ShinyHunters claims to have stolen data on most FBI employees
Quick Look
- ShinyHunters claims to have stolen data on nearly all current and former FBI employees, including names, addresses, and Social Security numbers, in retaliation for an FBI advisory.
- The group provided a screenshot and data sample, which Reuters partially verified, finding matches in at least 10 cases including FBI Director Kash Patel.
- The FBI acknowledged the claims and is investigating, while experts warn such breaches could be used to harass agents.
AI-generated summary
Why It Matters
ShinyHunters is a notorious hacking group known for attacks on Rockstar Games, Canvas, and attempts against Anthropic. The FBI had previously issued an advisory in May 2026 detailing the group's methods and advising targets not to pay ransom.
The digital extortion group known as ShinyHunters says it has stolen data about the majority of the FBI's current and former employees during a cyber attack.
In a statement posted to its dark-web site and during an online chat with Reuters, ShinyHunters said it had targeted the FBI in response to a May 2026 agency announcement that detailed the hacking group's methods and advised its targets not to pay it.
ShinyHunters wrote that it had stolen data "on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job".
As proof, the group offered what it said was a screenshot of a vandalised FBI job site and what it described as a small sample of its stolen data.
The FBI released a statement saying the agency was "aware of claims regarding unauthorised activity affecting FBIjobs.gov and is currently investigating".
Job site disrupted
Reuters could not verify the authenticity of the screenshot, but the job site did appear to have experienced recent disruption.
A message posted to the site on Tuesday, local time, said both it and the FBI Special Agent Applicant Portal were "currently unavailable".
The data sample appeared to contain information about FBI agents' names, home addresses, social security numbers, their assignments and, in some cases, the names of their family members.
Reuters was able to partially verify the authenticity of the information by running the details, including the social security numbers, against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs.
In at least 10 instances, including in the case of FBI director Kash Patel, Reuters found details that appeared to match.
A person familiar with the matter said the job descriptions in the data also matched in at least some cases.
However, the news agency could not establish where the data came from, or whether it had been stolen from the FBI's internal systems as the hackers said.
Attempts to reach the people whose details were in the sample data were unsuccessful.
Such breaches 'incredibly harmful'
Cynthia Kaiser, a former FBI official, said breaches like the ones claimed by ShinyHunters were "incredibly harmful" because they could be used by criminals to expose and put pressure on the people investigating them.
Ms Kaiser, who is now senior vice-president at cybersecurity firm Halcyon, noted that an old leak dating back to 2016 was still occasionally used today to harass FBI agents.
ShinyHunters is one of the world's most notorious hacking groups.
Its recent break-ins include the purported theft of millions of business records from video game developer Rockstar Games, the maker of Grand Theft Auto, and a May intrusion centred on education tool Canvas, which caused widespread disruption across schools and universities.
Earlier this month, AI company Anthropic said it caught ShinyHunters-linked hackers trying to use its tools.
On Sunday, the group told Reuters it had gone to war against another notorious cybercrime group, cl0p, in a rare bout of public score-settling.
What to Watch
AI outlook — possibilities, not facts
The FBI will complete its investigation and issue public findings on the breach
Likely · Within weeks
Affected FBI employees will be offered identity theft protection services
Possible · Within months
Open Questions
- Whether the stolen data was actually taken from FBI internal systems
- The full scope and authenticity of the data claimed by ShinyHunters
- Whether any misuse of the data has occurred so far
- The identity and location of the ShinyHunters group members