ShinyHunters Targets the FBI
The Group Says an FBI Warning Prompted the Hack
ShinyHunters has established a reputation as one of the more technically capable and prolific hacking and data-extortion groups operating today, with a record of large-scale breaches and an evident willingness to take on increasingly high-profile targets. It says its latest target, the Federal Bureau of Investigation, was chosen deliberately.
The group says the attack was retaliation for a Public Service Announcement issued by the FBI in May that described ShinyHunters’ methods, questioned claims sometimes used in data-extortion campaigns and instructed people approached for money not to pay. For ShinyHunters, whose leverage depends in large part on targets believing that it possesses what it says it possesses, the dispute concerned something commercially important: credibility.
Only days earlier, ShinyHunters had compromised and defaced infrastructure belonging to rival hacking group Cl0p, turning the methods of cyber extortion against another major hacking operation. TheZeal has covered that dispute separately in Hackers Hacking Hackers.
This time, ShinyHunters’ target was the FBI. The group claims it breached FBI-related systems on Monday, September 21, using a previously unknown vulnerability in Oracle PeopleSoft, and subsequently obtained sensitive information concerning current and former FBI personnel as well as people who had applied to work for the bureau.
The FBI has confirmed considerably less.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau told BleepingComputer.
That wording is important because FBIJobs.gov is not, by itself, the FBI’s investigative network. According to the bureau’s own documentation, FBIJobs.gov is its public-facing careers website, where anyone can browse job descriptions, qualifications, locations, benefits and information about the hiring process.
A connected but separate site, apply.fbijobs.gov, is the FBI’s Oracle-based application portal. Applicants can create profiles there, search openings, submit applications and supporting documents, and track applications. The FBI also operates a separate Special Agent Applicant Portal.
Those distinctions make the scope of the incident especially important. Compromising an employment application system containing personnel and applicant records could expose extremely sensitive information without necessarily providing access to the FBI’s criminal investigative, intelligence or operational networks.
ShinyHunters claims the breach went considerably further.
The group told BleepingComputer that the initial entry point was a new and still-unpatched Oracle PeopleSoft vulnerability capable of remote code execution. It said it exploited the flaw against the FBI before moving laterally into FBI-managed infrastructure, including an AWS GovCloud environment.
“The Oracle product we exploited the 0day in is PeopleSoft. We found another one yesterday and immediately exploited it on the FBI,” ShinyHunters told BleepingComputer.
The group claims it subsequently reached services associated with FBI Criminal Justice, human resources and Medlink, as well as other systems. It also claims to have taken between two and three terabytes of information, including records concerning current and former FBI employees and people who had applied for jobs with the bureau.
Those claims have not been independently established.
BleepingComputer said it has not verified the existence of the alleged new PeopleSoft vulnerability, ShinyHunters’ claimed movement into other FBI systems, or the amount of data the group says it obtained. The FBI has not publicly confirmed that its wider internal systems were penetrated or that two to three terabytes of information were taken.
There is, however, evidence that at least some of the group’s claims cannot be dismissed outright.
ShinyHunters provided journalists with what it described as a sample containing information relating to roughly 5,000 FBI personnel. Reuters reported that the material appeared to contain names, home addresses, Social Security numbers, assignments and, in some cases, information concerning family members.
The group told Reuters that it possessed data “on almost ALL FBI Agents” as well as people who had applied for FBI employment.
Reuters tested portions of the sample against credit records and previously compromised data maintained by dark-web intelligence firm District 4 Labs. In at least ten cases, including that of FBI Director Kash Patel, details in the sample appeared to correspond with existing records. A person familiar with the matter also told Reuters that some of the employment descriptions appeared accurate.
What Reuters could not establish was where the information had come from.
That distinction is crucial. Evidence that ShinyHunters possesses authentic information relating to FBI personnel does not establish that the information was taken from FBI systems during this particular intrusion. Nor does it prove the group’s broader claim that it penetrated multiple internal FBI services or removed several terabytes of data.
The FBI’s employment infrastructure also appears to have been directly affected.
ShinyHunters supplied BleepingComputer with a screenshot purporting to show apply.fbijobs.gov carrying the group’s Umbreon emblem and the declaration: “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”
The message continued, “rooting your systems since ’19 ;)”, and claimed that personally identifiable and health-related information concerning FBI employees and applicants had been compromised.
CyberScoop reported that the FBI jobs site had been temporarily defaced, while Reuters said it could not independently authenticate the screenshot.
There was independently observable disruption. By September 22, FBIJobs.gov was advising visitors that apply.fbijobs.gov and the FBI’s Special Agent Applicant Portal were unavailable.
By September 23, the public FBIJobs.gov website was accessible again, although the status of the affected application portals remained unclear.
ShinyHunters told BleepingComputer that the FBI detected the intrusion quickly and disconnected affected systems. The group claimed that its access to several FBI networks disappeared at roughly the same time.
“They literally pulled the plug on everything,” a ShinyHunters representative said.
That account remains the group’s version of events. The FBI has not publicly confirmed that multiple internal networks were disconnected.
A defaced application portal does not demonstrate access to the FBI’s investigative or intelligence systems. It does, however, provide a visible component to an incident serious enough for the bureau to acknowledge publicly that it is investigating unauthorized activity affecting FBIJobs.gov.
The motive behind the attack is less obscure.
On May 15, the FBI’s Internet Crime Complaint Center published a Public Service Announcement concerning a cyberattack on an online learning management system that ShinyHunters claimed responsibility for. The FBI described ShinyHunters as specialising in large-scale data breaches and extortion and said threat actors may use genuine or exaggerated claims of access to sensitive or personal information to prompt victims to pay.
The announcement also said ShinyHunters actors commonly use harassment strategies, including threatening messages and calls to victims and family members, and said swatting had occurred in some cases. It warned that threat actors may falsely claim to possess sensitive or compromising material that does not exist.
Its advice to anyone contacted by those claiming to hold their personal information was direct: “Do not send payment or respond to their demands.”
ShinyHunters strongly disputes parts of that description.
Following the FBI incident, the group published a lengthy statement challenging the bureau’s account. It denied some of the conduct attributed to it, rejected the suggestion that it belongs to the loose cybercrime community commonly called “The Com,” and accused the FBI of publishing false information about its operation.
The group portrayed the FBI announcement as an attempt to interfere with its operation by weakening the confidence of the organisations and individuals it targets. ShinyHunters demanded that the FBI correct or remove the May document and gave the bureau one week to act.
It has said that demand is not financial and has not publicly demanded a ransom from the FBI. When BleepingComputer asked whether the allegedly obtained data would be released if the FBI refused to make changes, the group replied: “No comment.”
The dispute goes to the centre of how a data-extortion operation works. The value of stolen information depends partly on whether the intended target believes the attacker possesses genuine material and is prepared to release it. If organisations begin to suspect that ShinyHunters exaggerates its access or threatens to publish information it does not possess, its bargaining position weakens.
An FBI announcement cautioning victims about exaggerated claims and telling them not to pay therefore has the potential to damage that leverage. Cybersecurity intelligence firm Flashpoint said the FBI attack could strengthen ShinyHunters’ reputation as a credible threat, particularly because the group itself portrayed the FBI announcement as an attempt to undermine confidence in its claims.
Seen in that context, attacking the FBI may have served another purpose beyond obtaining information. If successful, compromising the very agency publicly questioning the group’s credibility would provide ShinyHunters with a conspicuous demonstration of its technical ability.
It would also carry considerable risk.
Most financially motivated hacking groups have obvious reasons to avoid unnecessarily antagonising the FBI. The bureau investigates computer intrusions, works with international law-enforcement agencies and has participated in operations that have identified suspects, seized infrastructure and dismantled major cyber operations.
Former FBI cyber official Cynthia Kaiser, now with cybersecurity company Halcyon, told CyberScoop that extortion groups often succeed because they operate with the discipline of businesses. She warned that turning their attention towards rival hacking groups or law enforcement for public humiliation can be the sort of behaviour that precedes takedowns, takeovers or defections.
ShinyHunters appears willing to take that risk.
When BleepingComputer asked whether attacking the FBI might bring greater pressure from the United States government to identify and apprehend those responsible, the ShinyHunters representative answered simply: “I don’t care.”
The remark is consistent with the group’s recent conduct. Days before the FBI incident, ShinyHunters compromised Cl0p’s leak site, displayed its own seizure notice and began attempting to extort the rival group. In both cases, the target was not merely a source of data. Reputation and public humiliation appear to have been important parts of the confrontation.
The broadest elements of ShinyHunters’ account nevertheless remain unverified. There is no independent confirmation that it obtained two or three terabytes from the FBI, reached all of the internal services it has named, or entered through the new PeopleSoft vulnerability it says it discovered.
What can be said with greater confidence is narrower. Unauthorized activity affected the FBI’s recruitment infrastructure, its application systems were disrupted, ShinyHunters appears to possess at least some authentic information concerning FBI personnel, and the bureau is investigating. Whether the incident ultimately proves to have been confined largely to recruitment and personnel systems or something substantially deeper remains unanswered.
ShinyHunters has made clear why it says it targeted the FBI. The bureau publicly challenged the group’s methods and told those it targets not to pay. ShinyHunters responded by claiming it had penetrated FBI systems themselves.
Whether the full extent of that claim is eventually proved remains to be seen. The decision to make the claim, and to invite the additional attention that comes with it, has already raised the stakes considerably.
