ShinyHunters hackers say they breached FBI, stole data on bureau employees


The digital extortion group known as “ShinyHunters” said on Tuesday that it had breached the Federal Bureau of Investigation and stolen data on a huge number of current and former FBI employees. The bureau did not respond to repeated messages seeking comment on Tuesday.

In a statement posted to its dark-web site and during an online chat with Reuters, ShinyHunters said it had targeted the FBI in response to a May 2026 agency announcement that detailed ShinyHunters’ methods and advised targets not to pay. It said it had stolen data “on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.”

As proof, the group offered what it said was a screenshot of a vandalized FBI job site and what it described as a small sample of its stolen data.

Read more…
Source:  CNBC News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • US Air Force admits SharePoint privacy issue as reports trickle out of possible breach

    October 1, 2025

    The US Air Force is reportedly investigating a potential data breach caused by a Microsoft SharePoint issue. A report from The Register revealed the Air Force Personnel Center Directorate of Technology and Information issued a data breach notification shared on social media. “This message is to inform you of a critical Personally Identifiable Information (PII) and ...

  • YouTube to pay $24.5 million to settle Trump lawsuit

    September 30, 2025

    YouTube agreed to pay $24.5 million to settle a lawsuit filed by President Donald Trump after he was suspended by social media platforms following the January 6, 2021, insurrection. This makes Alphabet-owned YouTube the last of the three Big Tech social media companies sued by Trump — which included Meta and then Twitter, now called X ...

  • ‘Widespread’ breach let hackers steal employee data from FEMA and CBP

    September 29, 2025

    A “widespread cybersecurity incident” at the Federal Emergency Management Agency allowed hackers to make off with employee data from both the disaster management office and U.S. Customs and Border Protection, according to a screenshot of an incident overview presentation obtained by Nextgov/FCW. The hack is also suspected to have later triggered the dismissal of two dozen ...

  • CISA Directs Federal Agencies to Identify and Mitigate Potential Compromise of Cisco Devices

    September 25, 2025

    Today, CISA issued Emergency Directive ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices to address vulnerabilities in Cisco Adaptive Security Appliances (ASA) and Cisco Firepower devices. CISA has added vulnerabilities CVE-2025-20333 and CVE-2025-20362 to the Known Exploited Vulnerabilities Catalog. The Emergency Directive requires federal agencies to identify, analyze, and mitigate potential compromises immediately. Agencies ...

  • US federal agency breached by hackers using GeoServer exploit

    September 24, 2025

    In mid-July 2024, a threat actor managed to break into a US Federal Civilian Executive Branch (FCEB) agency by exploiting a critical remote code execution (RCE) vulnerability in GeoServer, the government has confirmed. In an in-depth report detailing the incident, the US Cybersecurity and Infrastructure Security Agency (CISA) outlined how the attackers leveraged CVE-2024-36401, a 9.8/10 ...

  • Top auto insurance firm leaked over 5 million records

    September 24, 2025

    ClaimPix, a company which streamlines car insurance claims, was leaking sensitive customer data on the clearweb, including people’s phone numbers, and email addresses, an expert has warned. Security researcher Jeremiah Fowler, known for hunting down misconfigured and unprotected databases, recently found one such instance containing 5.1 million files, sharing his findings with WebsitePlanet. The archive was ...