ShinyHunters Claims Breach of FBI Systems

31272703869?profile=RESIZE_400xThe notorious extortion group ShinyHunters announced that it had breached the Federal Bureau of Investigation (FBI) and stolen records on current and former employees.  In a statement on its dark-web site, the group said it targeted the agency after a May 2026 advisory that outlined its methods and urged victims not to pay. It claimed to have taken data on almost all FBI agents and individuals who applied for jobs there. The announcement followed a brief appearance of the group’s banner on the FBI’s public hiring portal on 22 September. Reporters received a sample of around 5,000 records that appeared to match real individuals, though the origin of the data remains unconfirmed.[1]

See:  https://redskyalliance.org/xindustry/shinyhunters-cl0p

In an expert comment, Collin Hogue-Spears, senior director of solutions management at Black Duck, said the incident likely involved the public hiring portal rather than internal FBI systems. He noted that ShinyHunters had previously targeted Oracle PeopleSoft environments and that the group’s demand focused on retraction of the May advisory rather than payment.  Hogue-Spears stressed that internet-facing recruiting portals should allow only record submission, not retrieval of employee data, and that organizations must restrict access to PeopleSoft management interfaces.

Andrew Brandt, principal threat intelligence incident commander at Huntress, warned that release of the data could expose agents and their families to serious harm. He said the greater risk lay in ShinyHunters selling the information to criminal or nation-state groups, potentially enabling fraud, blackmail or physical threats against law enforcement personnel. Brandt added that the FBI would likely pursue the actors aggressively.

Jamie Akhtar, CEO and co-founder at CyberSmart, said the claims should be treated with caution until the FBI completes its investigation. He warned that the data could support convincing phishing, impersonation or blackmail operations.  Akhtar recommended that organizations apply vendor updates promptly, restrict access to HR platforms, enforce least-privilege access and monitor for unusual activity. Individuals should use unique passwords, enable multi-factor authentication and verify any sensitive requests through separate channels.

These events show the risks even the most well-protected organizations face when third-party or public-facing systems are exposed. Experts agree that tight controls on hiring portals and rapid patching remain essential defenses against such threats.

 

This article used AI to craft the content and is shared at no charge for educational and informational purposes only.

Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization.  We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC).  For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com    

Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929

 

[1] https://www.cybersecurityintelligence.com/blog/shinyhunters-claims-breach-of-fbi-systems-9765.html

You need to be a member of Red Sky Alliance to add comments!