LaraMag - Système d'actualités / Magazine Laravel Multilingue

collapse
...
Accueil / Droit / ShinyHunters Claims It Hacked the FBI and Stole Employee Data

ShinyHunters Claims It Hacked the FBI and Stole Employee Data

sept. 24, 2026  Chaudhry Arslan  137 vues

The cybercrime group ShinyHunters has claimed that it hacked the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information linked to current and former FBI employees as well as people who applied for jobs at the agency.

The group made the claim on its dark web site on September 22. It said the stolen information could include data related to almost all FBI agents and other agency employees. However, the FBI has not confirmed that the attackers accessed such a large amount of information.

tecno-camon-v30s-pakistan-priceoye-nnxme-500x500-33
 

ShinyHunters Claims It Hacked the FBI and Stole Employee Data

ShinyHunters claimed that several FBI services were affected, including Criminal Justice, human resources, and Medlink systems. The group also said it carried out the attack in response to an FBI public service announcement issued in May 2026.

That FBI announcement warned about ShinyHunters’ activities involving Canvas, an online learning management platform. The agency had also advised potential victims not to pay ransom demands. ShinyHunters later accused the FBI of spreading false information about its activities and said the public warning had not stopped its operations.

 

The group also rejected reports linking it to The Com, a decentralized cybercrime collective. ShinyHunters described those reports as misinformation and denied being part of the wider group.

ShinyHunters Claims PeopleSoft Zero-Day Attack

A ShinyHunters spokesperson told The Register that the attackers gained access by exploiting what they described as a new zero-day vulnerability in Oracle PeopleSoft. The group claimed the flaw allowed remote code execution and was used to compromise the FBI’s jobs website.

 

The FBI’s jobs website was also reportedly defaced with a message claiming that the site had been seized by ShinyHunters. The website is currently showing a scheduled maintenance message.

There is currently no public confirmation of a new pre-authenticated remote code execution zero-day in Oracle PeopleSoft matching the group’s claim. ShinyHunters has previously exploited a different PeopleSoft vulnerability, CVE-2026-35273, to gain access to enterprise networks and extort victims.

This means the latest claim still needs to be verified through technical evidence and an official investigation.

FBI Investigating the Claims

The FBI has acknowledged that it is aware of claims involving unauthorized activity against FBIjobs.gov. In a statement shared with Reuters, the agency said it is investigating the incident.

The statement does not confirm that ShinyHunters accessed FBI employee records or other sensitive databases.

The distinction is important because cybercriminal groups sometimes make claims before investigators can establish the full scope of an intrusion. At this stage, the alleged theft of information involving FBI agents and job applicants remains unverified.

The incident follows another high-profile move by ShinyHunters, which recently hijacked the dark web leak site associated with the Clop ransomware operation. The group used the site to issue a ransom demand and challenge its target.

Attack Shows Growing Focus on Trusted Access

Cybersecurity experts say the incident, if confirmed, would be notable because of the target involved. Cato Networks Vice President of Threat Intelligence Etay Maor said a public claim of compromising a law-enforcement agency is different from attacks against ordinary businesses.

Maor also noted that ShinyHunters has continued operating despite arrests, infrastructure seizures, and other disruption efforts. He described the group as an evolving criminal brand rather than a fixed group of people using the same infrastructure.

According to Maor, recent ShinyHunters campaigns have increasingly focused on trusted access routes. These include help-desk social engineering, malicious OAuth applications, and stolen tokens used to connect SaaS services.

The FBI investigation will determine whether ShinyHunters’ claims about the alleged breach are accurate and how much data, if any, the attackers obtained. Until investigators release more technical details, the full impact of the reported incident remains unclear.


Partager :

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont marqués *

Votre expérience sur ce site sera améliorée en autorisant les cookies Politique des cookies