The FBI has suffered a major data breach, with the hacker group ShinyHunters claiming to have obtained personal information of all its employees.

ShinyHunters asserts it has acquired personal data from employees of the U.S. Federal Bureau of Investigation (FBI), including current staff, former employees, and job applicants. According to a representative of the group, as reported by 404 Media, a cyber intrusion occurred. The hackers claim they obtained names, home addresses, phone numbers, family details, and other sensitive personal information.

"All FBI data has been exposed, including personal and protected health information of current and former FBI personnel, as well as complete records of all candidates. The data we possess exceeds what we are disclosing here."

According to ShinyHunters, attackers exploited a zero-day vulnerability in Oracle PeopleSoft to gain initial access. Subsequently, the threat actors allegedly penetrated AWS GovCloud infrastructure and downloaded between 2 to 3 terabytes of data. Notably, the group claims no ransom demand was made for the stolen information. A spokesperson for ShinyHunters stated the objective of the attack was to exert pressure on the agency.

ShinyHunters is a long-active data theft and ransomware group reportedly linked to over 300 data breaches worldwide. Its origins remain unclear, with conflicting reports suggesting ties to Russia, groups composed of youth from the United States and the United Kingdom, or connections to French-speaking regions, though no definitive national affiliation has been established. In May 2026, the group attacked Canvas, disrupting operations at approximately 9,000 schools globally and demanding millions in ransom. On September 22, it claimed control over the Clop leak site and encryption keys; on September 23, it breached the FBI’s human resources database.

Original source: toutiao.com/article/1877091928166467/

Disclaimer: This article reflects the views of the author alone.