The FBI is investigating ShinyHunters’ claim that it has stolen sensitive information belonging to roughly 38,000 bureau employees and agents.
The cybercrime group says it possesses names, job titles, badge numbers and personal information including home addresses, telephone numbers and details about spouses or partners.
Professor Ciaran Martin, the former head of the UK’s National Cyber Security Centre, said that if the claim proved true, it would be among the most serious types of data breach.
In a statement posted on X, the FBI said it was aware of the allegation and was “actively and aggressively investigating the matter”.
ShinyHunters said it breached the FBI’s servers on Monday night and began contacting journalists on Tuesday, providing samples and screenshots of the alleged stolen data.
The BBC reviewed a limited sample of the material, which appeared to be authentic.
According to Reuters, some of the data concerns officials’ assignments, including sensitive operations involving Chinese intelligence, Russian intelligence and drug cartels.
ShinyHunters is an international hacking collective believed to have originated in France. It has claimed responsibility for several prominent incidents, including breaches of Rockstar Games in April and the education platform Canvas in May.
The group says it exploited a vulnerability in the Oracle cloud storage system used by the FBI to access several systems, including FBIJOBS, FBI BEAST, which conducts employee and applicant background checks, FBI MedLink, which stores medical records, and FBI BICS, which contains investigation information.
In its dark-web post, the group said it did not target the FBI for financial gain.
Instead, ShinyHunters is demanding that the agency withdraw a May advisory about the group, saying it was offended by the way it was described.
The FBI’s public service announcement described ShinyHunters as “threat actors” that frequently “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims”.
The advisory added: “They target major companies across tech, finance, and retail, often stealing millions of customer records at once.”
ShinyHunters said it would give the FBI one week to correct or remove the allegations, warning that it would publish the full databases if the agency did not comply.
The FBI did not respond to repeated requests for comment from the BBC.
In its X statement, the agency said it was trying to determine whether the hackers had compromised FBI systems directly or accessed data through a third party.
“We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the post said.
William Wright of Closed Door Security described the incident as a retaliation attack and argued that it showed no organisation was immune from the group.
“The group clearly wants to control the narrative around its activities, ensuring nothing is said that could damage its reputation,” Wright said.
Andrew Brandt of cybersecurity firm Huntress warned that the threat could prompt the FBI to pursue and prosecute members of the group.
“ShinyHunters must feel pretty confident they won’t get caught to threaten a government agency like this,” he said.
Also Read
- Revolut Trials In-Store Facial Recognition Payment System in the UK
- 3I/ATLAS: Could This Interstellar Comet Reveal Clues About Life Beyond Earth?
- New Google DeepMind Chief Says Gemini 4 Nearing Completion, Aims for Rapid Release
- Key Details of the OpenAI‑Linked Breach of an Australian Government Site


