INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Seizes Job Applicants' Site and Acquires FBI Target Data
| 2026-09-22 18:43 CRITICAL HIGH LAW ENFORCEMENT
Executive Summary
AI-generated
On September 22, 2026, a high-profile hacking group called ShinyHunters claimed to have breached multiple FBI-related services and stolen data on all FBI employees and applicants. The affected individuals include approximately 100 Special Agents and thousands of job applicants. According to the attackers, they used a zero-day exploit in an Oracle product called PeopleSoft to access AWS GovCloud servers and download sensitive personal identifiable information (PII) and protected health information (PHI). ShinyHunters posted a "Public Service Announcement" on its DLS website, claiming that it has compromised FBI services including Criminal Justice, HR, Medlink, and others. The attackers are demanding payment in Bitcoins from the victims within one week to correct or remove false allegations made against them in an FBI report.
Technical Mitigations AI-generated
• Data Backup (ATT&CK mitigation for Defacement): Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups a
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ap•••••.gov
da•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered SpiderShinyHuntersShinyHunters
UmbreonUmbreonQilinQilin
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
governmentgovernment
Incident Timeline
May 2026
ShinyHunters claimed to have seized a job applicants' site and acquired data, escalating their dispute with the FBI.
Click on any entity below to view its context and source!
organisation
DataBreaches
DataBreaches is not surprised that they are protesting certain statements in the referenced May 2026 PSA.
threat_actor
ShinyHunters
In any event, what ShinyHunters has done in hacking the FBI is obviously illegal and amounts to extortion— or an attempt at extortion.
DataBreaches actually agrees with ShinyHunters that some of the descriptions in it do not really apply to ShinyHunters but to other groups — groups that have been conflated with ShinyHunters inaccurately.
Those who try to paint ShinyHunters with the label and wrongdoing of “The Com” generally do not provide evidence for some of the worst claims—claims that appear to be accurate for The Com, but not for the narrower group known as ShinyHunters.
Some of the conflation problem, however, is on ShinyHunters’ own head, as
they had told DataBreaches
that both ShinyHunters and Scattered Spider “are the same now,” and “they’ve always been the same.
FBI is One Victim, Clop was Another
ShinyHunters’ increased aggressiveness and posturing seem part of a new intensification of their pressure tactics.
The dispute stemmed from Clop’s use of a zero day that ShinyHunters had claimed as theirs.
The text of ShinyHunters’ public notices about Clop from their DLS appears below in reverse chronological order:
Note to Cl0p-_-
RESPONSE:
Its spelt *ShinyHunters, with no space, moron.
threat_actor
Scattered Spider
Some of the conflation problem, however, is on ShinyHunters’ own head, as
they had told DataBreaches
that both ShinyHunters and Scattered Spider “are the same now,” and “they’ve always been the same.
organisation
DLS
The text of ShinyHunters’ public notices about Clop from their DLS appears below in reverse chronological order:
Note to Cl0p-_-
RESPONSE:
organisation
Lapsus$
Shortly thereafter, Lapsus$ joined in.
organisation
Likhogray & Tarasov
I am 3-0 against you rich and broke criminals.
UPDATE, 20 Sep, 1:39 a.m ET:
Dear Likhogray & Tarasov, tell your boss j0nny to wake the fuck up.
organisation
Dear Likhogray & Tarasov
I am 3-0 against you rich and broke criminals.
UPDATE, 20 Sep, 1:39 a.m ET: Dear Likhogray & Tarasov, tell your boss j0nny to wake the fuck up.
organisation
EBS
I want all the money you made off the EBS campaign plus more AND WITH INTEREST.
organisation
CLOCK
CLOCK IS TICKING!
Clock is ticking moron.
organisation
the white board
Get your bosses in front of the white board in the war room.
Sep 2026
ShinyHunters edited their PSA to add a preface addressing the FBI's false allegations, claiming they seized job applicants' site and acquired data.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
Image: DataBreaches.net
What Will the FBI Do?
Will FBI refuse to negotiate with ShinyHunters?
Update:
ShinyHunters later edited their PSA to add a preface to their PSA:
2026/09/22
ShinyHunters claimed to have seized a job applicants' site and acquired data, prompting an FBI dispute.
Click on any entity below to view its context and source!
tactic
Extortion
Our PSA today works to address these allegations and correct them
It’s still extortion.
threat_actor
ShinyHunters
ShinyHunters’ PSA reads:
Our PSA today works to address these allegations and correct them.
2026/09/22
ShinyHunters claimed to have seized the job applicants' site and acquired data, including FBI agents' names, home addresses, phone numbers, and information on their spouses.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The defacement, with the ShinyHunters avatar depicting the Umbreon character from Pokemon, claims:
THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS
rooting your systems since ’19 😉
All FBI data was compromised including sensitive PII/PHI on incumbent and former FBI erployees and all applicant information.
A representative of the group, called ShinyHunters, told
404 Media
the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.
-SH
Updated: 23 Sep 2026
Extortion is Not Protected by the First Amendment
Although ShinyHunters may claim that they are not engaging in extortion, they most certainly appear to be engaged in extortion by demanding the government remove a document that they do not agree with, presumably with some understanding that they will delete the data they have acquired.
ShinyHunters Posts a “Public Service Announcement”
As of publication, ShinyHunters posted a “PSA” on its DLS, while the apply.fbijobs.gov site shows an “under maintenance” notice that appears to have replaced a former “unavailable” notice.
ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1).
Criminals from the same ecosystem as ShinyHunters have previously
used hacked data like phone records
to
track
, intimidate, and harass the FBI agents investigating them.
[…]
The representative said ShinyHunters said the group used a zero day exploit in an Oracle product
called
PeopleSoft
.
data_breach
1 data
ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1).
organisation
PeopleSoft
[…]
The representative said ShinyHunters said the group used a zero day exploit in an Oracle product
called
PeopleSoft
.
organisation
@vxdb
A copy of the defacement of the apply.fbijobs.gov page was uploaded to X.com by
@vxdb
.
organisation
AWS GovCloud
From there, the group managed to access AWS GovCloud servers and downloaded data.
organisation
NEVER
We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats.
organisation
UNEQUIVOCALLY
Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of “The Com”.
Tactical Metrics
Metrics
data_breach
1
Data
Click for context!
ShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired data (1).
Intelligence Sources
Data Breaches
2026-09-22
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:52
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
@vxdb
entity
8x
attribution
Attributing Entity
FBI
authority
3x
general metric
Sep
19
sep
3x
tactic
Cyber Operation Type
Extortion
tactic
3x
timeline
Temporal Reference
2026/09/22
date
2x
target region
Target Country
United States
country
2x
general metric
Hours
24
hours
2x
industry
Targeted Sector
Media
sector
2x
threat actor
APT Group
ShinyHunters
actor
2x
malware
Malware Payload
Umbreon
tool
Contextual Telemetry
Context Block
7 METRICS
general metric
Sep Update
21
sep update
general metric
Media
404
media
general metric
-Sh
23
-sh
data breach
Data
1
data
general metric
Quarter
2
quarter
general metric
Entities
3
entities
general metric
%
2
%
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.