Hackers say they won’t release all data stolen from FBI | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker

The cybercrime group that claims to have stolen a massive amount of personal data about what it describes as “all FBI employees and applicants” now says it has no plans to make the information public.
ShinyHunters, which breached the agency and defaced its jobs website last week, told Straight Arrow on Monday that it “never intended” or “planned to” publish the highly sensitive data.
“Since the very beginning we had made our decision that we would never publish this data,” the group said.
Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™
Point phone camera here
The hackers reportedly gained access to the data, which included information such as the names, job titles, Social Security numbers, addresses, badge numbers, dates of birth and phone numbers of current and former FBI employees, along with personal information on applicants and even the spouses of agents and applicants. The hackers apparently exploited a previously unknown vulnerability in software used by the bureau to store applicant and employee information.
The hack raised questions about the security of FBI computer systems and carried potential national security implications if personal information about agents involved in highly sensitive investigations became public.
A sample of the data containing information on 5,000 employees, provided to outlets such as 404 Media and Reuters, exposed everyone from members of the FBI’s secretive hacking unit to those tasked with investigating China, Russia and drug cartels.
‘Exaggerate, lie or bluff’
In a statement last week, the FBI said it was “aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”
The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the https://t.co/CXFsC8cNUA portal and alleged impact to FBI employee personally identifiable information (PII). While the point of breach is still undetermined—whether a third-party or the FBI’s…
— FBI (@FBI) September 23, 2026
In a now-deleted post on ShinyHunters’ dark web leak site, the group said the breach was carried out in retaliation against a public service announcement from the FBI in May that accused the hackers of using “harassment strategies” and “exaggerated claims of access to sensitive or personal information.”
In a statement to Straight Arrow at the time, ShinyHunters pushed back on the claims by saying that the group does not “exaggerate, lie or bluff.” The group added that the FBI had five days to delete or retract its public service announcement.
The hackers followed up with a second post, also later deleted, saying they had no further comments because they were “highly confident” they had achieved their goal.
In their statement to Straight Arrow on Monday, ShinyHunters expanded on its justification for not releasing the data and said it never intended to.
“Since the very beginning of this event, we have unequivocally and assiduously emphasized this is NOT extortion, this is NOT ransom, this is NOT financially motivated. However, the public and media have misinterpreted this as extortion and have assumed that if the victim entity does not comply within 1 week which we all know, including ourselves, they would never comply, we would publish all the data.”
ShinyHunters
The hackers described the FBI breach as “a marketing campaign to protect our business and actively combat disinformation.”
In an updated statement on Monday, the bureau told 404 Media that it was “working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple Bureau wide communications within 24 hours of public reporting. The FBI treats the security of its information and the safety of its workforce as top priorities, and our investigation is ongoing.”
While the hackers say they have no plans to release the full dataset, the sample containing information on 5,000 employees has already begun to spread. Cybersecurity expert and popular YouTuber John Hammond said in a video last week that he, too, obtained the sample.
Round out your reading


