{"id":673078,"date":"2026-09-23T12:19:32","date_gmt":"2026-09-23T12:19:32","guid":{"rendered":"https:\/\/buglecall.org\/?p=673078"},"modified":"2026-09-23T12:19:32","modified_gmt":"2026-09-23T12:19:32","slug":"hackers-say-they-broke-into-the-fbi-and-stole-thousands-of-agents-records-then-they-left-a-message-for-trump","status":"publish","type":"post","link":"https:\/\/buglecall.org\/?p=673078","title":{"rendered":"Hackers say they broke into the FBI and stole thousands of agents\u2019 records \u2014 then they left a message for Trump"},"content":{"rendered":"<div><img fetchpriority=\"high\" decoding=\"async\" width=\"1200\" height=\"630\" src=\"https:\/\/americanwirenews.com\/wp-content\/uploads\/2026\/09\/rf-pexels-fbi-1200x630.jpg\" class=\"attachment-facebook size-facebook wp-post-image\" alt=\"\" \/><\/div>\n<p>A notorious group of hackers broke into the FBI\u2019s website and obtained a treasure trove of information on the bureau\u2019s \u201cemployees and applicants.\u201d<\/p>\n<p>\u201cWe hacked the FBI,\u201d a spokesperson for the ShinyHunters hacking group told <a href=\"https:\/\/www.404media.co\/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees\/\" target=\"_blank\" rel=\"noopener\">404 Media<\/a>. \u201cWe hold data on all FBI employees and applicants.\u201d<\/p>\n<p>The spokesperson added that the group now has the names, home addresses, phone numbers, and spouse information of all of the bureau\u2019s employees. As proof, the spokesperson handed 404 Media a sample appearing to contain the personal data of 5,000 FBI employees.<\/p>\n<p>A brief investigation by 404 Media found that the sample data, including names and numbers, does correspond to real people in the bureau.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">ShinyHunters just defaced the FBI Jobs page <a href=\"https:\/\/t.co\/u3upEpLxvY\">pic.twitter.com\/u3upEpLxvY<\/a><\/p>\n<p>\u2014 vxdb (@vxdb) <a href=\"https:\/\/x.com\/vxdb\/status\/2102441068016857504?ref_src=twsrc%5Etfw\">September 22, 2026<\/a><\/p>\n<\/blockquote>\n<p>The hackers with ShinyHunters also temporarily defaced the FBI\u2019s online employment portal by placing a banner on top mockingly saying that \u201cthis site has been seized by ShinyHunters.\u201d<\/p>\n<p>The defaced site also contained a stark warning: \u201cAll FBI data was compromised including PII\/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.\u201d<\/p>\n<p>The defaced site also contained a jab at President Donald Trump that read as follows: \u201cThank you for your attention to this matter.\u201d<\/p>\n<p>The hacking attack happened sometime Monday. According to the ShinyHunters spokesperson, they hacked the FBI\u2019s website by using a \u201czero day exploit\u201d that they found in Oracle software called PeopleSoft.<\/p>\n<p>\u201cFrom there, the group managed to access AWS GovCloud servers and downloaded data,\u201d according to 404 Media. \u201cThe representative said the exfiltrated data totalled between two and three terabytes.\u201d<\/p>\n<p>What remains unclear is the purpose of the hack. While ShinyHunters usually extorts its victims for money or attention, in this case they seem to want something else.<\/p>\n<p>\u201cWhat we plan to do is not something I\u2019d call extortion, maybe coercion,\u201d the spokesperson said. \u201cThis is not financially motivated.\u201d<\/p>\n<p>This suggests the hack was motivated either by personal grievances or political grievances. Many suspect the grievances are personal.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">Cybercrime group <a href=\"https:\/\/x.com\/hashtag\/ShinyHunters?src=hash&amp;ref_src=twsrc%5Etfw\">#ShinyHunters<\/a> just claimed to have breached the <a href=\"https:\/\/x.com\/hashtag\/FBI?src=hash&amp;ref_src=twsrc%5Etfw\">#FBI<\/a>, allegedly stealing data on thousands of bureau personnel. The twist? They claim it isn\u2019t financially motivated\u2014it\u2019s personal. <img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f9f5.png\" alt=\"\ud83e\uddf5\" class=\"wp-smiley\" \/><img decoding=\"async\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/17.0.2\/72x72\/1f447.png\" alt=\"\ud83d\udc47\" class=\"wp-smiley\" \/><\/p>\n<p>\u2014 Prashant Singh (@LibranLifter) <a href=\"https:\/\/x.com\/LibranLifter\/status\/2102476816418275656?ref_src=twsrc%5Etfw\">September 22, 2026<\/a><\/p>\n<\/blockquote>\n<p>According to 404 Media, ShinyHunters also published a post online accusing the FBI of having made \u201cfalse allegations\u201d against the hacking group in a previously published report.<\/p>\n<p>Published in May, the <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260515\" target=\"_blank\" rel=\"noopener\">FBI report<\/a> ripped into the hacker group, accusing it of using \u201creal or exaggerated claims of access to sensitive or personal information to prompt payment from victims.\u201d<\/p>\n<p>\u201cVictims may receive an extortion email signed as ShinyHunters,\u201d the report read. \u201cTo exert pressure on victims, SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.\u201d<\/p>\n<p>\u201cThreat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist,\u201d the report continued. \u201cFollowing these pressure tactics, SH actors have sometimes posted exfiltrated data to various iterations of the SH data leak site on the Tor network.\u201d<\/p>\n<p>In its online post, ShinyHunters stressed to the FBI that it\u2019s \u201callowing you a time of 1 week to correct\u201d or remove the report.<\/p>\n<blockquote class=\"twitter-tweet\" data-conversation=\"none\">\n<p dir=\"ltr\" lang=\"en\">Here is the full message in screenshot form. <a href=\"https:\/\/t.co\/iZo5fFDyd7\">pic.twitter.com\/iZo5fFDyd7<\/a><\/p>\n<p>\u2014 Dark Web Informer (@DarkWebInformer) <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/2102452790513877413?ref_src=twsrc%5Etfw\">September 22, 2026<\/a><\/p>\n<\/blockquote>\n<p>Allan Liska, a threat intelligence analyst at Recorded Future, suggested to <a href=\"https:\/\/www.axios.com\/2026\/09\/22\/shinyhunters-fbi-employees-data-hack\" target=\"_blank\" rel=\"noopener\">Axios<\/a> that it may be too late to stop the ramifications of the hack.<\/p>\n<p>\u201cThe data is out there and has likely been repeatedly downloaded and passed around to other threat actors,\u201d she noted.<\/p>\n<p>Andrew Brandt, a principal threat intelligence incident commander at Huntress, added that ShinyHunters might sell the data it extracted.<\/p>\n<p>\u201cIt doesn\u2019t take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released,\u201d he said.<\/p>\n<p>Cynthia Kaiser, a former deputy assistant director of the FBI\u2019s Cyber Division, dissed the group in a statement to <a href=\"https:\/\/www.politico.com\/news\/2026\/09\/22\/shinyhunters-fbi-cyber-hack-01088494\" target=\"_blank\" rel=\"noopener\">Politico<\/a>.<\/p>\n<p>She said that \u201cretribution\u201d attacks on the FBI are \u201cvery atypical behavior for ransomware gangs, but goes to show you the unpredictability and immaturity of the group.\u201d<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/americanwirenews.com\/wp-content\/uploads\/2026\/09\/rf-pexels-fbi-1200x630.jpg\" title=\"Hackers say they broke into the FBI and stole thousands of agents\u2019 records \u2014 then they left a message for Trump\" \/><\/p>","protected":false},"excerpt":{"rendered":"<p>A notorious group of hackers broke into the FBI\u2019s website and obtained a treasure trove of information on the bureau\u2019s \u201cemployees and applicants.\u201d \u201cWe hacked the FBI,\u201d a spokesperson for the ShinyHunters hacking group told 404 Media. \u201cWe hold data on all FBI employees and applicants.\u201d The spokesperson added that the group now has the&hellip; <a class=\"more-link\" href=\"https:\/\/buglecall.org\/?p=673078\">Continue reading <span class=\"screen-reader-text\">Hackers say they broke into the FBI and stole thousands of agents\u2019 records \u2014 then they left a message for Trump<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rop_custom_images_group":[],"rop_custom_messages_group":[],"rop_publish_now":"initial","rop_publish_now_accounts":[],"rop_publish_now_history":[],"rop_publish_now_status":"pending","footnotes":""},"categories":[18,19,10,21,12,11,9],"tags":[],"class_list":["post-673078","post","type-post","status-publish","format-standard","hentry","category-cancel-culture","category-censorship","category-civil-liberties","category-election-integrity","category-equal-justice","category-free-speech","category-religious-freedom","entry"],"_links":{"self":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/posts\/673078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=673078"}],"version-history":[{"count":0,"href":"https:\/\/buglecall.org\/index.php?rest_route=\/wp\/v2\/posts\/673078\/revisions"}],"wp:attachment":[{"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=673078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=673078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buglecall.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=673078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}