-
ShinyHunters says it broke into FBI systems through a hidden flaw in Oracle’s PeopleSoft software.
-
The group claims it stole 2 to 3 terabytes of data on FBI staff and job seekers.
-
The FBI says it is checking reports of strange activity on its jobs website, but has not confirmed a breach.

A hacking group is making a big claim. ShinyHunters says it broke into computer systems tied to the U.S. Federal Bureau of Investigation.
The group says it stole huge amounts of private data on FBI workers and people who applied for jobs there. The FBI has not confirmed a full breach. But the bureau says it is looking into strange activity on one of its websites.
How ShinyHunters Says It Got In
According to BleepingComputer and 404 Media, ShinyHunters used a zero-day flaw nobody knew about before. The flaw sits inside Oracle PeopleSoft, a software system many big agencies use. The hackers say the flaw lets them run their own code on FBI servers from far away. From there, they claim they moved into FBI systems hosted on Amazon Web Services GovCloud.
The group says it grabbed between 2 and 3 terabytes of data. That is a massive amount of information. ShinyHunters claims the stolen files came from FBI human resources records, criminal justice files, medical data, and job application systems.
The FBI told BleepingComputer it knows about the claims. The bureau said it is investigating unauthorized activity tied to its jobs website, FBIjobs.gov. However, the FBI has not confirmed that its wider systems were hit. It also has not confirmed the amount of data the hackers say they took.
Reports say the FBI jobs site itself was defaced. A message from ShinyHunters reportedly appeared on the page before the site went offline. The hackers claimed the stolen files included personal details and health information.
Records Match Real People, but Questions Remain
404 Media reviewed a sample of the alleged stolen files. The sample held roughly 5,000 records that ShinyHunters said belonged to FBI staff. The outlet checked some of the details against public information. Several phone numbers reportedly matched real people with the same names. Some of those names were linked to workers at the U.S. Department of Justice.
This match gives some weight to the group’s claims. Real names lining up with real phone numbers suggests the hackers hold genuine data. Still, this alone does not prove the FBI’s core systems were breached. It also does not confirm the larger 2 to 3 terabyte figure that ShinyHunters is claiming.
Large-scale data-sale claims have also surfaced in other cases. Our coverage on China mobile security concerns over an alleged 850 million-record data sale covers another reported claim involving a massive volume of allegedly stolen records, highlighting the need to verify such data before treating the claims as confirmed.
TechCrunch also reported that ShinyHunters says it holds files on thousands of FBI staff members and job applicants. Reuters and The Register have covered the story too, noting the FBI has given no immediate confirmation of a wider compromise.
A Grudge Against an FBI Warning
ShinyHunters gives a reason for the alleged attack. The group says it acted in response to an FBI warning issued back in May 2026. That warning, a public service announcement from the Internet Crime Complaint Center, linked ShinyHunters to large-scale data theft and extortion schemes. The notice also warned that the group might exaggerate how much access it really has.
The hackers reportedly gave the FBI one week to change or take down that May notice. They have not said what happens if the bureau refuses. It is still unclear whether they plan to release any stolen files publicly.
There is one detail worth clearing up here. ShinyHunters has exploited a PeopleSoft flaw before this year, but that earlier flaw is different from the one used in the alleged FBI break-in. Google Threat Intelligence reported in June that ShinyHunters had exploited a bug tracked as CVE-2026-35273, a serious flaw that let attackers run code without logging in first. That attack hit organizations before Oracle released a fix on June 10.
The flaw behind the alleged FBI hack is a separate, newer issue. Oracle and the FBI have not publicly confirmed this second flaw exists.
For now, many parts of this story remain open. The FBI is investigating the reported activity on its jobs website. The full scope of any breach, the method used to get in, and the true amount of stolen data are all still unverified. What is clear is that a well-known hacking group is making serious claims against a major U.S. law enforcement agency, and the coming days may bring more clarity.