INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters Issues Ultimatum to FBI Over Data Leak Concerns
| 2026-09-28 21:56 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
On September 22, 2026, the ShinyHunters group claimed to have compromised multiple FBI systems, including the Jobs portal, and downloaded between 2TB and 3TB of information. The group attributed this attack to an Oracle PeopleSoft zero-day vulnerability. In a subsequent one-week ultimatum, ShinyHunters stated it would not publish or sell the allegedly stolen FBI data, claiming it was part of a marketing campaign to counter FBI claims. This APT Group is believed to be behind the incident and has been attributed by sources as such. The targeted sector appears to be the FBI's internal systems, with potentially affected individuals being FBI employees and job applicants.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ha•••••.com
fb•••••.gov
ap•••••.gov
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
UmbreonUmbreon
Target & Sectors
Global Scope
Incident Timeline
September 22
Threat actors ShinyHunters claimed the FBI would not leak compromised data when their September 22 ultimatum ended.
Click on any entity below to view its context and source!
attribution
FBI Jobs
The clarification follows the group’s September 22
attack on the FBI Jobs portal
.
September 23, 2026
Threat actors known as ShinyHunters claimed that the FBI's data would not be leaked when an ultimatum expires.
Click on any entity below to view its context and source!
attribution
FBI
While the point of breach is still undetermined—whether a third-party or the FBI’s…
— FBI (@FBI)
September 23, 2026
2026/09/28
ShinyHunters claims it will not publish or sell the FBI data it allegedly stole, stating its one-week ultimatum was part of a marketing campaign to counter false allegations made by the agency.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The ShinyHunters extortion group says it will not publish or sell the FBI data it claims to have stolen, clarifying its intentions as the one-week period it gave the agency to correct or remove a disputed cybercrime report approaches its end.
“The reason why we have stated multiple times that this is not extortion is because since the very beginning we had made our decision that we would never publish this data,”
ShinyHunters
told Hackread.com.
Exclusive: ShinyHunters Says FBI Data Won’t Be Leaked When Ultimatum Ends.
ShinyHunters tells Hackread it never planned to publish or sell stolen FBI data and says its ultimatum was part of a marketing campaign to counter FBI claims.
ShinyHunters’ message – Click to enlarge – (Image credit: Hackread.com)
Some media reports and public discussion interpreted the one-week period as a deadline, after which the stolen FBI data would be published.
It also said it never referred to the one-week period as a “deadline.”
ShinyHunters Calls It a Marketing Campaign
Explaining the one-week demand, the group told Hackread.com that gaining publicity for its dispute with the FBI was part of the plan.
The One-Week Message and ShinyHunters’ Dispute With the FBI
Following the breach, the hackers published a lengthy message addressed to
FBI Director Kash Patel
and Brett Leatherman, assistant director of the FBI’s Cyber Division.
The message specifically objected to FBI statements that ShinyHunters may exaggerate claims of access to sensitive information, use harassment tactics including threatening victims and their family members or swatting, and falsely claim to possess sensitive or compromising material.
“Nothing will happen,” ShinyHunters told Hackread.com about the end of the one-week period.
organisation
Hackread.com
“The reason why we have stated multiple times that this is not extortion is because since the very beginning we had made our decision that we would never publish this data,”
ShinyHunters
told Hackread.com.
data_breach
2 TB
The group claimed to have downloaded between 2TB and 3TB of information, including FBI employee and job applicant data.
data_breach
3 TB
The group claimed to have downloaded between 2TB and 3TB of information, including FBI employee and job applicant data.
Tactical Metrics
Metrics
data_breach
2
Tb
Click for context!
The group claimed to have downloaded between 2TB and 3TB of information, including FBI employee and job applicant data.
Metrics
data_breach
3
Tb
The group claimed to have downloaded between 2TB and 3TB of information, including FBI employee and job applicant data.
Intelligence Sources
HackRead
2026-09-28
AlienVault OTX
2026-09-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T10:34
Comprehensive Tactical Telemetry
Highly Correlated Entities
8x
attribution
Attributing Entity
FBI Data
authority
3x
timeline
Temporal Reference
September 23, 2026
date
2x
tactic
Cyber Operation Type
Extortion
tactic
2x
data breach
Tb
2
tb
Contextual Telemetry
Context Block
4 METRICS
threat actor
APT Group
ShinyHunters
actor
industry
Targeted Sector
Media
sector
organisation
Identified Entity
Hackread.com
entity
malware
Malware Payload
Umbreon
tool
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.