Federal authorities are actively probing a bold claim by the hacker group ShinyHunters that they stole two to three terabytes of sensitive employee data via a zero-day exploit. The attackers are demanding the retraction of a federal advisory rather than seeking financial ransom.
By Nexvoro Tech Wire
PUBLISHED THU, SEP 24, 2026 12:53 AM UTC • 5 MIN READ
The Breach and the Banner: FBIJobs.gov Taken Offline
The Federal Bureau of Investigation is currently racing against the clock to investigate extraordinary claims made by a notorious hacker group. According to initial reports, the collective known as ShinyHunters successfully took down the agency's dedicated recruitment portal, FBIJobs.gov, replacing the main landing page with a provocative banner that explicitly declared: "THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS."
This dramatic digital incursion immediately triggered alarms across federal cybersecurity divisions. As of Wednesday, the employment portal remained entirely inaccessible to the public and prospective applicants. Internal sources within the Bureau confirmed that all personnel received an urgent internal email advising them to take immediate steps to protect their personal information while the federal investigation actively continues.
Scope of the Stolen Data: Terabytes of Sensitive Information
In communications with major journalistic outlets including The New York Times and Bloomberg, ShinyHunters asserted that they exfiltrated approximately two to three terabytes of data. While none of this expansive cache has been publicly leaked online yet, the compromised material allegedly includes the names of current and former special agents, job applicants, and corresponding home addresses, phone numbers, and the names of spouses.
Compounding the gravity of the situation, the stolen repository reportedly contains sensitive medical information and professional intelligence. Bloomberg noted that a sample of the data appears to feature potentially sensitive professional assignments detailing agents' specific work focuses - ranging from counter-intelligence operations targeting China, Russia, and Iran to domestic enforcement efforts directed against violent street gangs.
Motive and Ultimatum: Demanding a Retraction from Leadership
Unlike traditional ransomware syndicates driven by monetary extortion, ShinyHunters explicitly stated that their strike was not financially motivated. Instead, the group's primary objective is to force federal leadership - specifically FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI Cyber Division - to retract or edit a May advisory warning that previously targeted the hacking collective.
In a dark web message reviewed by Ars Technica, ShinyHunters expressed that they were "severely offended" by the FBI's public allegations that the group occasionally employs "exaggerated claims" to extract payments from corporate victims. The group stated unequivocally that their threats are genuine, while also vehemently denying accusations that they orchestrate swatting attacks against corporate workers or execute sextortion threats.
The Zero-Day Exploit and the Federal Response
Regarding the technical mechanism of the breach, precise details remain sparse. ShinyHunters disclosed to The New York Times that they successfully weaponized a zero-day, or previously undiscovered, computer bug within Oracle PeopleSoft software, an enterprise application widely utilized for human resources and financial management. Technology giant Oracle has remained silent thus far regarding the alleged vulnerability.
The FBI has not yet officially confirmed that the breach successfully compromised core systems. In an official statement posted to X on Wednesday, the Bureau noted that "the point of breach is still undetermined - whether a third-party or the FBI's enterprise." Federal officials emphasized that they are actively and aggressively investigating the matter while working closely with the third-party providers who support the jobs site to mitigate all associated risks.
Reporting synthesized under Nexvoro.tech Editorial Standards • Referenced via Ars Technica
Verified Dispatch