The personal information of potentially every FBI employee and applicant may now be in the hands of a notorious hacking group that defaced the bureau’s jobs website this week in what appears to be an act of revenge against the federal agency.
ShinyHunters, an infamous cybercriminal organization, claims to have stolen between two and three terabytes of sensitive data from the FBI, including home addresses, phone numbers, dates of birth, and information about agents’ spouses. The group told 404 Media the attack was “not financially motivated,” a sharp departure from its typical ransomware playbook.
“We hacked the FBI. We hold data on all FBI employees and applicants,” a representative for ShinyHunters said.
The hackers defaced apply.fbijobs.gov Monday night, styling their message after a law enforcement seizure notice. It read: “This site has been seized by ShinyHunters.” The message went further, claiming: “All FBI data was compromised including PII/PHI on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”
At the time of reporting, the FBI jobs site and its Special Agent Applicant Portal remained offline, displaying a message that the sites were “currently unavailable.”
The attack’s authenticity gained credibility when 404 Media reviewed a sample of the alleged stolen data covering 5,000 purported agents. Reporters cross-checked phone numbers using the OSINT Industries tool and found they matched the names listed in the files. A separate check using Darkside, a compromised-data tool built by cybersecurity company District 4, turned up some phone numbers associated with personnel at the U.S. Department of Justice.
ShinyHunters said it exploited a zero-day vulnerability in Oracle’s PeopleSoft software to gain initial access, then used that foothold to reach AWS GovCloud servers where it downloaded the massive trove of information.
The motivation behind the breach appears rooted in a grudge. ShinyHunters took issue with an FBI report that accused the group of exaggerating its access to victims’ systems to pressure them into paying ransoms, sending threatening messages and calls to victims and their families, and carrying out swatting attacks in some cases.
The hackers posted on their leak website calling the report’s contents “false allegations” and demanded a correction, giving the bureau “a time of 1 week to correct” or remove the report.
For now, thousands of current and former FBI employees, along with anyone who has ever applied to work for the bureau, must wonder whether their most personal information is sitting on a hacker’s server, waiting to be leaked or sold to the highest bidder.






