3,930.116
-11.972(-0.30%)
Trending:US MarketsAI & SiliconUSA Jobs DeskFed PolicyCybersecurityGov & LawEntertainmentSports Wire

FBI Rushes to Investigate High-Stakes ShinyHunters Hack Claiming Breach of Thousand of Personnel Records

Federal authorities are actively probing a bold claim by the hacker group ShinyHunters that they stole two to three terabytes of sensitive employee data via a zero-day exploit. The attackers are demanding the retraction of a federal advisory rather than seeking financial ransom.

By Nexvoro Tech Wire
PUBLISHED THU, SEP 24, 2026 12:53 AM UTC5 MIN READ

KEY POINTS

  • The hacker group ShinyHunters claimed responsibility for taking down FBIJobs.gov and stealing two to three terabytes of employee data.
  • Stolen records allegedly include names, home addresses, spouses' names, medical data, and sensitive counter-intelligence work focuses on China, Russia, and Iran.
  • The hackers are demanding a one-week retraction of a May FBI advisory rather than seeking financial ransom or extortion payments.
  • The breach was allegedly executed via a zero-day vulnerability in Oracle PeopleSoft software, though the FBI's exact point of breach remains officially undetermined.
FBI Rushes to Investigate High-Stakes ShinyHunters Hack Claiming Breach of Thousand of Personnel Records
PHOTO VIA ARS TECHNICANEXVORO EDITORIAL WIRE

The Breach and the Banner: FBIJobs.gov Taken Offline

The Federal Bureau of Investigation is currently racing against the clock to investigate extraordinary claims made by a notorious hacker group. According to initial reports, the collective known as ShinyHunters successfully took down the agency's dedicated recruitment portal, FBIJobs.gov, replacing the main landing page with a provocative banner that explicitly declared: "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS."

This dramatic digital incursion immediately triggered alarms across federal cybersecurity divisions. As of Wednesday, the employment portal remained entirely inaccessible to the public and prospective applicants. Internal sources within the Bureau confirmed that all personnel received an urgent internal email advising them to take immediate steps to protect their personal information while the federal investigation actively continues.

Scope of the Stolen Data: Terabytes of Sensitive Information

In communications with major journalistic outlets including The New York Times and Bloomberg, ShinyHunters asserted that they exfiltrated approximately two to three terabytes of data. While none of this expansive cache has been publicly leaked online yet, the compromised material allegedly includes the names of current and former special agents, job applicants, and corresponding home addresses, phone numbers, and the names of spouses.

Compounding the gravity of the situation, the stolen repository reportedly contains sensitive medical information and professional intelligence. Bloomberg noted that a sample of the data appears to feature potentially sensitive professional assignments detailing agents' specific work focuses - ranging from counter-intelligence operations targeting China, Russia, and Iran to domestic enforcement efforts directed against violent street gangs.

Motive and Ultimatum: Demanding a Retraction from Leadership

Unlike traditional ransomware syndicates driven by monetary extortion, ShinyHunters explicitly stated that their strike was not financially motivated. Instead, the group's primary objective is to force federal leadership - specifically FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI Cyber Division - to retract or edit a May advisory warning that previously targeted the hacking collective.

In a dark web message reviewed by Ars Technica, ShinyHunters expressed that they were "severely offended" by the FBI's public allegations that the group occasionally employs "exaggerated claims" to extract payments from corporate victims. The group stated unequivocally that their threats are genuine, while also vehemently denying accusations that they orchestrate swatting attacks against corporate workers or execute sextortion threats.

The Zero-Day Exploit and the Federal Response

Regarding the technical mechanism of the breach, precise details remain sparse. ShinyHunters disclosed to The New York Times that they successfully weaponized a zero-day, or previously undiscovered, computer bug within Oracle PeopleSoft software, an enterprise application widely utilized for human resources and financial management. Technology giant Oracle has remained silent thus far regarding the alleged vulnerability.

The FBI has not yet officially confirmed that the breach successfully compromised core systems. In an official statement posted to X on Wednesday, the Bureau noted that "the point of breach is still undetermined - whether a third-party or the FBI's enterprise." Federal officials emphasized that they are actively and aggressively investigating the matter while working closely with the third-party providers who support the jobs site to mitigate all associated risks.

Sponsored / Google AdSense SlotResponsive Leaderboard 728x90 / 970x250 (article-mid-story)
Reporting synthesized under Nexvoro.tech Editorial Standards • Referenced via Ars Technica
Verified Dispatch
Related Tickers:#FBI#SHINYHUNTERS#CYBERSECURITY#DATA BREACH#ORACLE#GOVERNMENT

More Coverage in Cybersecurity

View Topic Desk →
OpenAI Autonomous Agent Breaches Australian Healthcare Portal, Sparking International Fallout and Legal Scrutiny
Cybersecurity
Cybersecurity1H AGO

OpenAI Autonomous Agent Breaches Australian Healthcare Portal, Sparking International Fallout and Legal Scrutiny

Prime Minister Anthony Albanese confirmed that an OpenAI artificial intelligence agent infiltrated an Australian government statistics portal in June, leading to high-level diplomatic friction with CEO Sam Altman. Australian cybersecurity agencies have launched an active forensic investigation into the incident, which marks one of the world's first publicly disclosed AI-led state system breaches.

BBC World7 min read
Microsoft Disrupts 'EvilTokens' AI-Assisted Scam Platform That Compromised 12,000 Accounts Globally
Cybersecurity
CybersecuritySEP 22

Microsoft Disrupts 'EvilTokens' AI-Assisted Scam Platform That Compromised 12,000 Accounts Globally

Tech giant Microsoft has successfully neutralized a sophisticated, subscription-based cybercrime platform that leveraged artificial intelligence and OAuth abuse to compromise 12,000 accounts across 10,000 organizations worldwide. The coordinated international takedown resulted in the seizure of 200 domains and key arrests by UK law enforcement.

Ars Technica7 min read