ShinyHunters Claims Breach of FBI Systems, Stealing Data on Agents and Applicants
The extortion group says it compromised an Oracle server and Amazon cloud infrastructure, demanding the removal of an FBI report.

The cybercriminal group ShinyHunters claims to have breached systems at the Federal Bureau of Investigation, exfiltrating records on thousands of agents and employment applicants. The group announced the intrusion on its dark web leak site, claiming the theft of sensitive data covering almost all FBI agents and individuals who applied for jobs with the agency, as reported by TechCrunch (https://techcrunch.com/2026/09/22/hacking-group-shinyhunters-claims-it-breached-the-fbi-stole-agents-and-applicants-data/).
The incident was first reported by 404 Media, which received a data sample containing names, home addresses, and phone numbers of FBI agents and their spouses, verifying a portion of the records against public sources. The hackers stated the breach was not financially motivated, demanding that the FBI take down a published report that they allege contains false claims about their group.
According to 404 Media, the hackers initially breached an Oracle PeopleSoft server used for human resources and recruitment data before pivoting into an Amazon-hosted government cloud storing agent and applicant files. ShinyHunters claimed to have taken terabytes of information, though the syndicate did not detail what steps it would take if the FBI refuses to remove the report.
The exposed information presents significant counterintelligence risks, as foreign intelligence agencies or other threat actors could use personnel records and family contact details to attempt coercion or extortion. The hackers also defaced the FBI's hiring portal; at the time of publication, both the agency's primary jobs site and special agent applicant portal displayed notices stating they were down for maintenance.
Neither the FBI nor ShinyHunters responded to requests for comment. The claim marks the second reported breach of an FBI system this year, following an earlier compromise of a platform used to manage real-time wiretaps and foreign intelligence warrants. Separately, Iranian state-aligned hacking group Handala previously breached and published personal emails belonging to FBI Director Kash Patel.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


