tech
ShinyHunters Claims It Breached FBI, Stole Agent Data

The cybercriminal group ShinyHunters says it broke into FBI systems and stole personal data on thousands of agents and job applicants, including names, home addresses, and phone numbers, according to a claim posted on the group's dark web leak site and reviewed by TechCrunch.
The FBI did not respond to a request for comment on the claim Tuesday, TechCrunch reported, and the hackers likewise did not respond to a request for comment from the outlet.
What did ShinyHunters claim to have stolen?
On its leak site, the group said it obtained "sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job," according to TechCrunch, which reviewed the posting. The independent publication 404 Media first reported the breach after receiving a sample of stolen records that included names, home addresses, and phone numbers belonging to FBI agents and their spouses, TechCrunch reported.
ShinyHunters told 404 Media it took terabytes of data but did not specify what it intends to do with the material if its demands are not met, according to TechCrunch's account of the reporting.
How was the data verified?
404 Media verified a portion of the stolen records against public records, TechCrunch reported, lending credibility to at least some of the material the hackers say they took. TechCrunch reported that the hackers, according to 404 Media, first breached an Oracle PeopleSoft server — a system commonly used by human resources and recruiting teams to store job applicants' personal information — before pivoting to an Amazon-hosted government cloud storing data on both agents and applicants.
As of TechCrunch's report, the FBI's jobs site displayed a message saying the portal was "currently down for maintenance," and the bureau's special agent applicant portal was also offline. TechCrunch reported that the hackers had defaced the jobs site.
Why does the group say the hack isn't about money?
ShinyHunters described the intrusion as "not financially motivated," TechCrunch reported, and instead demanded that the FBI remove a report the group says contains false allegations about it. TechCrunch's report did not identify which FBI report the hackers are referring to, and the bureau has not addressed the demand publicly.
ShinyHunters has built a reputation for large-scale data theft and extortion campaigns, according to TechCrunch, though this incident is framed by the group itself as retaliatory rather than commercial.
What does this mean for FBI agents' safety?
The stolen data could pose a major counterintelligence threat, according to TechCrunch, because hackers or foreign intelligence services could use home addresses, phone numbers, and family information to coerce or extort agents into cooperating against their own government. Exposure of spouses' identifying information compounds that risk by widening the pool of people who could be targeted for pressure or surveillance.
TechCrunch's report did not include comment from cybersecurity or counterintelligence officials beyond describing the general risk, and the FBI has not issued public guidance to affected personnel as of the report's publication.
Has the FBI faced breaches like this before?
This is the second known breach of an FBI system this year, TechCrunch reported. Earlier in 2026, unidentified hackers broke into a bureau system used to manage real-time wiretaps and foreign intelligence-gathering warrants — access that could have revealed the identities of surveillance targets, according to TechCrunch.
Separately, FBI Director Kash Patel had his personal email account hacked and leaked by Handala, an Iran-backed hacking group, in what TechCrunch described as retaliation for U.S.-led strikes against Iran. Neither prior incident has been publicly linked to the ShinyHunters claim, and TechCrunch's report treated them as distinct episodes in a pattern of intrusions targeting the bureau this year.
The FBI's silence on the latest claim leaves several questions unresolved: whether the bureau has confirmed the intrusion internally, how many agents and applicants are affected, and whether the requested report will be withdrawn. TechCrunch said it would continue seeking comment from the bureau.
Questions
What data does ShinyHunters claim to have stolen from the FBI?
The group says it took names, home addresses, and phone numbers of FBI agents, their spouses, and job applicants, according to TechCrunch.
Is the ShinyHunters FBI hack financially motivated?
No. The group told 404 Media, as reported by TechCrunch, that the breach was not financially motivated and instead demanded the FBI remove a report it says contains false claims about the group.
How did the hackers reportedly gain access?
TechCrunch reported that 404 Media found the hackers breached an Oracle PeopleSoft server used for HR data, then pivoted to an Amazon-hosted government cloud containing agent and applicant records.