Tech News
← Home  ·  All topics

Shinyhunters

21 GoKawiil briefs on this topic

FBI investigates ShinyHunters' claim of stealing employee data via jobs site bug

Hacker group ShinyHunters claims to have exploited an unknown vulnerability on FBIJobs.gov, taking the site offline and posting a banner declaring it 'seized.' The group told The New York Times it stole two to three terabytes of data including names, addresses, phone numbers, spouse names and medical information of current and former FBI employees and applicants, though none has been leaked yet.

ShinyHunters claims theft of 2-3TB of FBI employee data via Oracle zero-day

Hacking group ShinyHunters says it stole terabytes of sensitive data on FBI employees and job applicants, exploiting a zero-day flaw in Oracle's PeopleSoft software to breach Amazon Web Services' GovCloud. A sample reviewed by Reuters and 404 Media reportedly includes names, addresses, birthdates and Social Security numbers for about 5,000 employees, and the group also claimed responsibility for briefly hijacking the FBI's website. The FBI confirmed it is investigating a claimed compromise of the FBIJobs.gov portal and possible exposure of employee personal information.

Hackers deface FBI jobs website, claim access to agents' home addresses

A hacking group calling itself ShinyHunters defaced the FBI's jobs recruitment website and claims to possess home addresses of FBI agents. The group has demanded that the bureau retract a warning it issued in May about ShinyHunters, giving the FBI a one-week deadline.

ShinyHunters claims theft of FBI agent and applicant data

Hacking group ShinyHunters says it breached FBI systems and stole personal data on thousands of agents and job applicants, including names, home addresses and phone numbers. 404 Media reported the group first breached an Oracle PeopleSoft HR server before pivoting into an Amazon-hosted government cloud, and the FBI's job application portals appeared defaced and offline. ShinyHunters says the hack is not financially motivated and is demanding the FBI remove a report containing what it calls false allegations about the group.

ShinyHunters claims theft of FBI employee data, defaces bureau jobs site

Hacking group ShinyHunters told 404 Media it breached FBI-related systems and obtained personal data on all FBI employees and applicants, including names, home addresses, phone numbers, birthdates and spouse details. The group provided a sample of roughly 5,000 records, and 404 Media verified some phone numbers matched named individuals and linked others to Justice Department personnel. ShinyHunters also defaced the FBI's jobs website on Tuesday.

ShinyHunters claims new PeopleSoft zero-day used to breach FBI systems

The ShinyHunters extortion group told BleepingComputer it exploited a new remote-code-execution flaw in Oracle PeopleSoft to access FBI systems and move into FBI-managed AWS GovCloud infrastructure, claiming theft of 2-3TB of data including employee, applicant, HR and Medlink records. The group shared a screenshot showing the FBI Jobs site defaced with its logo and a message asserting sensitive PII/PHI had been stolen, and said the FBI quickly took the affected systems offline.

ShinyHunters breach Clop's dark web leak site, demand extortion payment

ShinyHunters, a data-theft and extortion group, defaced rival ransomware gang Clop's dark web leak portal over the weekend, claiming to have exploited an unpatched file-upload flaw in the site's Grav CMS. The attackers say they stole Clop's source code, plugins, system logs and private encryption keys, and are now demanding an unspecified eight-figure Bitcoin payment from Clop while threatening to expose details of victims who paid ransoms.

ShinyHunters breaches Clop ransomware's leak site, defaces it and claims stolen data

The extortion group ShinyHunters says it exploited an unauthenticated file upload flaw in Grav CMS to compromise the Tor-based data leak site run by the Clop ransomware operation. The attackers uploaded a taunting message, later fully defaced the site with Pokémon-themed ASCII art, and claim to have exfiltrated source code, CMS plugins, system logs and other server files. BleepingComputer confirmed the defacement was live on Clop's infrastructure and that the uploaded file could be downloaded from the site.

Google Infiltrates and Disrupts Notorious Supply Chain Hacker Group

Google’s threat intelligence team secretly embedded an undercover analyst within the hacking group TeamPCP during its extensive supply chain attack campaign. This inside access allowed Google to monitor the group’s activities, warn potential targets, and assist law enforcement in identifying key members. The operation uncovered critical security lapses and contributed to arrests in Australia last month.

ShinyHunters leak stolen Florida DAVID driver database after ransom refusal

The ShinyHunters hacking group released hundreds of thousands of files taken from Florida's DAVID motor vehicle database, saying it did so because the state agency refused to pay ransom or negotiate. Florida's FLHSMV confirmed the breach, which occurred after attackers obtained a police officer's login credentials stored on a personal device.

Anthropic reports ShinyHunters used Claude AI to mine 1.8M Android apps for secrets

Anthropic disclosed that between December 2025 and August 2026 it detected and disrupted misuse of its Claude AI models by multiple threat actors, including groups tied to ShinyHunters. One French-speaking member, 'frkoo', ran automated pipelines on AWS servers that downloaded 1.8 million Android APKs, decompiled them, and scanned for hardcoded credentials using TruffleHog, funneling verified findings into a categorized Telegram network. The same actor also harvested GitHub organization emails to obtain access tokens and ran a carding site impersonating French police to sell stolen payment data.

FLHSMV: DAVID driver database breached via stolen Plant City police credentials

Florida's Department of Highway Safety and Motor Vehicles confirmed the ShinyHunters extortion group breached its DAVID driver database on September 4, 2026, after the gang claimed to have stolen over 200,000 driver records. FLHSMV said the intruder used login credentials from a single Plant City Police Department account that had been improperly saved on the employee's personal device, contradicting ShinyHunters' claim that it exploited a password-reset flaw across multiple accounts.