ShinyHunters claims FBI breach, agents' data stolen
Original: Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
Why This Matters
A breach exposing FBI agents' home addresses creates direct counterintelligence and physical security risks at scale.
Cybercriminal group ShinyHunters claims to have breached FBI systems, stealing data on thousands of agents and job applicants — including home addresses and phone numbers of agents and their spouses. The group says the hack is 'not financially motivated' and demands the FBI remove a report alleging false claims about them.
ShinyHunters, the group behind several major data theft operations, posted the breach claim on its dark web leak site. According to 404 Media, which first reported the story, the hackers compromised an Oracle PeopleSoft server — commonly used by HR and recruiters — then pivoted to an Amazon-hosted government cloud containing agents' and applicants' personal data. The group claims it took terabytes of data. A sample shared with 404 Media, containing names, home addresses, and phone numbers of FBI agents and spouses, was partially verified against public records. The FBI's jobs portal and special agent applicant portal were both reportedly taken offline, with a 'maintenance' notice displayed. The FBI did not respond to comment requests. Security experts warn the stolen data poses a serious counterintelligence risk — foreign intelligence services could use it to coerce or blackmail agents. This marks the second known FBI system breach this year; earlier in 2026, unidentified hackers accessed a system managing wiretap and foreign intelligence warrants. FBI Director Kash Patel's personal email was also previously hacked by Iran-linked group Handala.