ShinyHunters Claims FBI Breach: 5,000 Records Shared as Evidence

ShinyHunters claims it breached FBI systems using an Oracle PeopleSoft zero-day, exposing sensitive employee and applicant data.

Written By
Matt Gonzales
Matt Gonzales
Sep 23, 2026
5 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A hacking group claims it breached FBI systems and stole sensitive information tied to thousands of FBI personnel and job applicants, including details about some employees’ spouses.

ShinyHunters claimed on Sept. 22 that it breached the FBI and obtained sensitive employee and applicant information, according to a 404 Media report that first reported the alleged intrusion. The publication reviewed a sample containing 5,000 purported FBI records, including names, addresses, phone numbers, and information about some employees’ spouses.

The FBI has not confirmed that its systems were breached or that data was stolen. The bureau said in a statement provided to multiple news organizations that it is aware of claims involving unauthorized activity affecting FBIJobs.gov and is investigating.

If ShinyHunters’ claims prove accurate, the exposed information could create risks beyond conventional identity theft, potentially giving threat actors personal details they could use for targeted phishing, impersonation, doxxing, and other attacks against law enforcement personnel and their families.

ShinyHunters claims it stole FBI employee and applicant data

ShinyHunters claims it obtained sensitive information about FBI employees and applicants after breaching systems associated with FBIJobs.gov.

404 Media said the sample provided by the hackers included 5,000 purported FBI records containing names, addresses, phone numbers, and details about some employees’ spouses. The publication said it verified portions of the data by comparing the sample data with public records.

However, the total number of people potentially affected remains unknown.

When TechCrunch asked ShinyHunters about the number of victims, the hackers did not provide an exact figure. Instead, the group claimed it was “very confident” it had information on most FBI personnel as well as a substantial amount of applicant data.

ShinyHunters also claimed it stole terabytes of information. Neither the amount of data nor the group’s claims about the incident's overall scope have been independently confirmed.

The incident comes after another FBI investigation into suspicious activity affecting a system used to manage surveillance and wiretap warrants earlier this year.

Advertisement

Attackers claim PeopleSoft provided the initial way in

The alleged attack may have started with an enterprise system used to manage sensitive workforce information.

ShinyHunters claims it exploited a new Oracle PeopleSoft zero-day vulnerability to gain access to FBI-related systems and steal employee and applicant data.

BleepingComputer reported that the group claimed it used the PeopleSoft flaw to compromise FBI systems. The vulnerability and full intrusion chain have not been independently verified.

The claim follows a broader campaign involving Oracle PeopleSoft systems. During that campaign, ShinyHunters previously told BleepingComputer that an earlier attempt to compromise an FBI PeopleSoft portal had failed.

The PeopleSoft connection would fit a broader pattern of attacks against HR and enterprise resource planning platforms, which can concentrate large quantities of sensitive employee and applicant information in a single environment.

ShinyHunters has previously claimed to have stolen more than 800,000 records from Wynn Resorts’ PeopleSoft environment. As eSecurityPlanet examined in February, Wynn confirmed unauthorized access to employee data but did not confirm ShinyHunters’ claimed victim count.

The group has also targeted other major organizations and enterprise systems. In May, ShinyHunters alleged it stole 42 million records from Charter Communications following a campaign involving social engineering and compromised identities.

Stolen FBI data could create risks beyond identity theft

If the stolen information is as extensive as ShinyHunters claims, the consequences could extend well beyond the immediate data breach.

Names, home addresses, phone numbers, family connections, and employment information could give attackers raw material for highly targeted social engineering. Instead of relying on generic phishing messages, attackers could potentially construct convincing communications using personal information about an employee, spouse, workplace, or professional relationship.

Information identifying law enforcement personnel and their families could also potentially facilitate harassment, doxxing, impersonation, or attempts to collect additional intelligence.

The risk becomes particularly significant when different pieces of stolen information are combined. An attacker who knows an employee’s name, phone number, home address, and family connections has substantially more context to build a believable impersonation attempt than one working with only an email address.

Advertisement

ShinyHunters said it targeted the FBI in response to a public advisory it claims contained false allegations about the group.

The hackers also reportedly defaced FBIJobs.gov. The FBI’s jobs website and special agent applicant portal subsequently displayed messages indicating that services were unavailable or undergoing maintenance.

What security teams can learn from the FBI breach claim

For enterprise security teams, the biggest lesson may be the one behind the FBI headline: HR, recruiting, and ERP platforms can become high-value targets because of the volume and sensitivity of the information they store.

Systems such as PeopleSoft can contain employee records, applicant information, contact details, payroll information, and other personally identifiable information. A successful compromise can therefore give an attacker more than a database to sell or leak. It can provide a detailed map for subsequent attacks against an organization’s workforce.

Security teams should consider several defensive measures:

  • Treat HR and ERP platforms as critical assets. Apply robust monitoring and access controls to systems that contain employee and applicant information.
  • Reduce unnecessary internet exposure. Review whether PeopleSoft and other administrative interfaces need to be publicly accessible and restrict external access where possible.
  • Monitor for unusual data access. Large database queries, bulk exports, or unexpected outbound transfers can be warning signs of data exfiltration.
  • Segment sensitive systems. Compromising a recruiting or HR application should not provide an attacker with an easy path to unrelated cloud services or internal infrastructure.
  • Strengthen privileged access. Enforce multifactor authentication, least-privilege access, and additional controls around administrative accounts.
  • Prepare for secondary attacks. When employee information is exposed, organizations should anticipate targeted phishing, impersonation, credential theft, and other social engineering attempts that use stolen information as context.

For defenders, the unanswered question is not only whether ShinyHunters’ FBI claims ultimately prove accurate. Organizations should also ask what an attacker could learn about their workforce if an HR or recruiting platform were compromised, and whether that information could serve as the starting point for the next attack.

Until the FBI, Oracle, or independent security researchers provide additional technical evidence, the claimed PeopleSoft zero-day, the total number of affected individuals, and the amount of data allegedly stolen should all be treated as unverified.

Related reading: ShinyHunters isn’t alone in targeting workforce systems: a breach of a Starbucks HR portal exposed sensitive employee information after attackers compromised employee credentials via phishing.

Matt Gonzales

Matt Gonzales is the Managing Editor of Cybersecurity for eSecurity Planet. An award-winning journalist and editor, Matt brings over a decade of expertise across diverse fields, including technology, cybersecurity, and military acquisition. He combines his editorial experience with a keen eye for industry trends, ensuring readers stay informed about the latest developments in cybersecurity.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.