News Made Clear · Loading…
A website used by ShinyHunters went offline after its deadline for the FBI to change a disputed advisory expired. The cause is unknown.
What has changed? · 01/10/2026, 03:17 UTC
Review information is loading.
The FBI is investigating claims that hackers stole sensitive personnel records, as ShinyHunters threatens to publish the data and current and former staff voice fears about the safety of agents and their families. [1] [2]
The bureau said on 23 September that it was investigating a claimed compromise of its fbijobs.gov recruitment portal and alleged exposure of employees’ personal information. It said the breach point remained undetermined — including whether it involved a third-party provider or the FBI’s own systems — and that it was working with providers to reduce risks. [2]
ShinyHunters has threatened to publish databases and documents within four days unless its demands are met, BBC News reported on 25 September. Rather than demanding money, the group wants the FBI to retract a warning published in May about its tactics. [1]
Nextgov/FCW reported receiving an apparent sample of the stolen data containing roughly 5,000 entries, listing employees’ names, home addresses, telephone numbers and information about spouses and siblings. The total number of people affected remains unclear. [4]
BBC News said it had seen samples of fitness-for-work medical examinations containing blood and urine test results. [1]
A former FBI cyber investigator told the BBC that current agents in a group chat feared criminals could use their details for convincing phishing attempts, scams or demands for bribes. Michael McPherson, a former agent now serving as senior vice president of security operations at cybersecurity firm ReliaQuest, warned of “a security threat which cuts to the core of agent safety, particularly their families”. [1]
Some information may already be circulating beyond the attackers’ control. Cynthia Kaiser, a former senior FBI cyber official who now leads Halcyon’s Research Centre, told the BBC that ShinyHunters appeared to have lost control of some data being shared in online groups of cyber researchers.
Before the deadline, ShinyHunters told Hackread it would not publish or sell the FBI data it claims to hold, and said nothing would happen when the deadline passed. [11]
13 listed sources · explore evidence, limitations and provenance.
Sign in to give this article a thumbs up or down.
Private test discussion. Comments are readers’ views and are not yet automatically fact-checked. Editing is available for 60 seconds after posting.
Sign in with a confirmed reader account and choose a username to read comments and participate.
Sorting applies to top-level comments; replies remain oldest first. New comments and likes can change the order. Refresh for the current ranking.
Loading comments…
The FBI’s 15 May advisory concerned an attack on a learning-management system. It warned that criminals use real or exaggerated claims of access to sensitive information to pressure victims into paying, described harassment by ShinyHunters actors and advised people not to pay or respond to demands. [3]
A ShinyHunters spokesperson told The Register that the claimed FBI attack was intended to contest the advisory’s allegations, describing it as a public-relations and marketing initiative for the group’s business. [5]
Bloomberg reported that the FBI emailed all personnel on 23 September, urging protective steps while the investigation continued. A former cyber investigator told the BBC that staff had been advised to sign up for DeleteMe, a service that helps remove personal information from data-broker websites. [6] [1]
A website used by ShinyHunters went offline on Wednesday, 30 September, Reuters reported. The outage came a day after the group’s deadline for the FBI to correct or remove a May advisory about its activities expired. The advisory remained online. [8]
The cause of the outage is unknown. The FBI declined to say whether it had taken action to bring down the website, and ShinyHunters could not be reached for comment. [8]