"It’s a game and it’s the world we live in,” a ShinyHunters spokesperson told The Register.
ShinyHunters' stated motive and message
ShinyHunters told The Register that the group hacked the FBI not for money, but to “protect our business” and rebut a May 2026 FLASH bulletin that, the FBI said, linked the crew to harassment, swatting and false-claim tactics. The crew said the FBI intrusion was “specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report,” and that publishing proof of the breach “directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers.”
The group framed the operation as a marketing and reputation exercise intended to reassure “future corporate partners we engage with for payment,” whom the group described as likely to prefer negotiating with ShinyHunters rather than going to full public disclosure. The spokesperson said the breach was addressed to FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI’s Cyber Division.
PeopleSoft zero-day and AWS GovCloud servers
ShinyHunters told The Register the initial access to the FBIJobs.gov portal was obtained via an Oracle PeopleSoft preauthentication zero-day vulnerability. The portal remained offline as of Friday while the FBI investigated, and the group claimed the same PeopleSoft vulnerability could expose similar HR and employee records at other organizations.
After the portal access, the crew said it breached the FBI’s managed servers on AWS GovCloud and removed “thousands of personnel files” belonging to current, former, and prospective FBI employees. Oracle “hasn’t responded” to questions about the zero-day, and ShinyHunters declined to say whether they had used the bug against other victims.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildScope of stolen FBI personnel data
According to the group and samples reviewed by journalists and security researchers, the files included personally identifiable information: home addresses, phone numbers, email addresses, Social Security numbers, job titles, assigned field office and emergency contact information. The Register reported that the crew claimed to “hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.”
The FBI confirmed to The Register that it was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII).” An FBI spokesperson told The Register the point of breach remained undetermined — “whether a third-party or the FBI’s enterprise” — and that investigators were “actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”
Previous Instructure / Canvas intrusion and the May FLASH bulletin
The Register recounts ShinyHunters’ role in a separate late-April intrusion of Instructure’s Canvas platform, where the group claimed to have stolen data tied to hundreds of millions of students, teachers and staff. After the initial ransom deadline passed on May 6, ShinyHunters injected a ransom message into about 330 Canvas school login portals, prompting Instructure to take the platform offline for a day — an outage that coincided with final exams and Advanced Placement testing for many schools.
Instructure “reached an agreement” with ShinyHunters; Alliance Risk CEO David Vainer told The Register he estimated the payment was in the $5 million to $30 million range. The FBI’s FLASH bulletin followed that incident and attributed a range of harassment tactics to ShinyHunters — allegations the crew disputes.
What this means for technologists, regulators, and FBI employees
- Technologists and security teams: The reported use of a PeopleSoft preauth zero-day to reach HR systems and then AWS GovCloud-hosted servers underscores risk to enterprise HR portals and cloud-hosted managed environments. The claim that the vulnerability remains unpatched raises urgency for organizations using Oracle PeopleSoft to verify patch status and compensating controls.
- Policymakers and regulators: A high-profile claim of stolen personnel PII tied to an agency hiring portal highlights questions about third‑party supply-chain and hosted-service risk, and the need for coordination with providers that support critical recruitment and HR infrastructure.
- FBI employees and applicants: The group’s claim of “thousands” of personnel files exposed — with samples said to include Social Security numbers, home addresses and emergency contacts — directly implicates current, former and prospective employees and their families and could require targeted mitigation steps depending on the bureau’s final forensic findings.
The FBI has acknowledged the claim and said it is investigating while the portal remains offline; ShinyHunters says the operation was a demonstration of technical capability and a business-preservation strategy. The tension between a criminal crew framing intrusion as reputation management and an agency treating the incident as an active compromise sets up a forensic and legal contest whose resolution — whether the breach was a third-party failure, an enterprise intrusion, or both — remains to be determined.
Source: The Register




