Cyber extortion group ShinyHunters has issued a dramatic two-day deadline to the FBI, claiming it has compromised sensitive agency systems and threatening to publish the allegedly stolen information unless the bureau responds. The group wrote: “You have exactly two days to contact us to prevent publication of all your data containing sensitive information. Deadline: Sep 25, 2026.”
The threat follows a claim by the cybercrime group that it breached the FBI and obtained information belonging to agents and people who applied for jobs at the agency. The allegation has not been independently verified, although the FBI has acknowledged it is investigating claims of unauthorized activity involving its FBIJobs website.
A ShinyHunters spokesperson told The Register that the group allegedly exploited a new Oracle PeopleSoft zero-day to obtain remote code execution and deface the FBI’s jobs website. The attackers reportedly replaced the site with a banner reading, “This site has been seized by ShinyHunters.”
The website now displays a maintenance notice stating, “Scheduled Maintenance Underway. We're Sniffing Out Site Updates for You!”