Technology 16 sources · over 4 days Latest coverage 23 Sept 2026, 8:06 am UTC

ShinyHunters Claims Breaches of FBI and Clop Ransomware Leak Site

The hacking group ShinyHunters says it infiltrated both the FBI and the Clop ransomware gang, raising urgent questions about security at the world's top law enforcement agency and among cybercriminals.

By Ethan Cole · First published 23 Sept 2026

In brief

  1. ShinyHunters first breached the Clop ransomware group's dark web leak site using a vulnerability in its content management system.
  2. The hackers reportedly stole sensitive data, including private keys and internal files, from Clop and defaced its leak site.
  3. Shortly after, ShinyHunters claimed to have hacked the FBI, stealing data on thousands of agents and job applicants.
  4. The group says it used a zero-day flaw in Oracle PeopleSoft to access FBI systems and demands the agency correct its description of them.
  5. Both the FBI and Clop are actively investigating the breaches as questions remain about the scale and authenticity of the stolen data.
ShinyHunters Claims Breaches of FBI and Clop Ransomware Leak Site
Source: The Register

Timeline · 7 moments

7 moments Open the full timeline →

ShinyHunters breaches Clop ransomware gang's leak site

BleepingComputer ↗

Unauthenticated file upload led to theft of Clop's private keys

DEV Community ↗

Clop's leak site defaced and extortion demand issued by ShinyHunters

The Register ↗

ShinyHunters claims breach of FBI, theft of employee data

The Register ↗

Hackers say they used PeopleSoft zero-day to access FBI systems

BleepingComputer ↗

ShinyHunters posts evidence of FBI data theft, demands retraction

SecurityWeek ↗

FBI launches investigation into ShinyHunters breach claims

nu.nl ↗

How it started

ShinyHunters, a well-known hacking group, began by targeting the Clop ransomware gang. Using an unauthenticated file upload vulnerability in the Grav CMS running Clop's Tor leak site, they gained access to sensitive files. This allowed them to steal internal data and the private keys used for the site's onion service.

The breach was quickly made public when ShinyHunters defaced Clop's site, taunting the rival gang and posting their own logo. This unusual move, where one criminal group attacked another, drew immediate attention from cybersecurity watchers.

How it unfolded

On September 19, 2026, reports emerged that ShinyHunters had successfully compromised the Clop ransomware gang's leak site. The group exploited a file upload flaw, stole source code and private onion service keys, and publicly mocked Clop by defacing their site.

Shortly after, ShinyHunters escalated its campaign by announcing it had breached the FBI. On September 22, the group claimed to have stolen over 2 TB of data, including details about FBI employees and job applicants. They stated the breach was not financially motivated but a response to how the FBI described them in official reports.

ShinyHunters said it used a previously unknown zero-day vulnerability in Oracle PeopleSoft to access internal FBI systems. The hackers posted evidence of the breach on their dark web site and threatened to release more data if their demands were not met.

The FBI acknowledged awareness of the claims and began an investigation into the reported breach. Meanwhile, Clop was left dealing with the aftermath of the attack on its own infrastructure.

Where it stands

Currently, both the FBI and Clop are investigating the extent of the breaches. The FBI has not confirmed the full scope of the data loss or its authenticity, but security experts warn that any compromise of agent data could have serious national security implications.

ShinyHunters continues to demand that the FBI retract statements made about the group in previous threat reports. The situation remains fluid, with the potential for more data leaks if negotiations or investigations stall.

What to watch

Key questions remain about whether the stolen FBI data is genuine and how much information could be exposed if released. The FBI's investigation may determine if agents or applicants are at risk, and whether the zero-day vulnerability has been patched. Observers are also watching for possible retaliation or further escalation among hacking groups.

Written from 16 outlets' coverage of this story. Every timeline entry links to the original report.

More in Technology

All →