Reverse email, phone number, username or name lookup - Predicta Search
Predicta
Search
Back to blog
cybersecurity
threat-intelligence
cybercrime
osint

ShinyHunters Says It Hacked the FBI: When the Hunters Come for the Bureau

Predicta Lab

October 5, 2026 · 8 min read

Minimal shield with a magenta crosshair next to the title When the Hunters Come for the Bureau

The defacement was a taunt in itself: "This site has been seized by ShinyHunters," a parody of the takedown banners the FBI plasters across criminal marketplaces it dismantles. By Tuesday, September 22, the joke had given way to something more sober. Apply[.]fbijobs[.]gov and the Special Agent Applicant Portal both displayed "currently unavailable," and the bureau confirmed to multiple outlets that it "is aware of claims regarding unauthorized activity affecting FBIjobs[.]gov and is currently investigating." A week later, that investigation was still the last official word on the affair. Then the handcuffs came out.

What is verified, what is only claimed

ShinyHunters says it broke in on Monday 21 night. In the group's telling, it exploited a zero-day in Oracle PeopleSoft, the HR platform behind the recruitment site, pivoted into AWS GovCloud servers, and walked away with 2 to 3 terabytes covering "almost ALL FBI agents" plus everyone who ever applied for a bureau job, along with internal services it names as Criminal Justice, HR and Medlink. All of that, as of this writing, is still claim.

What independent reporting has established is narrower, but it is not nothing. 404 Media, which broke the story, received a sample of 5,000 alleged agent records: names, home addresses, phone numbers, dates of birth, in some cases spouse details. OSINT lookups matched sample phone numbers to real people with the same names, and breach-archive searches tied some numbers to Department of Justice personnel. Reuters went further, checking details including Social Security numbers against credit bureau records and archives held by dark-web intelligence firm District 4 Labs: at least ten records appeared to match, including FBI Director Kash Patel, and a person familiar with the matter said job descriptions lined up in some cases. Later reporting found the sample also contained references to medical material, including psychiatric evaluations and drug-test results, which sharpens the stakes considerably. And on September 28, the FBI reportedly told its own agents and employees that their personal information, including names, addresses, job titles and Social Security numbers, had been exposed in a security incident, while still declining to publicly confirm a breach. What nobody has established is provenance. The data is at least partly real, but no public evidence yet shows it came out of FBI internal systems rather than being stitched together from older breaches.

Two-column comparison of ShinyHunters' claims versus independently confirmed facts

A grudge, not a ransom note

ShinyHunters insists the operation is not financially motivated. Its stated grievance is a May 2026 FBI bulletin, published after the group's attack on Instructure's Canvas platform, which the hackers call defamatory: they deny belonging to The Com, deny swatting victims' relatives and deny fabricating compromising material to extort targets. Their leak-site statement, addressed by name to FBI cyber division assistant director Brett Leatherman and director Kash Patel, gives the bureau one week to correct or delete the offending lines, an ultimatum that runs out at the end of September. Asked what happens to the data otherwise, the group declined to say. It has since softened that ambiguity, telling TechCrunch it will not publish the stolen FBI data because the breach was meant to make a point and dispute the allegations, which it considers done.

The posture fits a pattern of escalating brazenness. In June the same crew exploited a PeopleSoft zero-day (CVE-2026-35273) to extort roughly one hundred universities. Its 2026 victim list already includes Salesforce, Snowflake, McKesson and Instructure. Earlier in September it hacked and defaced the leak site of the Clop ransomware gang, a rival criminal operation. And the group now claims it is turning its new exploit on Fortune 500 companies.

The bureau answers with handcuffs

The real reply to the ultimatum arrived not as a correction but as a video: in a message published on FBI.gov, Brett Leatherman, the very official the hackers addressed by name, announced that the Dutch National Police had arrested one of the alleged leaders. The details confirmed by Dutch police on September 29 are stranger than the video lets on. The suspect, a 24-year-old from Amsterdam, was actually arrested on September 15 for participating in a criminal organization and has been remanded in custody for at least 90 days. Investigators say his seized laptop contained information about two murders to be committed abroad, now the subject of a separate investigation. Brian Krebs and other outlets have identified him as Pepijn van der Stap, chief technology officer of the security firm Neo Security, profiled by Bloomberg in 2024 as a researcher who moonlighted as a criminal hacker. Two caveats temper the triumph: neither the video nor the Dutch statement explicitly ties the arrest to the jobs-portal intrusion, and the group itself told TechCrunch the man "has no association with us."

A year the FBI would rather forget

This is the second reported compromise of an FBI system in 2026, after a March intrusion into a network managing real-time wiretaps and foreign-intelligence warrants. Add the Iran-linked Handala group leaking director Patel's personal email the same month, and the picture is an agency whose own perimeter is under sustained, occasionally successful assault.

The counterintelligence stakes are hard to overstate. A dataset pairing agents with home addresses, phone numbers and spouses is prime coercion and surveillance material for foreign services, and a direct physical threat if it reaches the criminals those agents investigate. Cynthia Kaiser, a former senior FBI cyber official now at Halcyon, says her first worry is short-term harm to agents from the people they put behind bars, and points to the 2016 FBI employee breach as an example: that data is still circulating on the dark web a decade later. Datasets like this do not expire.

Sources: 404 Media, TechCrunch, CyberScoop, BleepingComputer, Cybersecurity Dive, Reuters, FBI (video), TechCrunch (arrest)

Infostealers

Infostealers lets you enter your domain and instantly see which employee accounts, passwords, and systems have been compromised by infostealer malware.

Infostealers - Are your credentials already exposed?

On Our Radar

Audit once, trust forever: the zero-click hole in four AI coding agents

Air Security disclosed Plugin4Shell, a zero-click remote code execution class affecting Claude Code, OpenAI Codex, Gemini CLI and GitHub Copilot. The agents pinned marketplace plugins to a commit SHA but never verified that the fetched code matched it, so attackers could silently swap approved plugins for malicious revisions. Claude Code 2.1.179 and Codex 0.146.0 ship fixes, while Gemini CLI is deprecated without a patch and Copilot relies on GitHub-side protections. Vendors were notified in June 2026. [ CybersecAsia // dev.to ]

Ten years of romance scams end with a flight from Cape Town to a New Jersey courtroom

Five alleged leaders of the Cape Town zone of Black Axe, the Nigerian criminal network formally known as the Neo Black Movement of Africa, were extradited from South Africa on September 11 and arraigned in Trenton federal court on September 14. US prosecutors say the group ran romance scams from 2011 to 2021 that defrauded more than 100 victims, then used threats to squeeze out further payments. Each faces wire fraud and money laundering counts carrying up to 20 years, a rare case of extradition reaching the leadership tier of a West African fraud syndicate. [ US Department of Justice // The Record ]

Seven million Meta glasses, one petition, and Europe running out of patience

Pressure is mounting across Europe against camera-equipped smart glasses after secretly filmed footage of women and girls surfaced online, with a Stop Smart Glasses petition in Britain and Ireland passing 9,100 signatures. Oslo has banned the devices in schools, France's CNIL has urged vigilance, and the European Data Protection Board has commissioned a report due this autumn, while MEPs push for EU-wide rules. Meta sold roughly 7 million pairs in 2025, up from 2 million over the two previous years combined. [ AFP via Digital Journal // Gulf News ]

Geolocating the strikes Mali shows on the evening news

A joint Bellingcat and Jeune Afrique investigation geolocated more than a dozen drone strikes by the Malian military in northern Mali, documenting at least 30 civilian deaths, including 13 people killed in Amasrakad, seven of them children. Using strike footage broadcast on national television, satellite imagery and witness testimony, the researchers show strikes repeatedly hitting markets, compounds and mining sites, with experts describing a guilt-by-location targeting logic. The Malian army, which presents the strikes as precise operations against terrorists, declined to answer the investigation's questions. [ Bellingcat ]

Six years late, 403 million euros: Ireland finally bills Google for location tracking

Ireland's Data Protection Commission fined Google 403 million euros on September 21 for processing users' location data unlawfully and unfairly through Web and App Activity, Location History and Location Accuracy, between May 2018 and February 2020. The inquiry was opened in February 2020 after complaints from European consumer organisations; it is the DPC's first fine against Google and its fourth largest under the GDPR. Google has six months to bring the processing into compliance. [ Data Protection Commission // The Record ]

Written by Predicta Lab

Don't miss our future newsletters !

Get the latest OSINT news, monthly recaps and product updates in your inbox.

More newsletters from Predicta Lab

background shape