Overview: ShinyHunters Successfully Hacks the FBI
This video provides an in-depth analysis of a confirmed cyber attack against the Federal Bureau of Investigation (FBI) by the notorious hacker group ShinyHunters. After being called out in an FBI flash report, the group retaliated by compromising the FBI's internal systems and exfiltrating massive amounts of sensitive data.
Key Incidents and Impacts
- Website Defacement: The FBI jobs application portal (apply.fbijob.gov) was replaced with a maintenance message and an image of dogs, signaling a breach.
- Massive Data Theft: ShinyHunters claims to have stolen 2 to 3 terabytes of data. To understand the context of such massive data breaches, you can review the Comprehensive Guide to Cyber Crime Penalties in the U.S. for the legal consequences involved.
- Data Type: This includes personally identifiable information (PII), health information, and application details of current and former FBI employees and all job applicants.
- Affected Systems: Multiple FBI services were compromised, including Criminal Justice, HR, and MedLink.
The Exploit: How It Happened
- Primary Attack Vector: A zero-day exploit was used against Oracle PeopleSoft, a cloud-based HR and application management tool. These exploits are a classic example of Common Cybersecurity Threat Vectors and How to Protect Your Systems.
- Method: The attackers exploited a critical vulnerability (related to CVE-2026) allowing remote code execution without authentication.
- Lateral Movement: From the PeopleSoft system, the group moved into Amazon Web Services (AWS) government cloud servers to download the bulk of the data.
ShinyHunters' Demands and Ultimatum
- Motivation: The hack was a direct response to an FBI flash report labeling the group as a criminal cyber threat.
- Demand: ShinyHunters demands a public apology from FBI Director Kash Patel and Assistant Director Brett Leatherman, along with the removal of the flash report.
- Ultimatum: The group has given the FBI seven days to comply. If they fail, the entire stolen database, including the data of thousands of agents and applicants, will be publicly leaked on their dark web site.
Additional Context
- Track Record: The video references ShinyHunters' previous hack of the Florida DMV, where they leaked 52 GB of compressed data when the state refused to pay. This establishes their credibility and willingness to follow through on threats.
- Denial of Allegations: The group denies being part of "the Comm" (a loosely affiliated criminal community) and claims they never engage in swatting or personal threats. They frame their actions as a First Amendment response to disinformation.
- Current Status: While the FBI has not officially commented, journalists at 404 Media have verified a sample of the data, which includes personal details of 5,000 employees (addresses, phone numbers, DOBs, and spouse information). This data provides key Types of Digital Forensic Evidence in Cybersecurity Investigations for analysts.
User Takeaways
Security Implications:The video underscores how sophisticated groups can breach even high-level government agencies using single zero-day exploits. For a deep dive into recognizing these tactics, see the 30-Day Ethical Hacking Challenge: Day 1 - Introduction to Ethical Hacking.What to Watch:A week from the video's release, the public may be able to download the FBI data from ShinyHunters' dark web leak site if the FBI does not issue an apology.Speculation:The creator muses on the possibility of even more explosive data (like unredacted Epstein files) being released, though this remains unconfirmed. Such incidents highlight the need for Understanding Advanced Threat Detection: Insights from F-Secure's Cybersecurity Webinar.
Conclusion: The ShinyHunters hack represents a significant humiliation for the FBI and a potential major national security incident. The situation remains dangerously unstable, with a ticking clock on the release of highly sensitive personnel data.
Hello guys and gals. Me Mudahar. I got a smile on my face. Why ladies and gentlemen? Because I'm witnessing
internet warfare. Now today we're going to go on to the old dock web friendos because earlier today I had a friend
from VXDB actually message me and show me this interesting defacement. Actually we all kind of caught it earlier today.
It pinged me on my little alert. So this is a Umbreon. This site has been seized by shiny hunters. What site, you may
ask? APPLY.FBIJOB.GOV. DOG. THE FBI just keeps getting [ __ ] Now, if you go to the actual URL right
now, you can see that they got a picture of two dogs. Cute little dogs. Scheduled maintenance underway. Oh, maintenance,
you say? Well, let's look a little deeper. Let's see. Let's see why you need maintenance.
So, basically what these guys kind of showed was that all FBI data was compromised.
May I remind you this is like the most elite law enforcement team in the [ __ ] world. All right. one of them,
including sensitive personally identifiable information, health information on incumbent and former FBI
employees and all applicants. Are you watching this video? Did you like, "Oh man, I'm going to apply to the FBI. I'm
going to send my information." Hit the enter key. Well, it seems like they've got it. It seems like it's out
there. Uh, by the way, you might be like, "Woman, why are you laughing right now?" To be honest with you, the FBI has
become a former shadow of its like self. I used to have a lot of respect for this organization, but honestly, last couple
years, it's just all been down the [ __ ] drain. We have a lot more than what we claim here. Thank you for your
attention to this matter. So, may I remind you, you live in a perfect time, okay? As doomer as the world feels,
remember you can sit here, all right, with your [ __ ] Discord on this monitor and you can witness the FBI
versus like debt sec right now in front of your browser. Now, we're going to enter parts of the internet that you
probably shouldn't be accessing without like 14 different internet condoms. Just live vicariously through the fat Indian
guy that you're watching right now because as always, I will go to the dark web. So here they provided a link to
their deep web onion address which obviously if you followed my channel you know I'm a bit of an afficionado when it
comes to the old dank web. So we decided to go to that link and we entered shiny hunters internet like you know [ __ ]
deb like address. So I've shown you this before right I've shown you this page. Now the last time we looked at it the
state of Florida's DMV got hacked and these guys threatened to leak that information. And you might be
like, "But Muda, how can you even verify if these guys are legit?" See, the state of Florida failed to reach an agreement
despite their incredible patience and all the chances and offers we made. They don't care. So, the state of Florida
didn't pay and they have released 52 gigabytes of compressed data from the state of Florida's DMV. This can contain
some very personal information. You can just hit that big blue download button. In fact, if you look over here, in a
matter of less than one hour, I will be able to access and see and verify just what has happened with the state of
Florida's DMV hack. Right? These people do not [ __ ] around. I'm not here to promote them. I'm not here to say that
these people are cool and whatnot or they're in the right. Obviously, this is a criminal cyber hacking group, okay? I
I'm not promoting them. But this is a group that many people, the FBI, law enforcement agencies, big companies,
cyber security experts, everyone will tell you, yeah, they're pretty legit. Okay, these guys have been basically
breaching everything that you can imagine, right? I've went over them in the past. So, they've released an a PSA.
So, dear assistant director Brett Leatherman. Now, obviously, this is uh I'm trying to open this up. I don't
think I can. Something with their page isn't really giving me anything here. So, what I'm going to do is I'm going to
actually highlight this. I'm going to open up a text editor just so we can better read this right over here, too.
Right. And here you go, ladies and gentlemen. Let's uh let's just let's just uh let's zoom this up a little bit.
Dear assistant director Brett Leatherman and Director Cash Patel of the FBI. Mind you, Cash Patel is also somebody that's
been going through a fair bit of hacks recently. Like just this year, [ __ ] we were looking at like [ __ ] photos of
him leaked out all of his emails and [ __ ] During quarter two of this year, the FBI made substantial false
allegations regarding our organizations in a flash report, which I believe they're actually referring to this
report, this little public service announcement where the FBI has said that these individuals, Shiny Hunters, which
claimed the cyber attack that caused discretion, is a cyber criminal group specializing in large-scale data
breaches. They target major companies across tech, finance, retails. Threat actors often use the real or exaggerated
claims of access to sensitive or personal information to prompt payment of victims. Victims may receive an
extortion email uh you know sign from shiny hunters to exert pressure on the victims. So basically they've been
severely offended so offended that they hacked the [ __ ] agency man. We were very disappointed to see an agency of
your standing would resort to such circulation of disinformation in AN ATTEMPT TO DISRUPT OUR OPERATIONS. was
an effort that ultimately proved unsuccessful. You know, this is like just just imag It's kind of
dude, they're just openly [ __ ] with the largest [ __ ] law enforcement agency in the country, dude. Just for
everyone to see. This is like a This is like a movie to these people, bro. You know where it's like, you know what they
say, like, don't stick your dick in a hornets's nest, bro. They're gang banging the hornets's nest right now.
For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and
assertive posture. Okay. Our PSA today works to address these allegations and correct them. We have compromised the
FBI. We hold very sensitive data on almost all FBI agents and individuals who filed an application with the FBI
for a job, whether it be a special agent or any other role within your agency. The following FBI services were
compromised. So, the criminal justice, the HR, med link, and more. We are willing to allow you a time of one week
to correct or simply remove the 2026 quarter 2 flash report, guys. 7 days. Okay? It's like the ring. You know, you
pick up the phone, you will die in seven. We have seven days. The FBI doesn't pay up or respond or correct
their [ __ ] or apologize publicly, which to be honest with you, I don't think the US government will. Okay? They don't
[ __ ] with no terrorists. We might we might be able to we might I might be able to download the FBI database or
this leaked information in a week. That's how this works. You know, they have triggered they they have pissed off
the wrong crazy psychos. So basically they mentioned the three points and allegations right that they wanted to
correct right over here. We wish to state unequivocably, "Our threats and claims are very real, not exaggerated,
and never a bluff." This PSA today is living evidence of that. So, basically, the FBI was like, "Yeah, they're they're
just all huffing and puffing, dog. I don't know if I would have stated that when their entire leak site is filled
with just download links to everything. We wish to state unequivocably, we have never conducted swatting attacks against
corporate victims personnel." Hold up. I was about to sneeze. God, I hate that. I hate the feeling when
you're about to sneeze and you just don't. Nor have we ever texted victims, personal family members any threats. We
wish to state unequivocably that we have never claimed to have sensitive or compromising information. Finally, we
wish to state unequivocably that we are not a part of the comm. We have never been a part of the comm. The comm is a
propaganda started by the information security industry which has brainwashed past FBI and DOJ officials into
formalizing this nonsense. As a big believer and supporter of the US Constitution, we are exercising the
First Amendment and actively combating disinformation. It's not a ransom, coercion, or extortion. Your federal
policies do not apply here. This PSA ain't financially motivated. They don't even want money, boys. These guys don't
even want money. They just want an apology. THEY HAVE [ __ ] AND ACTED THE FBI and
they're like, "You give us an apology." It's just insane to witness this, man. Like, you know, we live in a great We
live in an insane time, dog. We recognize that certain elements within your Flash report appear to stem from
biased public reporting by certain journalists who have previously and intentionally propagated false
narratives about our organization and attempt to disrupt our operations. and hinder clients trust in our organization
hoping nobody pays us. Should those journalists, and you know very well who you are, continue these unwarranted
attacks and defamatory statements, we'll be forced to respond in a civil manner with a conserate and forceful defense of
our reputation. Are they going to is the is the cyber hacking group going to [ __ ] sue people for defamation? That
shit's getting insane, bro. God damn. Now, when these guys refer to the comm for instance, the comm is actually
something known as the community, it's an English grouping, English-speaking international group of interconnected
members whose whose members may many of whom are minors engage in a variety of criminal violations. The FBI estimates
thousands of individuals identify as current or recent members of the comm. So, they don't want to like associate
themselves with these individuals. I'm assuming that shiny hunters probably assumes these people are just like
script kitties and [ __ ] for the most part like squatting people, you know, downloading like [ __ ]
download downloading like scripts off of like GitHub and using them against like, you know, weak uh, you know, companies
or like weak servers, weak threats or whatever. They don't want to be associated with it. So basically these
people have felt defamed and now we are possibly going to witness in a week the leaking of FBI personnel information and
god knows what other [ __ ] right? Like I'd be I'd be amazed if you know I'd be amazed if shiny hunters had access to
like the unredacted Epstein files for instance. And uh they were just like by the way if you don't apologize to us
we'll just leak all this [ __ ] in a week right which you mean this is this is like a cyber criminal group. They're
very, they know they're a cyber criminal group, right? Obviously, I could imagine if they had like unredacted files or
something, like co-conspirators. Either they would have like the FBI SWAT hit teams of their house, you know, putting
two in the chest, one in the head, or the FBI might actually capitulate and go, "Yeah, yeah, we we'll apologize.
Just just don't don't leak anything that would make Big Daddy look bad." You know what I mean? To be fair, I don't know if
the FBI is going to be looking into this because currently even their director is like currently talking about like
removing beastiality as disqualifiers for FBI applicants. Again, I don't know what's going on with a lot of these US
agencies. [ __ ] is just straight up comical these days. Um I again, I don't even know the exact I just wanted to
bring up the beastiality thing because it was hilarious to me like why this what like it feels like an onion
article. You know, the FBI previously automatically disqualified people who acknowledged engaging in crimes
including prostitution or beastiality. So, I guess even if you were forced into it, they didn't want to punish victims
who were trafficked so that you know people who were forcibly like committing beastiality, they could be at least
allowed to apply into the FBI, which I don't know how much of an overlap that [ __ ] is to be honest with you. I feel
like on a case-byase basis, you could probably hire people. you would just know that they're victims or something.
I don't know, man. The FBI is a wild place these days. But basically, from what we've understood, they've actually
been breached. Now, you might be wondering, okay, but Muda, how do you know that they've been breached? What
could they have done to breach them? Right? And of course, this is where shiny hunters kind of really did explain
what has actually happened. So, for instance, according to the fellows over at 404 Media, these people have actually
apparently seen this information for themselves. The representative provided a sample appearing to contain an individ
personal data of 5,000 employees that included the alleged addresses, phone numbers, date of birth, and in some
details their their spouses as well, too. So, that's a lot of personal [ __ ] And honestly, for for somebody who works
in law enforcement, this can be some very scary [ __ ] to have leaked out, right? There's a lot of agents out there
that probably don't want their personal in I mean obviously nobody wants their personal information to be so easily
accessible. But you know people that work in the FBI look I know we can all laugh about individuals in the FBI or
whatever or or the state of the FBI but the FBI does consist of a lot of men and women that do put their lives on the
line to fight against some really really dark [ __ ] And and ultimately, I think for a lot of those people that simply
are just doing their like, you know, jobs, right? Really, just law enforcement officers doing their job,
this is a pretty scary situation, especially knowing that not only is your information potentially out there, but
the information of your spouse and [ __ ] who knows, maybe even your children, right? That's like the last thing you
would ever [ __ ] want. So, obviously, I don't know what the response from the FBI is going to be on this. Maybe they
will actually apologize or maybe in a week I will actually be able to download this information as will anybody on the
dark web and we can verify this for ourselves. So basically the way that they actually hacked stuff over here
they said that their group used a zeroday exploit. Basically meaning that a zero-day exploit is an exploit that
has not been detected. It's something that maybe they have found maybe they purchased from like another hacking
group for a sum of money and that zero day exploit which currently no like the company that is being hacked doesn't
know that it exists they absolutely exploited it and what did they exploit they exploited something known asoft
so I wanted to look a little bit deeper into what peopleoft was and umoft is actually like a tool that I guess you
can use to apply for jobs or whatever it's like a cloud-based tool that Oracle provides here right now. I guess the way
that People Soft sort of looks and this might be actually relatively older information. Actually, this is from
2015, so it is pretty damn old. But you can see that it kind of just looks very similar to this. So, obviously, if this
is breached, this is a database that consists, as you can imagine, with addresses, city, county, state, yada
yada yada. And just a quick mockup with a local AI tool based on the information that was provided. For instance, if you
were applying to the FBI, you were just throwing in information over here. You know, you had your application, you put
in your full name, contact, yada yada yada. This information, if breached, which it seems like it is, was used uh
to just basically grab a [ __ ] ton of people's information, right? So, the group managed to access AWS government
cloud servers and then started downloading data. So they started with this breach in Peopleoft and then they
moved into again the government cloud servers that are done through Amazon, right? So again, we live in a day and
age where hacking [ __ ] has gotten dramat I wouldn't say super dramatically easy. Like I don't want to make it sound like
you can just go to like any AI agent tool and like tell it like hack the FBI, but you know people that you know may
have not been great hackers can now work with the tool and sort of navigate their way through you know the process of
breaching into sites. But then again I'm extrapolating here. I don't know if these guys used LMS. I just know that
they use like a zero day exploit. But basically the actual representative said that they got around 2 to three
terabytes of data. So, what's in those two to three terabytes of data? I mean, it's crazy to think that is that's
almost like all the drive space I have on the system that these guys basically have just grabbed from the Federal
Bureau. And so, yeah, ladies and gentlemen, the FBI has without a doubt gotten basically completely hacked. You
know, technically speaking, this is not something that's super duper new. For instance, even when it comes to things
like Peopleoft, right? you know, not too long ago in 2026 over here, you can see that this CVE that you can look up for
yourself was related to critical remote code exploitation in that people soft tool, right? So again, if people have
access to tools like this, they can basically remotely exploit without authentication and if successfully
exploited, the vulnerability may result in remote code execution, which can allow you to then run whatever you want
on these systems. And then you can move around and and and and and do much more destructive things from this one entry
point. Again, the reality of this is that it takes very little sometimes, you know, it takes one little crack in the
matrix to break into and then, you know, if you're good enough, you can move around and and that's basically how an
organization as large as the FBI gets hacked like this and information gets released. Now, obviously, for the sake
of, you know, investigative journalism here, nothing here is 100% verified. You have the word of shiny hunters who has
said that they've hacked the FBI. There's no complete confirmation. The FBI obviously hasn't said anything. But
again, if the state of Florida's DMV hack that I'm currently downloading is to be, you know, confirmed, then, you
know, based on the track record here, there's a good chance that in a week most people will be able to download
Shiny Hunters's, you know, exfiltrated data, you know, if the FBI doesn't do anything. So yeah, ladies and gentlemen,
the FBI got [ __ ] perma hacked. And honestly, the only thing that I could be hoping out of this, the only thing that
I could be hoping out of this [ __ ] is the only thing that I could hope is somehow the unredacted Epstein files
show up. But I feel like if that was the case, it's me being hopeful, they would have announced it, right? They would
have mentioned it. Or maybe they will mention it in private if they do communicate with the FBI before the
drones get sent out to strike whatever location. Uh, and maybe they can work their way through it, RIGHT? MAYBE, JUST
MAYBE. But yeah, ladies and gentlemen, wild [ __ ] man. If you like what you saw, please like, comment, and
subscribe. Dislike if you dislike it. I am out.
The attack exploited a zero-day vulnerability in Oracle PeopleSoft, the FBI's cloud-based HR and application management tool. This critical flaw allowed remote code execution without authentication, enabling the hackers to breach the system. From there, they moved laterally into Amazon Web Services (AWS) government cloud servers to steal 2 to 3 terabytes of data.
ShinyHunters exfiltrated 2 to 3 terabytes of sensitive information, including personally identifiable information (PII), health records, and application details of current and former FBI employees and job applicants. A verified sample from 404 Media contained personal data of 5,000 employees, such as addresses, phone numbers, dates of birth, and spouse information.
The hack was retaliation for an FBI flash report labeling ShinyHunters as a criminal cyber threat. The group demands a public apology from FBI Director Kash Patel and Assistant Director Brett Leatherman, along with removal of the flash report. They issued a seven-day ultimatum to comply, threatening to publicly leak the stolen data on the dark web if refused.
The FBI has not officially commented, but journalists at 404 Media verified a data sample including personal details of 5,000 employees. The attack was confirmed by website defacement of the FBI jobs portal (apply.fbijob.gov) and ShinyHunters' public claims, backed by their track record of previous hacks like the Florida DMV breach.
Multiple FBI services were breached, including Criminal Justice, HR, and MedLink systems. After compromising Oracle PeopleSoft, the attackers moved into Amazon Web Services (AWS) government cloud servers to download the bulk of the stolen data, highlighting the lateral movement technique used.
If the FBI does not issue a public apology and remove the flash report within seven days, ShinyHunters will publicly release the entire stolen database on their dark web leak site. This includes sensitive data of thousands of agents and applicants, posing major national security and privacy risks, as seen in their previous Florida DMV leak.
The breach demonstrates how a single zero-day exploit can compromise even high-level government agencies, emphasizing the need for robust vulnerability management and patching. It also highlights the importance of monitoring third-party cloud services and implementing layered defenses to prevent lateral movement, as outlined in common cybersecurity threat vectors.
Keep this summary
Save it to LunaNotes and it becomes a real note in your library — editable, searchable, and ready to turn into flashcards or a diagram. Free to start.
Save to LunaNotesOr summarise for another video.
This summary and transcript were automatically generated using AI with the Free YouTube Transcript Summary Tool by LunaNotes.
Related summaries
30-Day Ethical Hacking Challenge: Day 1 - Introduction to Ethical Hacking
Join us for the first day of the 30-Day Ethical Hacking Challenge! In this video, we explore the fundamentals of ethical hacking, its definition, and the different types of hackers. Learn how curiosity drives hacking and the importance of ethical practices in cybersecurity.
Understanding Advanced Threat Detection: Insights from F-Secure's Cybersecurity Webinar
In this comprehensive webinar, Marco Finck, Director of Advanced Threat Protection at F-Secure, discusses the evolving threat landscape and the importance of advanced detection technologies in cybersecurity. Key topics include the attacker mindset, detection technologies, and practical tips for improving response capabilities.
Former CIA Officer Reveals Secrets of Counterterrorism and Espionage
Former CIA counterterrorism officer John Kiriakou shares an unprecedented account of hunting terrorists, recruiting spies, and the personal toll of living a double life. This in-depth interview covers the dangers of the job, the reality of CIA operations after 9/11, and the controversial use of torture, offering a rare look inside America's intelligence community.
Incident Response and Digital Forensics: A Comprehensive Overview
In this engaging webcast, Paul Sarian and John Strand delve into the critical topics of incident response and digital forensics, responding to audience demand for more content in these areas. They discuss practical tools, techniques, and the importance of baselining systems to effectively identify and respond to security incidents.
The FTX Collapse: A Deep Dive into the Downfall of a Crypto Giant
In this video summary, we explore the dramatic collapse of FTX, the world's second-largest cryptocurrency exchange, and the implications of its downfall. From the misappropriation of customer funds to the critical differences between custodial and non-custodial wallets, this summary provides insights into the events that led to one of the biggest scandals in crypto history.
Most viewed summaries
A Comprehensive Guide to Using Stable Diffusion Forge UI
Explore the Stable Diffusion Forge UI, customizable settings, models, and more to enhance your image generation experience.
Kolonyalismo at Imperyalismo: Ang Kasaysayan ng Pagsakop sa Pilipinas
Tuklasin ang kasaysayan ng kolonyalismo at imperyalismo sa Pilipinas sa pamamagitan ni Ferdinand Magellan.
Mastering Inpainting with Stable Diffusion: Fix Mistakes and Enhance Your Images
Learn to fix mistakes and enhance images with Stable Diffusion's inpainting features effectively.
Pamamaraan at Patakarang Kolonyal ng mga Espanyol sa Pilipinas
Tuklasin ang mga pamamaraan at patakaran ng mga Espanyol sa Pilipinas, at ang epekto nito sa mga Pilipino.
How to Install and Configure Forge: A New Stable Diffusion Web UI
Learn to install and configure the new Forge web UI for Stable Diffusion, with tips on models and settings.
Found this summary useful?
Take it with you. One click puts it in your own LunaNotes library.
Save to LunaNotes