ShinyHunters Claim FBI Breach: The Hacking Group That Started With Rockstar
Games › News
Gaming News

ShinyHunters Claim FBI Breach: The Hacking Group That Started With Rockstar

24 September 2026 · 3 min read · News

In April 2026, the hacking collective ShinyHunters claimed to have stolen millions of business records from Rockstar Games, the developer behind Grand Theft Auto. It was a significant breach of a major game studio, and it positioned the group as a serious threat within the games industry. Five months later, ShinyHunters has moved to an entirely different scale of target: the United States Federal Bureau of Investigation.

From Game Studios to the FBI: ShinyHunters’ Escalating Targets

ShinyHunters is an international cybercrime collective — believed to have originated in France — that has spent several years accumulating a notable list of high-profile victims. Before Rockstar, the group was already known for data thefts affecting major consumer platforms. In May 2026, it breached Canvas, the education platform used by schools and universities across the United States, causing widespread disruption. Earlier in September, Anthropic disclosed that ShinyHunters-linked hackers had attempted to misuse its AI tools.

Each breach has been bigger than the last. The Rockstar breach in April generated significant attention partly because of the GTA brand, but its operational impact was limited to one company’s internal records. A verified FBI breach, by contrast, would expose the personal details of thousands of federal agents — including those working counter-intelligence, organised crime, and drug enforcement roles. The claimed FBI intrusion, if confirmed, would represent the group’s most consequential action yet.

What the Group Claims to Have Stolen

ShinyHunters says it accessed multiple FBI systems — including FBIJobs, FBI BEAST (background check records), FBI MedLink (agent medical records), and Criminal Justice Information Systems — via a zero-day vulnerability in Oracle’s PeopleSoft software. From there, the group claims to have reached FBI-managed AWS GovCloud servers, downloading between two and three terabytes of data covering current and former agents as well as job applicants.

As evidence, the group shared a 5,000-line spreadsheet with press contacts. The sample data appeared to include names, home addresses, phone numbers, dates of birth, Social Security numbers, emergency contact details, and in some cases information about agents’ spouses. Reuters was able to partially verify more than 22 individual entries by cross-referencing the sample against credit bureau records and dark-web intelligence data. Details matching FBI Director Kash Patel’s entry were among those the agency was able to confirm.

Retaliation, Not Ransom: A Different Kind of Threat

“We hacked the FBI. We hold data on all FBI employees and applicants. This was not about money. The FBI lied about us and we want them to retract it.” — ShinyHunters statement

The stated motive sets this breach apart from the group’s usual activity. In May 2026, the FBI published a public advisory detailing ShinyHunters’ methods and explicitly advising organisations not to pay any ransom demand from the group. ShinyHunters says Tuesday’s attack was a direct response: a form of institutional retaliation rather than a financial play. The group gave the bureau one week to retract or correct the advisory, threatening to publish the full database if it refuses.

That framing makes the FBI breach more politically charged than commercially motivated. ShinyHunters is not asking for money — it is asking a federal law enforcement agency to publicly admit it was wrong about them. The FBI is unlikely to comply.

What the FBI Has Said — and What Remains Unverified

The bureau confirmed in a statement that it was “actively and aggressively investigating” the matter and working with third-party providers who support FBIJobs.gov to assess the extent of any breach. The FBI has not confirmed whether ShinyHunters successfully accessed its internal systems or whether the data came from a third-party contractor’s infrastructure.

That distinction matters. A breach of the FBI’s own internal systems is qualitatively different from a breach of an external contractor running an FBI-branded web portal. Reuters noted it could not establish the origin of the stolen data despite partially verifying its accuracy. The FBI’s own statement conspicuously leaves open the possibility that no internal system was penetrated. Current and former agents are left in an uncomfortable middle position: some of their personal details appear to be in ShinyHunters’ hands regardless of where they originally came from.

🎮
Stay updated with Gaming

Follow EverythingEdinburgh for the latest gaming and esports news

More Gaming News → Follow on Google
EverythingEdinburgh Gaming
EverythingEdinburgh Gaming
Gaming Editor

The EverythingEdinburgh Gaming team covers esports, PC, console and gaming industry news.