Someone using the ShinyHunters name wants the FBI to take back its warning about the group. Their way of making the point? They say they broke into FBIjobs.gov through a new PeopleSoft zero-day and walked away with 2–3 terabytes of data.
The FBI isn’t there yet. It says it is investigating claims of unauthorized activity affecting its jobs site. The zero-day, the move into FBI-managed AWS GovCloud, and the enormous theft figure all come from the group.
In May, the FBI warned that ShinyHunters actors may exaggerate their access and harass victims to pressure them. The person behind this new claim calls the FBIjobs operation retaliation and wants that warning corrected or removed within a week. Asked whether the group would release alleged FBI data if it refused, the representative would not say.
Before we get lost in terabytes, let’s talk about the name. Which ShinyHunters is making this claim?
ShinyHunters 101: the name is not the crew
If you’re new to ShinyHunters, keep these three things separate:
The OG crew: The ShinyHunters account advertised stolen data from more than 60 companies in 2020–21, according to the U.S. Justice Department. Sébastien Raoult, a member of that early operation, was arrested in 2022 and sentenced in 2024.
The reused name: Le Monde found at least two phases of people using it, with no proven connection between them. An apparent original member objected to others taking the name. Google Threat Intelligence tracks separate clusters behind later ShinyHunters-branded activity.
The FBIjobs claimant: No public evidence ties the person talking to reporters now to the original 2020 crew. The handle is familiar. The people behind this claim are not established.
I wrote in my BreachForums piece: “ShinyHunters goes down? Someone else will copy the brand.” That’s the problem with reading today’s headline as an OG reunion.
What does the newer operation actually do?
Google documented a newer playbook under the ShinyHunters name: someone poses as IT, gets an employee’s sign-in details and MFA codes, and pulls data from cloud apps for extortion. Its researchers track several clusters because the shared name does not tell them which operator ran which job.
Even Scattered Lapsus$ Hunters was a claimed alliance of three notorious names, not a verified roster. The labels travel faster than anyone can pin down the people behind them.
PeopleSoft: two different stories
In May and June, Mandiant watched a ShinyHunters-branded cluster exploit a then-unknown PeopleSoft flaw against education-sector systems. Oracle later identified it as CVE-2026-35273.
Now the FBIjobs claimant says it found another PeopleSoft zero-day. Don’t put the June CVE under the FBI headline: this is supposed to be a new flaw, and no technical proof has surfaced. Mandiant’s report also does not identify the person talking to reporters about the FBI.
What has anyone actually seen?
The group sent BleepingComputer a picture of an allegedly defaced FBI Jobs page and two supposed records. The outlet could not independently verify those records or their source.
Separately, 404 Media received about 5,000 purported employee records. Some details checked against real people and DOJ-linked phone numbers, according to BleepingComputer. The sample deserves attention. It still leaves the route in, the scale of any theft, and the alleged new flaw open.
The FBI’s 2022 privacy assessment described a candidate system using PeopleSoft and AWS GovCloud and handling sensitive applicant information. That tells us why a jobs portal would be attractive. It cannot tell us what happened there this week.
The CodeAIntel take
In the underground, a known handle buys attention. A new operator can benefit from the ShinyHunters name without proving any link to the original crew. Here, the claimant is using that reputation to pick a public fight with the FBI and demand a retraction.






