A prolific cybercriminal group known as ShinyHunters claimed Tuesday that it breached FBI systems and stole terabytes of data on current and former agents along with job applicants.

The group posted the assertion on its dark web site and provided samples to media outlets including names, home addresses, phone numbers, and details on spouses for thousands of individuals. Independent verification of portions of the sample matched public records and other sources.

ShinyHunters said it gained initial access Monday night through a previously unknown vulnerability in Oracle PeopleSoft software used for human resources functions before pivoting to Amazon Web Services GovCloud infrastructure. The hackers claimed compromise of services including Criminal Justice, HR, and Medlink.

The group demanded the FBI retract or revise a May advisory that detailed its extortion tactics and advised victims against paying ransoms. It insisted the operation was not financially motivated.

The FBI jobs website displayed maintenance notices Tuesday, and the bureau confirmed it is investigating claims of unauthorized activity affecting their website. No official confirmation of the full scope of any breach has been issued.

Such a compromise poses serious counterintelligence risks, as personal details on federal agents and their families could enable foreign adversaries or criminals to target or coerce personnel involved in sensitive investigations.

This incident underscores ongoing vulnerabilities in federal systems despite repeated warnings about cyber threats. Law enforcement agencies face increasing pressure from sophisticated actors who exploit any weaknesses in recruitment and personnel databases.

The FBI has faced scrutiny over its cybersecurity posture in recent years. Director Kash Patel and agency leadership will likely face questions about how such access was allegedly achieved and what steps are underway to mitigate damage and prevent recurrence.

No immediate response came from the hackers regarding further actions if demands are unmet. The bureau has historically advised against ransom payments, and government policy prohibits them in most cases.

Reports indicate the hackers defaced the recruitment portal with messages mimicking law enforcement seizure notices before the site went offline for maintenance.