• About Us
King of Computer Media
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us
No Result
View All Result
King of Computer Media
No Result
View All Result

Home - Anti-Virus Software and Internet Security - After leaking Rockstar files, hacker group ShinyHunters strikes again—claims to have hacked the FBI and stolen the personal data of nearly all its agents.

After leaking Rockstar files, hacker group ShinyHunters strikes again—claims to have hacked the FBI and stolen the personal data of nearly all its agents.

KOCPC Editor by KOCPC Editor
September 25, 2026
in Anti-Virus Software and Internet Security, Latest Technology News

Fresh off exposing Rockstar Games’ internal documents, the hacker group ShinyHunters has now set its sights on the FBI. On Tuesday, the criminal group, which makes its living from data leaks and extortion, posted on a dark web notice board and reiterated in an online conversation with Reuters that it had breached the FBI’s recruitment portal and held data on “nearly all FBI agents and every person who has submitted a job application to the FBI.” The FBI’s public response remained as brief as usual, saying only that it was aware of claims of unauthorized activity on FBIJobs.gov and was investigating. The unit responsible for the investigation has yet to determine whether the data leaked from a third-party service provider or was taken from the FBI’s own systems.

Job recruitment website down for two days straight.

FBIJobs.gov is the main gateway for job seekers to learn about the FBI and start the application process. On Tuesday, the website posted a notice saying that the site itself and the “Special Agent application portal” were unavailable; by Wednesday morning, the entire site was still offline. As of now, opening the URL returns a 503 error on the homepage (the page has just been restored).

The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the https://t.co/JGTF1WehtI portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined—whether a third-party or the FBI’s…

— FBI Phoenix (@FBIPhoenix) September 24, 2026

ShinyHunters also claimed to have briefly replaced the pages of a recruitment website, swapping in an icon of the Pokémon Umbreon and putting up a banner reading “This site has been taken over.” The group said the FBI quickly detected the intrusion and immediately took the affected systems offline, while access to multiple networks was cut off at the same time.

The motive was retaliation for the FBI’s public warning.

This time there was no ransom deadline, and the playbook differed from the group’s past extortion model. ShinyHunters framed the attack as retaliation, aimed at an FBI advisory published in May 2026 that detailed the group’s tactics and advised victim organizations not to pay.

In an advisory, the FBI described ShinyHunters as a “cybercriminal group specializing in large-scale data breaches and extortion,” and said these actors often coerce victims into paying through claims of real or exaggerated access. Their usual tactics include sending threatening text messages and making threatening phone calls to victims and their families; in some cases, they even engage in “SWATing,” which is maliciously calling the police to direct a SWAT team to raid a residence.

The group expressed dissatisfaction with this description, demanded that the FBI correct or take down the notice within a week, and emphasized that its actions had nothing to do with money. In a message sent to The New York Times, a representative wrote: “We reiterate that we are not extorting the FBI; this is not financially motivated. The sole purpose is to set the facts straight.” The group also denied any connection to the criminal network law enforcement calls “The Com.”

Sample comparison: some data matches.

To convince the outside world, ShinyHunters presented two pieces of evidence: a screenshot claimed to show a compromised recruitment website, and about 5,000 records of agent data, saying this was only a small portion of it.

The authenticity of the screenshots cannot be verified, but the contents of the sample are far more problematic than a doctored webpage. The records Reuters obtained include agents’ names, home addresses, Social Security numbers, and duty assignments, and some entries also include family members’ names. Reporters compared the names, mailing addresses, and Social Security numbers with credit bureau records and old leaked data held by the dark web intelligence firm District 4 Labs; at least 9 matched. Another report mentioned that records related to Director Kash Patel appeared in the sample.

Reuters stressed that a match only shows the data exists; it cannot prove the source, nor can it prove that the data leaked from FBI internal systems as the group claims.

The intrusion vector is suspected to be a PeopleSoft zero-day vulnerability.

The group disclosed its own intrusion path: on the evening of Monday, September 21, it exploited a previously undisclosed vulnerability in Oracle PeopleSoft to gain remote code execution, then moved laterally to the AWS GovCloud government cloud environment storing agent and applicant files, and claimed to have accessed internal services including criminal justice, HR, and Medlink.

This would be the group’s second exploitation of a PeopleSoft vulnerability this year. In June, Oracle issued an emergency advisory for CVE-2026-35273, a vulnerability in PeopleTools that allows unauthenticated remote code execution; Mandiant and Google later confirmed that ShinyHunters exploited it between May 27 and June 9, mainly targeting universities. Nissan later disclosed that an employee data breach was linked to the same vulnerability, and the group claimed to have compromised 100 organizations and about 300 PeopleSoft instances. The new vulnerability currently has no public CVE ID, and neither Oracle nor Mandiant has confirmed it.

Personnel data and confidential systems are two different things.

Jason Pack is a retired FBI supervisory special agent and currently CEO of Media Rep Global Strategies. He told Fox News Digital that obtaining personnel data and obtaining access to classified investigative systems are two different things. “Based on what is known so far, there is no indication they got the keys to the kingdom.”

He further explained that if assignment information fell into the hands of foreign intelligence agencies, it would create counterintelligence concerns, because they could use it to identify individuals worth approaching, or even assessing for recruitment, but he stressed that this does not mean it has already happened. He also warned that if adversaries know who someone is, where they work, and what they are responsible for, they can design a more credible scam script around that person; and the risk does not end once the vulnerability is fixed—criminals may hold onto the data and use it weeks or months later.

Conclusion: The Announcement, the Outbreak of War, and the Truth Yet to Be Determined

ShinyHunters has been quite active this year. In addition to Rockstar Games’ business records, its May intrusion into the learning platform Canvas affected thousands of schools across the U.S. during final exams, and the group has also been linked to a leak of 4.4 million TransUnion credit records; in early September it claimed to have breached Florida’s driver’s license database, and on the 19th of the same month it defaced rival cl0p’s announcement site and threatened ransom, while Anthropic said it caught hackers associated with the group in September trying to use its tools.

Before this controversy comes to an end, the FBI’s position remains that it is “investigating,” while the group’s claims are only partly supported by evidence. Anyone who has already submitted a job application to the FBI should be extra cautious about sudden contacts that accurately mention the contents of their application.

Source: 1 / 2

Source: KOCPC Chinese

Tags: FBIhackerShinyHunters

Recent Posts

  • The Xiaomi 18 Pro Series dual-size imaging flagships will debut in Taiwan this year.
  • OmniTranscript is a free online tool for converting videos into transcripts and subtitles, supporting YouTube, manual uploads, IG, and TikTok.
  • After leaking Rockstar files, hacker group ShinyHunters strikes again—claims to have hacked the FBI and stolen the personal data of nearly all its agents.
  • Apple releases a video highlighting new child safety features on its devices.
  • The date for the latest Minecraft Live has officially been revealed! Players speculate that the developers will introduce a brand-new dimension, the first in 15 years.

Recent Comments

No comments to show.
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology

No Result
View All Result
  • Home
  • Tech News
  • AI News
  • Apps & Tutorials
  • Mobile & Telecom
  • Lifestyle
  • About Us

We welcome partnership inquiries and product review opportunities from smartphone manufacturers, iPhone accessory brands, and app developers.koc kocpc.com.tw|Privacy Policy |Hosting & Maintenance: Fast Line Taiwan, A-Chang Digital Technology