Blogs>ShinyHunters vs. the FBI: What the Alleged FBIJobs Breach Teaches Every Security Team

ShinyHunters vs. the FBI: What the Alleged FBIJobs Breach Teaches Every Security Team

Simulations Labs
📅October 4, 2026
ShinyHunters vs. the FBI: What the Alleged FBIJobs Breach Teaches Every Security Team

Cybercrime groups usually target companies. On September 22, 2026, one of the most notorious went after the FBI itself.

The extortion group ShinyHunters claimed it had breached the Federal Bureau of Investigation and stolen data on current and former employees and job applicants. The FBI's jobs site was defaced with the group's Umbreon Pokémon logo and a "This site has been seized by ShinyHunters" banner, then taken offline for maintenance. The FBI has confirmed it is investigating but has not confirmed the full scope of what the group claims.

What ShinyHunters claims happened

ShinyHunters says it got in on the night of September 21 by exploiting a previously unknown vulnerability in Oracle PeopleSoft, the software behind the FBI's jobs portal. From there, it claims it moved into additional FBI-managed systems, including HR, medical and criminal justice services.

The group says it took between 2 and 3 terabytes of data, including names, home addresses and phone numbers of agents and their families. Those figures come only from ShinyHunters. A sample of around 5,000 records was shared with journalists, and one former agent confirmed to NBC News that a document about them was authentic.

Security firm Vectra's analysis suggests the attackers bypassed a fix for a PeopleSoft flaw that was patched three months earlier. That detail matters: the same group exploited a PeopleSoft vulnerability, CVE-2026-35273, against more than 100 organisations in June.

Why they did it

Unlike most ShinyHunters operations, this one doesn't appear to be about money. The group says it was retaliation for a May 2026 FBI advisory that detailed its tactics and urged victims not to pay. ShinyHunters disputes parts of that advisory and demanded the FBI correct or remove it within a week.

The FBI breach also came right after another headline-grabbing move. On September 18, ShinyHunters hijacked the dark web leak site of rival ransomware gang Clop, exploiting a file upload flaw in the site's content management system. It then set an eight-figure extortion demand against Clop itself. Taken together, the two incidents show a group that is escalating fast and courting attention.

Experts note this is unusual territory. Nation-state hackers have breached law enforcement before, but a cybercrime brand publicly claiming an FBI compromise is a different and far more provocative step.

Where things stand now

The FBI says it is "aggressively" investigating, including whether the attackers got into third-party software or the bureau's own internal systems. According to NPR, many FBI employees first learned about the breach from media reports. Brett Leatherman, assistant director of the FBI's cyber division, posted a video vowing to hunt down the group's members.

Dutch authorities and the FBI have since announced the arrest of an alleged ShinyHunters leader in Amsterdam, though officials have not directly tied the arrest to the FBI hack. Shortly before that announcement, ShinyHunters told reporters it would not publish the stolen FBI data. It admitted, however, that it can't guarantee the sample already shared with journalists won't leak.

Even unconfirmed, the incident has alarmed former officials. Personnel data on agents could be used to expose and pressure the very people investigating cybercrime.

Lessons for every security team

You don't need to be the FBI to learn from this. The same weaknesses exist in organisations of every size.

  • A patch is not the end of the story. If Vectra's analysis is right, attackers bypassed a fix released three months earlier. After patching a critical flaw, test whether the fix actually holds against variations of the original exploit.
  • Public-facing portals are front doors. A jobs site sounds low-risk, but it gave attackers a claimed path to far more sensitive systems. Map what every external application can reach, and segment it.
  • Third-party software needs a joint playbook. When a vendor or contractor runs part of your infrastructure, agree in advance who investigates, who has the logs and who speaks publicly.
  • Tell your own people first. Employees learning about a breach from the news damages trust and slows response. Internal communication belongs in every incident plan.
  • Practice against real attacker behaviour. ShinyHunters chains known vulnerabilities, fast exploitation and public pressure. Teams who have rehearsed those moves respond faster and make fewer mistakes.

Turn headlines into hands-on practice

The best time to learn how an attack like this unfolds is before it happens to you. Reading about exploited enterprise software and defaced portals is useful; working through those scenarios with your own team is far better.

Simulations Labs is a no-code platform for running cybersecurity simulations, from CTF competitions to full cyber ranges and cyber drills. Pick ready-made labs across web security, network security, cryptography and more, or use Simulations Copilot to describe a scenario, such as web application exploitation or incident response, and get matching challenges in seconds. Run private internal competitions, follow progress on live leaderboards and use the analytics to see exactly where your team's skills need work.

The next ShinyHunters-style campaign is already being planned somewhere. Start your free Simulations Labs account, no credit card required, and get your team practising this week.

Sources