ZeroFox Intelligence Flash Report - ShinyHunters Claims Breach of Sensitive FBI Data
|by Alpha Team

ZeroFox Intelligence Flash Report - ShinyHunters Claims Breach of Sensitive FBI Data
Product Serial: F-2026-09-23a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recent ShinyHunters breach of the Federal Bureau of Investigation (FBI) and the defacement of the FBI's job application website.
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On September 22, 2026, prominent ransomware and digital extortion (R&DE) collective ShinyHunters claimed a breach of the Federal Bureau of Investigation (FBI) and defaced the FBI job application web site.
- ShinyHunters claims it exploited an Oracle PeopleSoft zero-day to steal 2–3 TB of data on almost all FBI agents and job applicants; Reuters independently matched details in a sample of the data against public and previously breached records, though the FBI has confirmed only that it is investigating unauthorized activity on fbijobs[.]gov.
- The claim lands amid a rare convergence of geopolitical flashpoints: the run-up to the November 3 U.S. midterm elections, an escalating U.S.-Iran conflict with fighting also intensifying between Saudi Arabia and Iran-backed Houthi forces, and a Russian gray-zone campaign of drone incursions and sabotage against NATO members.
- ShinyHunters is a decentralized, financially motivated brand with no confirmed nation-state affiliation, and the group states its motive is retaliation over a May 2026 FBI advisory. Given the timing, the target, and the precedent set by Rhysida’s pre-election breach of Berlin’s city government in August 2026, ZeroFox assesses there is a roughly even chance this incident reflects something beyond retaliation alone: deliberate exploitation of the ShinyHunters brand, wittingly or not, for political interference or intelligence-collection purposes.
- ZeroFox warns the more immediate risk is that ShinyHunters sells the stolen personnel data to criminal or nation-state buyers, who could exploit it for blackmail, targeting of agents’ families, or counterintelligence purposes.
Tags: tlp:clear, geo-political, threat actor