ShinyHunters demands FBI retract May characterization of group within one week
The Federal Bureau of Investigation is investigating an apparent breach of its employment portal, FBIjobs.gov, after a hacking group known as ShinyHunters claimed responsibility for accessing “very sensitive data” on nearly all FBI agents and individuals who have applied to work at the bureau.
In a statement Wednesday, the FBI said it was “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” The website, which serves as the main portal for prospective employees to learn about the FBI and initiate the application process, remained offline Wednesday morning. An FBI spokesperson declined to comment further, and an email sent to an address associated with the organization was not immediately returned.
A message that circulated online from ShinyHunters claimed the group had “compromised very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.” The message was directed to FBI Director Kash Patel and to the assistant director in charge of the bureau’s cyber division.
In its message, ShinyHunters said it would give the bureau one week to correct or remove what it characterized as false allegations in an FBI public service announcement from May. That announcement described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion.” The May PSA also characterized ShinyHunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims,” commonly harass or threaten victims, and “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”
ShinyHunters said in its message that it was “offended” by those characterizations and demanded that the FBI remove them. The group’s claims could not be independently verified.
Unverified breach claim
The Guardian, which first reported the story, noted that the hacking group’s claims could not immediately be verified. The FBI’s own May characterization of ShinyHunters explicitly stated that the group “may falsely claim to have sensitive or compromising information.” The bureau has not publicly confirmed or denied whether data was actually exfiltrated from the jobs portal.
Earlier FBI cyber incidents
In March 2026, the FBI disclosed that it was investigating “suspicious activities” on an internal system that contains sensitive information related to surveillance operations and investigations. Also that month, a pro-Iranian hacking group claimed to have hacked an account belonging to Patel and posted online what appeared to be years-old photographs of the director, along with a work resume and other personal documents dating back more than a decade. The Guardian reported that the FBI has been a common hacking target.
Investigation timeline
The FBI has not announced a timeline for its investigation or for restoring the FBIjobs.gov website. ShinyHunters has set a one-week deadline for the bureau to retract its May characterization. It remains unclear whether the FBI will respond to that demand, or when — or whether — the bureau will confirm or deny that any data was actually taken.