The FBI jobs site, which was temporarily defaced, remains unavailable and the agency said it’s investigating the claims.
The post ShinyHunters claims attack on FBI exposes almost all agents appeared first on CyberScoop.
The FBI is investigating an attack on its own systems after ShinyHunters claimed responsibility for the incident, putting the prolific cybercrime group in the most direct conflict yet with agents responsible for investigating data extortion attacks.
The Monday breach, first reported by 404 Media, allowed ShinyHunters to temporarily deface the FBI jobs site. The group claimed it stole “very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job,” in a lengthy post on its data-leak site.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” a spokesperson for the agency said in a statement.
An alert on the FBI jobs site notes that apply.fbijobs.gov and the Special Agent Application Portal are currently unavailable.
The attack marks a sobering escalation by ShinyHunters, a notorious group that previously targeted major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers. Previous victims of ShinyHunters this year include Instructure, Salesforce, Snowflake and McKesson.
“The ShinyHunters ransomware group appears to be actively trying to put a target on their back,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop.
ShinyHunters claims it targeted the FBI in response to a public service announcement it says contains false allegations about the group. The FBI issued the PSA following ShinyHunters’ May attack on Instructure, the company behind Canvas, a widely used central hub for K-12 and university coursework, exams and communication.
The group responded with its own “PSA” on its data-leak site, insisting it is not affiliated with The Com, has never conducted swatting attacks or claimed it had sensitive or compromising information, including embarrassing photos or videos, to extort victims.
The PSA was addressed to Brett Leatherman, assistant director of the FBI’s cyber division, and FBI Director Kash Patel.
“While ShinyHunters has in the past been hyperbolic about the criticality of the data they’ve accessed, the group has established itself as a legitimate threat,” Flashpoint analysts told CyberScoop.
“This attack benefits ShinyHunters by bolstering their reputation as a credible threat,” the analysts added. “In the group’s statement on their leak site regarding the breach, they portray the FBI’s PSA as an “attempt to ‘disrupt’ our operations and hinder clients’ trust in our organization hoping nobody pays us.”
The threat group typically uses social engineering, abuses weaknesses in identity systems or exploits vulnerabilities to gain access to cloud-hosted environments containing troves of sensitive or proprietary data, which it threatens to leak if the victim doesn’t pay a ransom.
ShinyHunters doesn’t appear to be seeking a payoff in this case, but rather a bid to coerce the FBI into amending or removing the May PSA. The group didn’t make any direct threat in the data-leak site post to release the stolen data, but it set a deadline of one week for action.
That coercive approach toward the FBI could backfire, according to experts.
“Ransomware groups are largely successful because they operate like businesses,” said Kaiser, a former deputy assistant in the FBI’s cyber division. “Targeting other criminal groups or law enforcement — especially in ways intended to publicly shame — demonstrates a lack of discipline that historically has led to takedowns, takeovers or defections.”
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Cybergang ShinyHunters behauptet Einbruch in FBI-Jobportal | 0 | 11.3 | 24-09-2026 |
| 2 | Группировка ShinyHunters заявляет, что взломала ФБР и похитила данные всех сотрудников | 0 | 9.57 | 23-09-2026 |
| 3 | ShinyHunters Site Goes Dark After Claiming Massive FBI Data Breach Amid Dutch Investigation | 0 | 5.8 | 01-10-2026 |
| 4 | Hackeři pronikli do FBI. Tvrdí, že získali zdravotní záznamy a identity desítek tisíc agentů | 0 | 6.16 | 26-09-2026 |
| 5 | Hackergrupp: Har stulit känsliga hälsouppgifter om alla FBI-agenter | 0 | 13.52 | 25-09-2026 |
| 6 | FBI warns ShinyHunters members to come forward after alleged leader’s arrest | 0 | 6.82 | 29-09-2026 |
| 7 | ShinyHunters says it won’t publish FBI data | 0 | 8.92 | 28-09-2026 |
| 8 | FBI 与荷兰合作逮捕 ShinyHunters 组织领导成员 | 0 | 8.4 | 30-09-2026 |
| 9 | This Week in Security: FBI Gets Hacked, Muse Vulnerable to ClickFix, Popular Rust Developers at Risk, and New Attacks Against RSA | 0 | 30.1 | 25-09-2026 |
| 10 | Jail time for Maine child in 764 marks turning point in federal law enforcement | 0 | 11.09 | 02-09-2026 |