ShinyHunters Claims FBI Systems Compromised in Retaliation Attack
The FBI is investigating a cyberattack on its systems after the notorious ransomware group ShinyHunters claimed responsibility for breaching FBIjobs.gov, the agency’s official job application portal. According to the group’s statement on its data-leak site, the intrusion allowed them to temporarily deface the site and access what they describe as "very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job."
The breach was first reported by 404 Media on Monday and prompted an immediate response from the FBI. An agency spokesperson confirmed awareness of the unauthorized activity affecting FBIjobs.gov and stated that an investigation is underway. Visitors to the FBI jobs site now see an alert indicating that both apply.fbijobs.gov and the Special Agent Application Portal are currently unavailable.
Motivation: Response to FBI Public Service Announcement
ShinyHunters says the attack was carried out in retaliation for a public service announcement (PSA) issued by the FBI following the group’s May ransomware attack on Instructure, the education technology company behind the Canvas learning platform used by K-12 schools and universities nationwide.
In their own counter-PSA posted on their leak site, ShinyHunters denied affiliations with cybercrime collective The Com, refuted claims of conducting swatting operations, and rejected allegations that they possess or threaten to release embarrassing personal media for extortion purposes. The message was directly addressed to Brett Leatherman, assistant director of the FBI’s cyber division, and FBI Director Kash Patel.
Experts Warn of Reputational Risk and Escalation
Cybersecurity analysts from Flashpoint told CyberScoop that while ShinyHunters has historically exaggerated the sensitivity of data they claim to steal, the group has demonstrated real capabilities and should be treated as a legitimate threat. "This attack benefits ShinyHunters by bolstering their reputation as a credible threat," the analysts noted, pointing out that the group framed the FBI’s PSA as an attempt to disrupt their operations and undermine client trust.
The group’s typical tactics include social engineering, exploiting identity system weaknesses, and leveraging cloud environment vulnerabilities to steal sensitive or proprietary data, which they then use to extort payments. In this case, however, ShinyHunters did not demand a ransom. Instead, they issued a one-week deadline for the FBI to amend or remove the May PSA, signaling a coercive motive rather than financial gain.
Law Enforcement Veteran Calls Move Undisciplined
Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center and a former deputy assistant director in the FBI’s cyber division, warned that targeting law enforcement — especially with the intent to shame — often backfires. "Ransomware groups are largely successful because they operate like businesses," she said. "When they deviate into actions meant to publicly embarrass or provoke authorities, they historically invite takedowns, internal takeovers, or mass defections."
As of the FBI’s latest statement, no evidence has been publicly released confirming the extent of the data accessed, and ShinyHunters has not followed through on threats to leak the alleged agent information. Nevertheless, the incident marks a significant escalation in the group’s pattern of targeting high-profile institutions, adding federal law enforcement to a list of prior victims that includes Salesforce, Snowflake, McKesson, and various healthcare and education providers.
Source: CyberScoop