Hackers hit the FBI — ShinyHunters say they have stolen 2TB of employee data, but the attack isn't looking for money, just an apology
ShinyHunters defaces FBI’s jobs site, claiming a PeopleSoft zero‑day let them steal 2TB of HR data Group says attack is not for ransom but to dispute FBI’s May PSA alleging harassment and swatting tactics Experts warn exploit itself is highly valuable; FBI site reclaimed, investigation ongoing into breach claims The ShinyHunters extortion group is currently doing brand management in the most ShinyHunters way possible - by hacking into the FBI and stealing the agency’s sensitive files.
The Bureau’s jobs site was defaced and replaced with the usual ShinyHunters content - an ASCII image of the group’s logo, and a message saying “This site has been seized by ShinyHunters.
Rooting your systems since ‘19 :)”.
But instead of putting the FBI on its data leak site and threatening to release stolen files if a ransom isn’t paid, ShinyHunters started speaking to the press, telling The Register it found a zero-day vulnerability in the Oracle PeopleSoft human resource management system, which allowed them to remotely execute arbitrary code on the underlying server.
They used this ability to (allegedly) steal more than 2TB of sensitive data from the FBI’s servers, including names, addresses, phone numbers, and information on spouses for current, former, and prospective FBI employees.
“We hold data on all FBI employees and applicants,” the spokesperson told The Register , noting they had compromised human resources, MedLink, and Criminal Justice Information Services.
Brand management The FBI has yet to comment, and so do both Oracle and AWS, but what’s most peculiar about this incident is that it doesn’t seem to be financially motivated.
So far, everything ShinyHunters’ have been doing was for the money.
They would break into a company, steal their files, and then pressure the victims into paying a ransom demand in exchange for deleting the stolen information.
This time around, the group claims the goal of the attack is to force the FBI to change the record on how it operates.
“This is NOT financially motivated,” the group told The Register .
“We want the FBI to correct or retract their statements they made, which included substantial false allegations.” The statements were made in a security bulletin published on May 15 this year, right after the Canvas attack.
In early May 2026 Instructure, the edtech giant behind the popular Canvas learning system, confirmed suffering a cyberattack and losing sensitive customer data.
It was later disclosed that some of the world’s top universities, including Harvard, Oxford, and MIT , were among the victims.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.