The FBI hack by cybercriminal group ShinyHunters, encompassing the personal data of nearly 'all' FBI employees, has been countered by arrests of suspects.

On September 23rd, 2026 the Federal Bureau of Investigation shared that it was “aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII).” The announcement, made on X (formerly Twitter), the FBI explained that they were still investigating the means of the breach working to address and resolve risk. Following this public announcement, the FBI reportedly issued a memorandum to employees declaring the alleged compromise a “cyber security incident” that exposed sensitive information like names, addresses, job titles, and even social security numbers. Private medical information, like lab work results and psychiatric evaluations was also part of the breach.
The hack was first reported by 404 Media, who spoke with a representative of the cyber criminal gang - ShinyHunters - that openly claimed responsibility for the intrusion, saying “We hacked the FBI. We hold data on all FBI employees and applicants”. 404 Media shared that other critical information - phone numbers and information on employee spouses - was accessed by the hackers, who supported their claims by showing 404 Media a sample of 5,000 alleged agents. ShinyHunters also told TechCrunch they were “very confident we have data on mostly all of FBI,” along with “a substantial amount of applicants data”.
ShinyHunters’ history in the cybercriminal space lends credence to these claims. White Blue Ocean, a digital security company, described ShinyHunters as “one of the most recognised threat actors among the hacking community”, for their years of stealing and then selling data code, and records from several companies, starting in mid-2020. Within the first month of activity, the organization was selling hundreds of millions of user records from Tokopedia, Unacademy, Zoosk, HomeChef, Mindful, Chatbooks, and Minted. Other apps targeted by the group have been Wattpad, BigBasket, and PlutoTv. In 2026, ShinyHunters made news for their hack of Grand Theft Auto producer, Rockstar Games. They took over headlines again in __ for their monumental ransomware hack on Instructure, the parent company of the widely-used Canvas educational tool. The intrusion used an exploit in Oracle PeopleSoft hit over 8,000 schools, reaching the data of 30 million active accounts. With this context, the FBI hack sounds more plausible - but leads to questions about the cybersecurity of one of the US’ most recognizable agencies.
News of the hack put scrutiny on the FBI, with the New York TImes calling the incident “embarrassing” in their headline covering the issue. There, the NYT recounted other security incidents that have recently rocked the agency, starting with the Salt Typhoon Hack of late 2024, that was called the “worst telecom hack in our nation’s history” after a Chinese-state sponsored hacking group infiltrated eight telecommunications firms in the US - gathering the cellular metadata of nearly every American and listening into calls with top officials in the US. The hackers also used wiretap networks used by the FBI monitoring suspected criminals. Earlier this year, the department’s director, Kash Patel, also had his old personal email hacked by Iranian-linked hackers in a war that is increasingly cyber-enabled.
In their conversation with 404 Media, the group was transparent about their motivations for the attack, saying that FBI wasn’t targeted for financial gain - the reason for all their other hacks - but rather to pressure the agency into retracting allegations about harassment and swatting. ShinyHunters reportedly demanded an answer by the following Tuesday, with the group seemingly recognizing that the FBI wouldn’t meet the request in a Monday statement, explaining that they “had made our decision that we would never publish this data”, since the hack was really “a marketing campaign to protect our business”. The group also shared that they “seek no escalation as our goals have widely been accomplished”. Even with this deescalation, the FBI responded to the hack by “working around the clock to investigate the cyber incident”.
In the last couple of days, this work appears to have paid off. Eight days after the 404 Media story, and one day after the deadline ShinyHunters imposed expired, their website was taken down. Dutch police, who arrested an alleged member of the group about a week before the hack in connection to other crimes, alerted the FBI after seizing the suspect’s laptop. The arrest emboldened FBI leaders, like assistant director of FBI Cyber Brett Leatherman, to ask others to turn themselves in: “Other groups believed anonymity or their friends would protect them… but arrests have a way of changing who is willing to talk. The longer you stay in this, the more we learn about you, you know how to find us, we know how to find you.”
Leatherman’s warning continues to feel relevant. On October 3rd, 2026, Reuters shared that the FBI had detained Saif al-Din Khader in Jordan, a suspected member of ShinyHunters and was working with him to contain the damage wrought by the hack. Khader has been associated with cybercrime before, with Brian Krebs identifying him as a part of Lapsus$ Hunters, a larger umbrella group that includes ShinyHunters. The FBI framed the detainment as a sign of things to come, as it “continues to aggressively investigate the recent cyber incident allegedly involving ShinyHunters, having already worked with partners to arrest multiple subjects - and we will spare no resource in bringing each of the responsible individuals to justice.” This week, the FBI also attributed the breach to a “security failure of a platform managed by a third-party organization — after a contractor failed to implement a security patch explicitly issued to secure the platform”. The platform responsible, Accenture, has now been dropped as a contractor as the FBI continues their investigation.
Even outside of ShinyHunters, the FBI has been able to score a win in their fight against cybercrime. On August 18th, 2026, the FBI and Department of Justice issued indictments on 17 hackers linked to the Mabna Institute (an Iranian based organization created to help Iranian academics unlawfully access non-Iranian resources while also working at the behest of the government and private companies as hackers). Now, one of the suspects - Amir Barati - has been extradited to the US. The move, along with the bureau’s progress in the ShinyHunters investigation suggests that the agency is well on its way to improving national cybersecurity, despite the ongoing challenges levied by threat actors.