
ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve their reputation and keep their business" afloat. So it hacked the FBI to make a statement, the group told The Register. It's a game and it's the world we live in," a ShinyHunters spokesperson told us. We are just protecting our business as any other business would do. It's about who does their job better." On Friday, the FBI confirmed the breach to The Register, after earlier in the week saying the bureau was investigating ShinyHunters' claims. "The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII)," an FBI spokesperson told The Register. "While the point of breach is still undetermined - whether a third-party or the FBI's enterprise - we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk." On Tuesday, the criminals told us that they broke into the bureau via yet another Oracle PeopleSoft zero-day flaw in the FBIJobs.gov portal, which remains down as of Friday. Then, they breached the FBI's managed servers on AWS GovCloud and swiped thousands of personnel files belonging to current, former, and prospective FBI employees. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group claimed in a message posted online and addressed to FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI's Cyber Division. Sample files reviewed by journalists and security researchers appear to contain agents' home addresses, phone numbers, email addresses, Social Security numbers, job titles, assigned field office, and emergency contact information. 'We refuted the misinformation disseminated by the FBI' According to a spokesperson for ShinyHunters, the FBI hack isn't about the money, and the crew did not demand a multimillion-dollar extortion payment to not leak the agents' personal details. Our breach of the FBI was executed specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report," a spokesperson told The Register. The FBI bulletin, published soon after the group breached ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff, said ShinyHunters uses harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting." The criminals, it continued, may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist." ShinyHunters contends this is all false. By hacking the FBI and releasing its statement about the hack, we demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers," the spokesperson told us in an interview. This was fundamentally a public relations and marketing initiative for our business," they said. 'Results-driven professionals' or criminals? ShinyHunters said it believes that future corporate partners we engage with for payment will review this documentation, reinforcing our reputation as serious, results-driven professionals focused solely on transaction and resolution." Most people call these "future corporate partners" victim organizations, breached by the digital thieves, and threatened with data leaks unless they pay an extortion demand. The FBI intrusion establishes our credibility, technical superiority and excellence, and capability with future corporate stakeholders, positioning us as a professional and predictable entity focused on concluding negotiations efficiently," the spokesperson said. It also puts a huge target on the crew, and we'd bet that the FBI, already gunning to arrest ShinyHunters members, is now doubling down on those efforts. The spokesperson said they and others in the crew started off as GnosticPlayers before rebranding as ShinyHunters in 2020, and that they have since seen the majority" of GnosticPlayers members arrested. This business, however, is a criminal operation. We asked them why they believe people will trust the words of criminals over those of law enforcement. They said it's due to ShinyHunters' unique and exceptional reputation along with over five years of history in the space...We are in a unique position and due to our vast capabilities and resources, victims are more likely to resolve the situation quickly and cheaper with us instead of going down the full disclosure route." Think of the children We also questioned how they justify doing what they do in this business" - breaking into IT systems, stealing data, extorting victims - considering the personal toll it takes on people, especially when the stolen files contain sensitive information about children as they did in the Canvas intrusion. ShinyHunters claims that they don't attack human beings. We attack the corporate structure. The Business. Not human beings. The money comes out of insurance pocket. Not people's or businesses' own. Full coverage by insurance. No personal harm is being done, only business harm that they recover from within a quarter considering the type of attack." Ransomware and other disruptive attacks are substantially worse and costly," they said. There are times in the work we do sometimes we have to push the corporate to the absolute limit to get them on the table," they continued, noting that there was an initial issue" with the Canvas intrusion that we cannot comment on, but it highly relates to the misinformation we are combating. It takes a lot of convincing to bring a corporate to the table to negotiate if they think you are not trustworthy and bluffing/exaggerating what you have." While we don't know for sure what this issue was, ShinyHunters switched to school-by-school extortion after compromising Instructure, the company that owns the Canvas online learning platform, in late April and after the initial pay-or-leak deadline passed on May 6. They injected a ransom message into about 330 Canvas school login portals, causing Instructure to take the platform offline for a day - during final exams and Advanced Placement testing for many. Meanwhile, that PeopleSoft 0day The ed-tech company ultimately reached an agreement" with ShinyHunters, which is corporate-speak for they paid the extortion demand. Alliance Risk CEO David Vainer previously told The Register he estimates the figure sits somewhere between $5 million and $30 million. According to ShinyHunters, the PeopleSoft preauth vulnerability that they exploited in the FBI attack still doesn't have a patch. Oracle hasn't responded to The Register's questions about the zero-day, or any plans for a patch. Shiny had no comment" about whether the gang has abused the PeopleSoft bug to compromise other organizations. But they added: the zero-day would allow us to access similar HR/Employee personal information for other corporations who are vulnerable." They wouldn't put a dollar amount on how much they earn from extorting businesses, but boasted: our revenue performance significantly outperforms both our counterparts and legitimate real life businesses. We have reason to believe in a few months or soon an upcoming financial analysis or reports tracking our earnings will reflect substantial revenue growth." And they would not comment when asked if they worried about getting arrested and criminally charged for their digital intrusions and extortion attacks. (R)