NATIONAL

FBI Probes Shiny Hunters’ Claim of Total Agent Data Theft

7h ago · September 25, 2026 · 3 min read

Why It Matters

The Federal Bureau of Investigation is examining a severe allegation that hackers have compromised the personal and professional records of its entire workforce. The incident raises significant questions about federal cybersecurity defenses and the safety of intelligence personnel.

What Happened

The cyber-crime collective Shiny Hunters announced on Tuesday that it had breached FBI servers late Monday night. The group claims to have stolen sensitive data belonging to approximately 38,000 bureau staff members. According to the hackers, the stolen files include agents’ names, roles, badge numbers, home addresses, phone numbers, and information regarding their spouses.

The FBI confirmed it is aware of the claim and stated it is “actively and aggressively investigating the matter.” The bureau is working to determine whether the hackers directly breached its systems or if a third party was involved. Shiny Hunters contacted reporters with samples and screenshots shortly after making the announcement. The BBC reviewed a small portion of the data, which appeared genuine. Reuters reported that some of the leaked information contains details about officials’ job assignments involving Chinese spies, Russian intelligence, and drug cartels.

The hackers identified several compromised internal systems, including FBIJOBS, FBI BEAST, FBI MedLink, and FBI BICS. Shiny Hunters claims it exploited a vulnerability in the Oracle cloud storage system used by the bureau. The group stated its motive is not financial but rather retaliation for an FBI advisory issued in May. That advisory described Shiny Hunters as “threat actors” who use claims of access to prompt payment from targets in tech, finance, and retail sectors.

The hackers gave the bureau one week to correct or remove the allegations before publishing the full databases. The FBI did not respond to multiple requests for comment from the BBC. Cyber-security experts have weighed in on the severity of the breach. William Wright of Closed Door Security described the incident as a “retaliation attack.” Andrew Brandt of Huntress said the incident may provoke the FBI to track down and prosecute members of the hacking group.

By the Numbers

38,000 — approximate number of bureau staff whose information was allegedly stolen.

One week — deadline given by ShinyHunters for the FBI to retract allegations.

Monday night — claimed time of server breach.

Tuesday — day reporters were contacted with samples.

Zoom Out

Shiny Hunters is an international collective of hackers believed to have originally started in France. The group has a history of targeting major organizations, including a breach of Rockstar Games in April and the Canvas education platform in May. Professor Ciaran Martin described the incident as “as serious as it gets when it comes to data breaches.” William Wright added that “no organisation is safe from the group.”

What’s Next

The FBI continues its investigation into the scope of the breach and the identity of those responsible. The bureau faces a deadline set by Shiny Hunters to retract its previous advisory or risk the full publication of the stolen databases. Law enforcement may move to identify and prosecute members of the hacking collective in response to the alleged theft.

Last updated: Sep 25, 2026 at 5:10 AM GMT+0000 · Sources available
STAY INFORMED
Get the Daily Briefing
Top stories from every state. One email. Every morning.