ShinyHunters Claims Breaches of FBI and Clop Ransomware Leak Site
The hacking group ShinyHunters says it infiltrated both the FBI and the Clop ransomware gang, raising urgent questions about security at the world's top law enforcement agency and among cybercriminals.
By Ethan Cole · First published 23 Sept 2026
In brief
- ShinyHunters claims to have breached the FBI's jobs portal and stolen 2 to 3TB of sensitive employee and applicant data.
- The group alleges the stolen information includes personal details and job assignments of thousands of current and former FBI personnel.
- The FBI has acknowledged awareness of the breach claims and stated it is actively investigating the incident.
- Some of the compromised data reportedly details roles in intelligence and counterespionage operations, including work against foreign spies.
- ShinyHunters is not seeking ransom but continues to demand a retraction of FBI statements about the group.
Timeline · 9 moments
ShinyHunters breaches Clop ransomware gang's leak site
BleepingComputer ↗Unauthenticated file upload led to theft of Clop's private keys
DEV Community ↗Clop's leak site defaced and extortion demand issued by ShinyHunters
The Register ↗ShinyHunters claims breach of FBI, theft of employee data
The Register ↗Hackers say they used PeopleSoft zero-day to access FBI systems
BleepingComputer ↗ShinyHunters posts evidence of FBI data theft, demands retraction
SecurityWeek ↗FBI launches investigation into ShinyHunters breach claims
nu.nl ↗Hackers say motive is FBI retraction, not ransom
TechRadar ↗Leaked data reportedly includes intelligence assignment details
CBC News ↗Update 23 Sept 2026, 9:31 pm UTC
Multiple outlets report that the FBI has confirmed it is investigating claims by ShinyHunters of a breach affecting thousands of current and former employees. The stolen data reportedly includes assignment details tied to sensitive intelligence roles and operations, but the FBI has not confirmed the authenticity or full scope of the breach.
Update 23 Sept 2026, 3:24 pm UTC
Multiple outlets report the FBI is now officially investigating claims that ShinyHunters breached its jobs site and stole up to 2TB of data on employees and applicants. The group says its motive is not financial but to force the FBI to retract a prior warning about them. The stolen data allegedly includes personal details and home addresses of agents.
How it started
ShinyHunters, a well-known hacking group, began by targeting the Clop ransomware gang. Using an unauthenticated file upload vulnerability in the Grav CMS running Clop's Tor leak site, they gained access to sensitive files. This allowed them to steal internal data and the private keys used for the site's onion service.
The breach was quickly made public when ShinyHunters defaced Clop's site, taunting the rival gang and posting their own logo. This unusual move, where one criminal group attacked another, drew immediate attention from cybersecurity watchers.
How it unfolded
On September 19, 2026, reports emerged that ShinyHunters had successfully compromised the Clop ransomware gang's leak site. The group exploited a file upload flaw, stole source code and private onion service keys, and publicly mocked Clop by defacing their site.
Shortly after, ShinyHunters escalated its campaign by announcing it had breached the FBI. On September 22, the group claimed to have stolen over 2 TB of data, including details about FBI employees and job applicants. They stated the breach was not financially motivated but a response to how the FBI described them in official reports.
ShinyHunters said it used a previously unknown zero-day vulnerability in Oracle PeopleSoft to access internal FBI systems. The hackers posted evidence of the breach on their dark web site and threatened to release more data if their demands were not met.
The FBI acknowledged awareness of the claims and began an investigation into the reported breach. Meanwhile, Clop was left dealing with the aftermath of the attack on its own infrastructure.
Where it stands
Currently, both the FBI and Clop are investigating the extent of the breaches. The FBI has not confirmed the full scope of the data loss or its authenticity, but security experts warn that any compromise of agent data could have serious national security implications.
ShinyHunters continues to demand that the FBI retract statements made about the group in previous threat reports. The situation remains fluid, with the potential for more data leaks if negotiations or investigations stall.
What to watch
Key questions remain about whether the stolen FBI data is genuine and how much information could be exposed if released. The FBI's investigation may determine if agents or applicants are at risk, and whether the zero-day vulnerability has been patched. Observers are also watching for possible retaliation or further escalation among hacking groups.


