148917 stories
·
0 followers

Does the ShinyHunters' hacked information also include the informants?

1 Share

AI Mode reply for Does the ShinyHunters' hacked information also include the informants?

Reports on the recent cyberattack by ShinyHunters indicate that the hackers compromised an online jobs portal (FBIjobs.gov) rather than internal investigative or intelligence databases.

Stolen Data Scope

The stolen data primarily consists of personnel and applicant records, affecting thousands of current and former FBI employees, special agent candidates, and job applicants.

  • Employee Details: The leaked 5,000-line sample contains names, dates of birth, Social Security numbers, phone numbers, home addresses, emergency contacts, and spousal information.
  • Job Assignments: In some cases, the records include the specific field offices or specialized high-stakes units employees were assigned to (such as counterespionage or narcotics units).
  • Medical Information: The dataset apparently includes health reports detailing prior medical or mental health history filed during the job application or vetting process.

Because the entry point was a recruiting and human resources function rather than a criminal intelligence system, informant identities and operational case files remain unaffected.

  • ShinyHunters hackers say they breached FBI, stole data on ...

    [1/2] In a statement posted to its dark-web site and during an online chat with Reuters, ShinyHunters said it had targeted the FBI...

  • Hackers Say They Stole Thousands of Sensitive F.B.I. ...

    Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records Encuentra más de nuestra cobertura en los resultados de bús...

Read the whole story
Michael_Novakhov
37 minutes ago
reply
http://michael_novakhov.newsblur.com/
Share this story
Delete

ShinyHunters: What is known about them?

1 Share

AI Mode Conversation: ShinyHunters: What is known about them?

ShinyHunters: What is known about them?

AI Mode reply for ShinyHunters: What is known about them?

ShinyHunters that has been active since at least 2019–2020. Recognized by its frequent use of Pokémon-themed branding and avatars, the group specializes in large-scale data breaches, corporate extortion, and selling stolen information on the dark web.

Tactics and Methods

Instead of traditional brute-force hacking, ShinyHunters exploits modern cloud environments and human vulnerabilities through sophisticated methods:

  • Identity & Access Exploits: They target Software-as-a-Service (SaaS) layers, exploiting cloud misconfigurations, OAuth token theft, and malicious SaaS applications.
  • Social Engineering: They rely heavily on "vishing" (voice phishing), often leveraging AI-powered voice manipulation to bypass multi-factor authentication (MFA) or trick employees into granting access.
  • High-Pressure Extortion: When a target is compromised, the group demands multi-million dollar ransoms. If ignored, they use extreme pressure tactics, including harassing victims' families via texts and phone calls, and orchestrating "swatting" attacks.
  • Collaborations: They are heavily linked with the broader international cybercrime network known as The Com, often collaborating with or sharing tactics with other prominent hacking groups like Scattered Spider and Lapsus$.

Notable Targets & High-Profile Campaigns

ShinyHunters has breached more than 400 organizations across retail, technology, finance, luxury goods, and aviation.

  • Corporate & Luxury Giants (2025–2026): Their recent campaigns targeted platforms like Salesforce and compromised major brands including Google, Workday, Louis Vuitton, Gucci, Adidas, Qantas, Coinbase, and Telus Digital.
  • Public and Institutional Attacks (2026): In early 2026, they claimed a breach of the European Commission's cloud infrastructure and knocked out an online Learning Management System (LMS) used by educational institutions across the U.S.

September 2026 FBI Breach Claim

In a highly publicized escalation on September 22, 2026, ShinyHunters claimed to have breached the Federal Bureau of Investigation (FBI).

  • The Motive: The group stated the attack was not financially motivated, but rather an act of "retribution" to "set the record straight" after an FBI public service advisory detailed their methods and instructed organizations not to pay them.
  • The Data: They claimed to have stolen 2 to 3 terabytes of data via a zero-day exploit in Oracle PeopleSoft software, containing records on almost all current and former FBI agents and job applicants.
  • Verification: Cybersecurity researchers and journalists partially verified sample data leaked by the group (including social security numbers and job histories that matched real individuals), though the exact point of origin remains under official investigation by the FBI.

Copied to clipboardFailed to copy to clipboard. Try again later.

  • ShinyHunters - Wikipedia

    ShinyHunters is a black-hat criminal hacker and extortion group. ShinyHunters is believed to be affiliated with The Com, a large i...

  • Who Is ShinyHunters? | Tactics, Top Attacks & How to Protect ...

    Their 2025–2026 campaign targeted Salesforce, Google, Workday, Louis Vuitton, Gucci, Adidas, Jaguar Land Rover, Coinbase, and Qant...

  • FBI Internet Crime Complaint Center (IC3) (.gov)

    ShinyHunters: Cyber Criminal Group Attacks Learning ... - IC3

    cyber-attack that affected an online Learning Management System ( LMS ), resulting in an interruption of service to educational in...

Read the whole story
Michael_Novakhov
39 minutes ago
reply
http://michael_novakhov.newsblur.com/
Share this story
Delete

Does the ShinyHunters' hacked informtion also include the informsnts?

1 Share

You said: Does the ShinyHunters' hacked informtion also include the informsnts?

Does the ShinyHunters' hacked informtion also include the informsnts?

AI Mode reply for Does the ShinyHunters' hacked informtion also include the informsnts?

Based on the available evidence, the alleged , as the data breach was specifically limited to an online employment portal.

The extortion group targeted FBIjobs.gov, which means the compromised records contain personnel information rather than investigative or intelligence databases.

According to reports from The New York Times and Reuters, the data stolen impacts the following groups:

  • FBI Personnel: Current and former FBI agents and officials.
  • Job Applicants: Anyone who submitted an application through the online portal.

What information was compromised?
The hackers released a sample spreadsheet detailing roughly 5,000 agents to verify their claims. While it does not include informants, it does feature highly sensitive personal and structural details, including:

  • Names, home addresses, phone numbers, and Social Security numbers.
  • Emergency contact details and the names of spouses.
  • Granular job assignments, detailing which agents are assigned to specific field offices or units handling high-stakes counterespionage, Russian intelligence, Chinese spies, and drug cartels.
  • Certain internal employee medical and mental health reports.

The Federal Bureau of Investigation has acknowledged the unauthorized activity on its recruitment site and is currently investigating the full scope of the breach.

Copied to clipboardFailed to copy to clipboard. Try again later.

  • ShinyHunters hackers say they breached FBI, stole data on ...

    As proof, the group offered what it … what the group said was information on roughly 5,000 agents it said was a sample of the over...

  • Cybercriminal group claims to steal thousands of FBI ...

    The FBI said it is investigating a possible breach into its online jobs portal, after a prolific cybercrime group publicly claimed...

  • Hackers Say They Stole Thousands of Sensitive F.B.I. ...

    included names of current and former agents corresponding home addresses, phone numbers, names of spouses, certain medical informa...

You said: Does the ShinyHunters' hacked informtion also include the informants?

Does the ShinyHunters' hacked informtion also include the informants?

AI Mode reply for Does the ShinyHunters' hacked informtion also include the informants?

Based on current official statements and cybersecurity reports, the , as the data breach was strictly limited to a public-facing recruitment and employment portal.

The extortion group targeted the FBIjobs.gov website rather than the bureau's classified investigative networks. According to reports from The New York Times and USA Today, the compromised records only affect:

  • FBI Employees: Current and former agents, intelligence analysts, and support staff.
  • Job Applicants: Individuals who applied for employment through the online portal.

What information was actually stolen?

While confidential informants are not exposed, the stolen data is still highly sensitive. The sample data released by the hackers includes:

  • Personal Identifiers: Names, home addresses, phone numbers, and Social Security numbers.
  • Family Details: Names of spouses and emergency contacts.
  • Operational Roles: Specific field office assignments, including agents tasked with counterespionage, Russian intelligence, Chinese counterintelligence, and drug cartel investigations.
  • Background Check Records: Internal employee medical and mental health reports submitted during the hiring process.

The Federal Bureau of Investigation has confirmed it is investigating the unauthorized activity on the third-party recruitment platform but maintains that its core operational and intelligence systems remain secure.

Copied to clipboardFailed to copy to clipboard. Try again later.

Read the whole story
Michael_Novakhov
39 minutes ago
reply
http://michael_novakhov.newsblur.com/
Share this story
Delete

ShinyHunters declared a de facto war on the FBI: What will happen now? - Predictions

1 Share

. The hackers state that this is a direct, non-financially motivated retaliation against a May 2026 FBI Public Service Announcement that criticized the group's extortion methods. Giving the FBI a one-week ultimatum to retract the warning, the group claims to have stolen 2 to 3 terabytes of sensitive data containing personal details, spouse information, and field assignments for thousands of agents and job applicants.

Cybersecurity analysts, counterintelligence experts, and law enforcement histories suggest the following scenarios will likely unfold as this conflict escalates:

1. High-Stakes Leaks & Geopolitical Exploitation

If the FBI maintains its standard policy and refuses to comply with the hackers' demands, a massive data dump is highly anticipated.

  • The Counterintelligence Threat: Initial samples already verified by journalists contain granular details about agents assigned to sensitive counterespionage operations involving foreign governments. According to counterintelligence experts, this information is a "goldmine" for foreign intelligence services like China or Russia. It is highly probable that state-sponsored actors will aggressively harvest the data to identify, track, or compromise American operatives.
  • Doxxing and Swatting: Criminal networks are likely to weaponize the data to harass and intimidate individual investigators. In the past, similar leaks have resulted in targeted doxxing and "swatting" attempts against agents and their families.

2. A Massive, Coordinated Law Enforcement Takedown

Historically, directly targeting the United States' primary federal law enforcement agency results in an unprecedented consolidation of law enforcement pressure.

  • Resource Marshal: Cybersecurity officials note that antagonizing the bureau typically acts as a catalyst for swift international action. The FBI, working with global partners, is expected to deploy aggressive disruption strategies—targeting ShinyHunters' dark-web infrastructure, server hosts, and communication channels.
  • Global Manhunt: While many cybercriminals operate with relative impunity in countries without U.S. extradition treaties, affiliates located in cooperative nations will likely face expedited arrests and indictments.

3. Supply Chain Hardening & System Overhauls

The breach allegedly stemmed from a pre-authentication remote code execution (RCE) zero-day flaw within Oracle PeopleSoft, which was used to pivot to deeper cloud infrastructures.

  • Federal Review: Because PeopleSoft infrastructure is utilized heavily across other major government entities—including the U.S. Army's massive personnel networks—this event will likely trigger mandatory, emergency cyber audits across the entire federal apparatus.
  • Third-Party Accountability: The FBI's cyber division will likely tighten scrutiny on commercial third-party vendors and GovCloud ecosystems to establish rigid barriers between public-facing applications and deep internal personnel databases.

AI can make mistakes, so double-check responses

Copied to clipboardFailed to copy to clipboard. Try again later.

Read the whole story
Michael_Novakhov
40 minutes ago
reply
http://michael_novakhov.newsblur.com/
Share this story
Delete

ShinyHunters' threat to publish the hacked FBI documents in a week: how significant, and what might it imply?

1 Share

The cybercrime group ShinyHunters’ threat to publish hacked Federal Bureau of Investigation (FBI) records within a week carries . The group claims to have compromised the bureau’s online jobs portal (FBIjobs.gov), stealing a major tranche of highly sensitive data covering almost all current and former FBI employees, as well as job applicants.

This situation represents a major escalatory stunt by a notorious cyber-extortion syndicate.

How Significant is the Threat?

  • Verified Operational Breach: While the overall scale is still being investigated by the bureau, the breach itself is real. ShinyHunters temporarily defaced the FBI recruitment site, and independent verification of a data sample containing roughly 5,000 real employee records confirms they hold genuine, highly sensitive information.
  • High-Stakes Exposure: The stolen records go far beyond basic corporate data. They reportedly contain names, home addresses, phone numbers, Social Security numbers, job assignments, spouse details, and even medical information.
  • A "Forever" Threat: Cybersecurity experts note that when law enforcement personnel data leaks, it doesn't have an expiration date. Past historical leaks of similar data have been weaponized by malicious actors for over a decade to dox, harass, and threaten investigators.

What Might It Imply?

1. Severe Counterintelligence and Operational Risks

Exposing the home addresses, personal phone numbers, and family details of agents undermines their safety and the integrity of ongoing investigations. Foreign intelligence agencies, organized crime syndicates, and domestic extremists could use this directory to target agents for blackmail, social engineering, or physical intimidation.

2. Retaliation Over "Brand" Reputation

Unlike typical ransomware or extortion threats aimed purely at financial payout, ShinyHunters is explicitly demanding that the FBI retract or remove a Public Service Announcement (PSA) issued in May 2026. The FBI's advisory accused the group of engaging in low-level sextortion schemes and bluffing about data access. ShinyHunters claims it breached the portal to defend its criminal "brand," seeking to force the top law enforcement agency to admit it circulated disinformation.

3. Exploitation of the Supply Chain

The FBI noted that the exact "point of breach is still undetermined," highlighting that the hackers may have targeted a third-party contractor or shared enterprise service responsible for managing FBIjobs.gov rather than breaking directly into the FBI's highly secured operational core networks. This emphasizes a persistent vulnerability: government cybersecurity is only as strong as its weakest vendor link.

4. The Likelihood of Leaks

Because the FBI is structurally incapable of capitulating to cybercriminals by retracting legitimate public safety alerts, the ultimatum is effectively a dead end. Given ShinyHunters' long track record of dumping data when demands are ignored—seen recently in data dumps involving institutions like Harvard University—there is a very high probability that a massive dataset of FBI personnel records will be leaked or sold on the dark web once the one-week deadline expires.

Copied to clipboardFailed to copy to clipboard. Try again later.

Read the whole story
Michael_Novakhov
40 minutes ago
reply
http://michael_novakhov.newsblur.com/
Share this story
Delete

FBI investigates breach of jobs website as hackers claim ‘very sensitive data’ stolen

1 Share

The FBI is investigating an apparent breach of its jobs website as a criminal hacking group claimed to have accessed “very sensitive data” on nearly all agents and job applicants.

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau said in a statement. The website, the main portal for prospective employees to learn about the FBI and initiate the application process, remained offline Wednesday morning.

A message that circulated online from a hacking group known as ShinyHunters claimed responsibility for the hack.

The message, directed to FBI director Kash Patel as well as the assistant director in charge of the FBI’s cyber division, said the hacking group had “compromised very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job”.

The claims could not immediately be verified, and an FBI spokesperson declined to comment further. An email to an address associated with the organization was not immediately returned.

In its message, ShinyHunters said it would give the bureau one week to correct or remove what it says are false allegations in an FBI public service announcement from May that described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion”.

That announcement characterized ShinyHunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims”, commonly harass or threaten victims and “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist”.

ShinyHunters said in its message to the FBI that it was “offended” by those characterizations and demanded that the FBI remove those claims.

The FBI has been a common hacking target.

In March, the agency disclosed that it was investigating “suspicious activities” on an internal system that contains sensitive information related to surveillance operations and investigations. Also that month, a pro-Iranian hacking group claimed to have hacked an account of Patel’s and posted online what appear to be years-old photographs of him, along with a work résumé and other personal documents dating back more than a decade.

Read the whole story
Michael_Novakhov
3 hours ago
reply
http://michael_novakhov.newsblur.com/
Share this story
Delete
Next Page of Stories