ShinyHunters Allegedly Claims Breach of FBI Jobs Site and Stolen Agents’ Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The FBI is investigating alleged unauthorized activity affecting its recruitment infrastructure after the ShinyHunters cybercrime group claimed it breached FBI systems, defaced the bureau’s jobs portal, and stole sensitive records belonging to employees and applicants. The incident places the data-extortion operation in direct confrontation with the federal agency responsible for investigating cybercrime.

The intrusion reportedly began Monday night and became visible when apply.fbijobs.gov briefly displayed a counterfeit seizure notice reading, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”

The page claimed personally identifiable information and protected health information concerning current and former FBI personnel and job applicants had been compromised. The FBI later took the application service and Special Agent Applicant Portal offline.

ShinyHunters Allegedly Breach Claim

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said. That statement confirms an inquiry and activity affecting the jobs domain, but it does not verify ShinyHunters’ claims about access to internal FBI networks, the quantity of data allegedly removed, or the intrusion method.

ShinyHunters told reporters it exploited an undisclosed Oracle PeopleSoft vulnerability that allegedly enabled remote code execution without authentication. According to the group, attackers then moved laterally into FBI-managed AWS GovCloud infrastructure and downloaded between two and three terabytes of information.

It also claimed access to human resources, Medlink, Criminal Justice, and other services. Oracle, AWS, and the FBI have not validated that technical account.

To support its allegations, the group supplied journalists with a sample of 5,000 purported FBI employee records. The material reportedly included names, home addresses, phone numbers, Social Security numbers, assignments, dates of birth, and details about spouses or other relatives.

Reuters partially matched information in at least 10 cases, while 404 Media linked several phone numbers to people bearing the listed names and to Justice Department personnel. Neither outlet could establish that the sample originated from compromised FBI systems.

The alleged exposure creates risks extending far beyond identity theft. Residential addresses, family relationships, assignments, medical details, and applicant background information could support doxxing, harassment, impersonation, social engineering, blackmail, or targeting by hostile intelligence services. Former FBI official Cynthia Kaiser warned that stolen personnel information can continue enabling harassment years after its disclosure.

ShinyHunters described the operation as nonfinancial and framed it as retaliation for an FBI cyber alert published in May. That advisory characterized the group’s reported tactics, including data theft, extortion, threatening communications, harassment, and pressure on victims not to resist payment demands. The attackers accused the bureau of making false statements and reportedly gave officials one week to correct or remove the document.

Despite the visible website defacement and limited validation of sample records, the central allegation remains unproven. A defaced internet-facing portal demonstrates unauthorized control of that web environment, but it does not itself prove access to wider FBI systems or confirm terabytes of exfiltration.

Investigators will need to review PeopleSoft logs, cloud audit trails, authentication events, lateral-movement evidence, and outbound data transfers to determine the incident’s real scope.

Until the FBI completes that assessment, affected employees, former personnel, applicants, and relatives should treat follow-on phishing, impersonation, account-recovery attempts, and unusual credit activity as credible risks.

Organizations using PeopleSoft should also monitor for anomalous administrative access and promptly apply applicable Oracle security updates, while avoiding unsupported assumptions that the alleged FBI entry vector is confirmed.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post ShinyHunters Allegedly Claims Breach of FBI Jobs Site and Stolen Agents’ Data appeared first on Cyber Security News.