The ShinyHunters hacking group claims to have stolen employee and applicant data from FBI-related services using an Oracle PeopleSoft zero-day, defacing the FBI jobs site in the process. A sample of 5,000 alleged agents revealed the stolen data includes members of the FBI's secretive Remote Operations Unit (its hacking team), exposing their identities, addresses, phone numbers, and spousal information—presenting a grave counterintelligence risk. Further reporting indicates that the hackers have also claimed to have stolen files containing the home addresses and job titles of agents involved in counterintelligence, drug cartel investigations, and covert surveillance. The FBI has officially confirmed it is investigating the claims. The group is demanding a retraction of a May 2026 FBI advisory that described their extortion methods, and has claimed to have exfiltrated 2-3 TB of data including from HR and CJIS systems. Dutch police have arrested 24-year-old Pepijn van der Stap, a previously convicted cybercriminal who had publicly rebranded himself as a 'reformed hacker' while working at the Amsterdam-based cybersecurity firm Hadrian and volunteering with the Dutch Institute for Vulnerability Disclosure. KrebsOnSecurity reports that in the days following the arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing additional sensitive FBI data and even attempting to extort the Russian ransomware group Cl0p. If authentic, the breach represents a serious counterintelligence risk, as agents and their families could be extorted or targeted by foreign intelligence services.
Last Updated: