ShinyHunters Claims Breaches of FBI and Clop Ransomware Leak Site
The hacking group ShinyHunters says it infiltrated both the FBI and the Clop ransomware gang, raising urgent questions about security at the world's top law enforcement agency and among cybercriminals.
By Ethan Cole · First published 23 Sept 2026
In brief
- ShinyHunters first breached the Clop ransomware group's dark web leak site using a vulnerability in its content management system.
- The hackers reportedly stole sensitive data, including private keys and internal files, from Clop and defaced its leak site.
- Shortly after, ShinyHunters claimed to have hacked the FBI, stealing data on thousands of agents and job applicants.
- The group says it used a zero-day flaw in Oracle PeopleSoft to access FBI systems and demands the agency correct its description of them.
- Both the FBI and Clop are actively investigating the breaches as questions remain about the scale and authenticity of the stolen data.
Timeline · 7 moments
ShinyHunters breaches Clop ransomware gang's leak site
BleepingComputer ↗Unauthenticated file upload led to theft of Clop's private keys
DEV Community ↗Clop's leak site defaced and extortion demand issued by ShinyHunters
The Register ↗ShinyHunters claims breach of FBI, theft of employee data
The Register ↗Hackers say they used PeopleSoft zero-day to access FBI systems
BleepingComputer ↗ShinyHunters posts evidence of FBI data theft, demands retraction
SecurityWeek ↗FBI launches investigation into ShinyHunters breach claims
nu.nl ↗How it started
ShinyHunters, a well-known hacking group, began by targeting the Clop ransomware gang. Using an unauthenticated file upload vulnerability in the Grav CMS running Clop's Tor leak site, they gained access to sensitive files. This allowed them to steal internal data and the private keys used for the site's onion service.
The breach was quickly made public when ShinyHunters defaced Clop's site, taunting the rival gang and posting their own logo. This unusual move, where one criminal group attacked another, drew immediate attention from cybersecurity watchers.
How it unfolded
On September 19, 2026, reports emerged that ShinyHunters had successfully compromised the Clop ransomware gang's leak site. The group exploited a file upload flaw, stole source code and private onion service keys, and publicly mocked Clop by defacing their site.
Shortly after, ShinyHunters escalated its campaign by announcing it had breached the FBI. On September 22, the group claimed to have stolen over 2 TB of data, including details about FBI employees and job applicants. They stated the breach was not financially motivated but a response to how the FBI described them in official reports.
ShinyHunters said it used a previously unknown zero-day vulnerability in Oracle PeopleSoft to access internal FBI systems. The hackers posted evidence of the breach on their dark web site and threatened to release more data if their demands were not met.
The FBI acknowledged awareness of the claims and began an investigation into the reported breach. Meanwhile, Clop was left dealing with the aftermath of the attack on its own infrastructure.
Where it stands
Currently, both the FBI and Clop are investigating the extent of the breaches. The FBI has not confirmed the full scope of the data loss or its authenticity, but security experts warn that any compromise of agent data could have serious national security implications.
ShinyHunters continues to demand that the FBI retract statements made about the group in previous threat reports. The situation remains fluid, with the potential for more data leaks if negotiations or investigations stall.
What to watch
Key questions remain about whether the stolen FBI data is genuine and how much information could be exposed if released. The FBI's investigation may determine if agents or applicants are at risk, and whether the zero-day vulnerability has been patched. Observers are also watching for possible retaliation or further escalation among hacking groups.


