Skip to content
logo The magazine for digital lifestyle and entertainment
CoBi News Security All topics
ShinyHunters Strikes Again

Hackers Claim Responsibility for FBI Attack

A man in a hoodie—allegedly a hacker—sits in front of a computer, surrounded by a flurry of data code.
ShinyHunters Claims Successful Cyberattack on FBI Photo: Getty Images

September 26, 2026, 6:39 am | Read time: 2 minutes

The cybercrime group ShinyHunters claims to have breached FBI systems and stolen large amounts of sensitive data. Initial samples suggest that at least parts of the released information could be genuine.

ShinyHunters publicly stated that they have seized between two and three terabytes of data from FBI systems. According to the group, this includes information on current and former employees as well as applicants for the U.S. federal agency. The FBI has not yet commented on the allegations.

Also of interest: Hackers steal 350 GB of data from the EU Commission

Simultaneously with the hackers’ claims, the FBI job application website was temporarily inaccessible and displayed a maintenance message. Whether this is actually related to the alleged attack is currently unclear. There is also no official confirmation of the data theft yet.

Attack via Oracle Software

According to ShinyHunters, the attack began on September 21 through a previously unknown security vulnerability in Oracle PeopleSoft. The software is often used for managing personnel and applicant data. Through this entry point, the attackers reportedly accessed additional systems.

The group claims to have subsequently accessed FBI-used servers at Amazon Web Services. The stolen datasets are said to have been exfiltrated there. Additionally, the hackers claim to have manipulated the FBI’s career page and displayed a message from the group. Neither Oracle nor Amazon have commented on the allegations so far.

Conflict with the FBI as a Possible Motive

Unlike many other attacks, ShinyHunters claims they are not demanding ransom this time. Instead, the group refers to an FBI report from May 2026. In it, the agency warned about the hackers’ methods and advised victims not to make ransom payments.

Several media outlets have since reviewed parts of the released datasets. Reuters reported that they were able to match various names and addresses with other databases. 404 Media also received a sample of about 5,000 datasets, some of which could be verified. However, whether the information actually originates from internal FBI systems or was compiled from other sources cannot be definitively proven at this time.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.