CNN TürkHAYSİYET 3. BÖLÜM FULL İZLEME LİNKİ: Haysiyet yeni bölümde neler olacak? Kanal D Haysiyet kesintisiz izleESPN DeportesGiants pierden por tiempo prolongado a DartThe Jerusalem PostTrump pledges 'unmatched military might' against drug cartels at UNGAESPNSource: Niners signing veteran receiver Cooks to practice squadPunchAlleged wiretapping: El-Rufai awaits Oct 26 no-case rulingDaily MaverickSAPS IN CRISIS: The State versus Shadrack Sibiya — unpacking the explosive rape, grooming, human trafficking chargesSDP Espectáculos¿Quién es quién en la serie de Timbiriche? Reparto y personajes para ViX한겨레이정현 검찰총장 대행 “이 대통령 공소취소, 진상조사 결과 살펴봐야”South China Morning PostShelters warn against poor treatment of warehouse guard dogs in New TerritoriesUOLRenan Santos: Jornalismo independente fez 'trabalho fundamental' no caso do Banco MasterColliderStar of Prime Video's #1 Action Hit Officially Responds to Shock CancellationSBS 뉴스김민석, '재제청 거부' 조 대법원장에 "대통령과 권력다툼 놀이 · 내란 성격"
The Daily Newsstand · Free, Always
Wednesday, September 23, 2026

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

Translate

ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. 

“This is NOT financially motivated,” a Shiny spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”

The FBI did not immediately respond to The Register’s request for comment.

REG AD

According to a ShinyHunters spokesperson, the extortion group exploited an Oracle PeopleSoft zero-day vulnerability on the FBI jobs webpage, which it says allowed remote code execution (RCE) on the servers. The group then defaced the website, replacing it with a “This site has been seized by ShinyHunters” banner and image shared with The Register

REG AD

ShinyHunters take over

Screenshot of ShinyHunters attack
ShinyHunters

At press time, the site says it is “currently down for maintenance but will be back up soon!”

FBI jobs site's down message

Screenshot of FBI jobs site
Jessica Lyons

ShinyHunters also claims it moved laterally from the compromised site onto the FBI’s managed servers on AWS GovCloud, and downloaded about 2 TB to 3 TB of data belonging to current, former, and prospective FBI employees.

“We hold data on all FBI employees and applicants,” the spokesperson told us.

ShinyHunters claims the compromised FBI services include human resources, MedLink, and Criminal Justice Information Services.

Neither Oracle nor AWS immediately responded to our inquiries, including whether Oracle is aware of a PeopleSoft preauth RCE zero-day, and whether AWS has any insight into the alleged data theft. We will update this story if we receive any response.

Unlike most of the group’s smash-and-grab operations that involve a multimillion-dollar ransom demand to not leak the stolen files, ShinyHunters said it isn't seeking an extortion payment from the FBI.

Instead, it wants the federal cops to retract statements made about ShinyHunters in a May 15 bulletin, shortly after the gang broke into ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff. The FBI said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”

The security alert also said that extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

REG AD

Shiny claims none of this is true. “I have been doing my very best to combat these allegations,” they told us. “And this is the best way to do it.” ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.