▶ Submind YouTube summaries
Thumbnail for oh my god

oh my god

Watch on YouTube

Video summary

The video presents a developing story regarding a major data breach attributed to the cybercriminal group known as Shiny Hunters, who allegedly hacked the Federal Bureau of Investigation and compromised sensitive employee information. The narrator confirms that while the specific data samples shown are synthetic for safety, the breach is real and involves a massive dataset containing names, addresses, phone numbers, and details about the spouses of FBI agents and applicants. This incident marks a significant escalation in cybercrime, with Shiny Hunters—a group active since 2019 known for supply chain attacks and ransomware—claiming to have stolen terabytes of data from the FBI's job application portal and other internal systems. The breach has exposed critical personnel information, including social security numbers and assignments, which poses a severe threat not only to current agents but also to their families. Upon accessing the group's leak site, Shiny Hunters issued a public safety announcement that frames their actions as a response to what they claim are false allegations made by the FBI in a recent flash report. In a lengthy monologue displayed on their website, the hackers demand that the FBI correct or remove these alleged inaccuracies within one week, asserting that their threats are not financially motivated and therefore do not constitute extortion. They specifically deny accusations of using swatting tactics or sending threatening messages to families, arguing that they are merely exercising their right to free speech and combating disinformation. However, the narrator points out the inherent contradiction in their stance, noting that holding data hostage until demands are met is the definition of extortion, regardless of whether money is explicitly requested. The video critically analyzes the group's behavior, highlighting how their public complaints mirror tactics often used by scammers to deflect blame while simultaneously threatening victims with data leaks. The narrator expresses deep concern over the group's decision to target law enforcement agencies, arguing that leaking such sensitive information provides other criminals with a ready-made resource for identity theft and fraud. Furthermore, the group's attempt to breach the leak site of another notorious ransomware gang, Kloppe, is cited as evidence of their chaotic and dangerous nature. The narrator concludes that while Shiny Hunters may view themselves as victims of slander, their actions have given law enforcement a clear target and have already caused irreparable harm to thousands of individuals, making them a prime candidate for arrest once the FBI completes its investigation.
Read the full video transcript
Yesterday, there was breaking news that the Federal Bureau of Investigations was hacked and that all their employee data was breached by a cyber criminal group called Shiny Hunters. I've received a sample of the breach data, but obviously I can't show that to you. This is all fake data. What I'm showing you here is all synthetic data just so you get a feel and can visualize what this looks like because obviously I just can't show you. But I can personally confirm after going through and verifying the data set, it looks legit. I've looked all across public sources and other information to validate and it's real. Breached FBI data. So, this is still breaking news and I want to tell you the story. So, yesterday I was doom scrolling on Twitter forward/x when I saw this post from my good friend VxDB. He says, "Shiny hunters just defaced the FBI jobs page." You can see the picture here, URL in the address bar. apply.fbiji.gov. This site has been seized by shiny hunters. Down below, all FBI data was compromised, including sensitive PII and PHI on incumbent and former FBI employees and all applicant information. They say, "We have a lot more than what we claim here. Thank you for your attention to this matter, shiny hunters." Now, I saw this fly by in the morning around 9:53 Eastern time, and VXDB later added another news article that was uh discussing this further, but I thought I was quick enough to tune into this. I went to go check the FBI apply site, and like 8 minutes after, there's a Oh, we're sniffing out site updates for you with scheduled maintenance. If you were to go take a look at the FBI jobs.gov website right now, at least at the time recording, it is a 503 service temporarily unavailable. But soon after in the morning yesterday, the news started to break. I think, hey, shout out 404 media was able to break the news on this. We hacked the FBI. Hackers say they have data on all FBI employees. And a sample of 5,000 alleged agents include names, addresses, phone numbers, and details even on their employees spouses. That 5,000line sample of the full data set is the data dump that I've received, by the way, and it does include wives and husbands and spouse information. So, this is a wild situation, and you've got everybody chirping about this thing. So, I'm going to try and approach this video in a couple different ways. I'd like to read what Shiny Hunters has said, and I want to see some of the other news and commentary online and kind of give my piece all throughout. In case you aren't familiar, Shiny Hunters is a wildly prolific cyber crime and hacking group. So much so that they apparently even have their own Wikipedia page. This says they are an extortion group that's been active since 2019. They've caused a significant number of data breaches via supply chain attacks, zeroday exploitation of vulnerabilities, voice and phone call fishing like social engineering, and they exfiltrate data like a data breach and demand a ransomware payment or some other action. If the targets don't pay the ransom, the stolen information is often leaked or sold on the dark web. Shiny Hunters is believed to be affiliated with the comm, a large international network of cyber criminals. They like the he he hahas. Getting a little bit of jokes with O Umbreon as their logo and mascot of shiny Pokemon from the Pokemon video game, hence the name shiny hunters. I'll leave a link to all this for you down below. But if you take a look at the notable data breaches here, let me zoom out. They have done quite a bit of damage. Some big names in here, of course, some of the most recent ones, P school, Canvas. Other ones that made wild headline news were Snowflake, Rockstar Games, and the most recent addition, the FBI. So, let's jump onto tour and try to connect to their dark web leak site so that we could then see what was their message, their PSA or public safety announcement about the FBI breach. And I am going to make fun of all the high school drama from all this cyber crime shenanigan crap. This is their leak site, though. Hey, super quick. Sponsor of today's video, Minimal. It's no question that AI has changed the security landscape. Faster execution and all the wild superpowers it gives you come from AI agents running with full [music] access, which is inherently a security risk. It's its greatest strength and greatest weakness that your robot is running around with all of your user permissions, your SSH keys, AWS credentials, browser cookies, everything. So, Minimal finds the right through line. Minimal is a hermetic sandbox for AI agents. It's a single Rust binary. No Docker Damon and no virtual machine to configure. It takes just one command and your AI agent only gets the project that it needs to work on and nothing else. That way you're not living in YOLO mode and you're not one mistake away from having your data Xfilled or your dev box exploited. Minimal makes every environment reproducible and includes a software bill of material for every system dependency. Get the best of both worlds between agent isolation and speed. Get identical machine agnostic sandboxes wherever you use AI. Get Minimal with my link [music] below in the video description. jh.live/minimal. Huge thanks to Minimal for sponsoring this video. So, let's jump onto tour and try to connect to their dark webb leak site so that we could then see what was their message, their PSA or public safety announcement about the FBI breach. And I am gonna make fun of all the high school drama from all this cyber crime shenanigan crap. This is their leak site, though, and it's a little tough to read. Their site kind of sucks. There's a popup banner. Welcome. It's very simple. When you pay us, your data is deleted, and you move on with your life. When you don't pay us, you get posted here, among other things. Can I click out of this? Can I please? Oh my god. All right, it's finally gone. Now, I am going to redact all the other victims listed here on this leak site because that's real victim data, right? Just out of polite courtesy. The one that we care about is this PSA. Read this. Now, this also kind of sucks because it's a big long thing that we kind of got to scroll through. So, I'm going to try and take all of this out and just throw in a text editor for us to be able to read. And here is what the uh love letter says. Dear FBI, during quarter two of this year, the Federal Bureau of Investigation made substantial false allegations regarding our organization in a flash report. We have been severely offended. Oh. Oh, no. Did your little feelings get hurt? We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to disrupt our operations. An effort that ultimately proved unsuccessful. [laughter] For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that. We have compromised the FBI. We hold very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job. Whether it be a special agent or any other role within your agency, the following FBI services were compromised. criminal justice, HR, Medlink, and more. Once again, that aligns with the 5,000line sample that uh I've received. And there is the listing of their individual job titles and their role in the FBI. Again, obviously not getting into specifics of the data, but there are maybe roughly a thousand individually named special agents and intelligence analysts and all the other specific roles in the organization. even just this slice of the data that they had. While there's no way for me to confirm beyond the sample that I have, the articles reporting on this from the journalists that reached out to Shiny Hunters to talk with them said that they told him, "Hey, they have two terabytes or three terabytes of data. The sample that I have is like one meg." Anyway, back to Shiny Hunters like long whiny monologue. This is where it gets banana town. We're willing to allow you a time of 1 week to correct or simply remove the 2026 quarter 2 flash report on us that includes several false allegations. Wait, you couldn't have just like deleted it yourself? You said you had all this access and you defaced the website, but you you didn't do what you wanted in the first place. This is the reference report from the FBI uh Q2 of 2026 on shiny hunters. And this was after the instructure and like canvas hack, but they discuss the damage that shiny hunters did and they talked through it. So we will put these maybe side by side and we'll do a sweet exercise in reading comprehension. So shiny hunters temper tantrum on the lefth hand side, FBI report on the right hand side. They were whining about threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. I mean that's just true. Uh I see that right there. I think the point that Shiny Hunters is trying to make when they say, "Oh, we wish to state unequivocally our threats and claims are very real, not exaggerated and never a bluff. This PSA today is living evidence of that." Okay, Claude. To be clear, they put the line copy paste verbatim. Threat actors often use their real or exaggerated claims. So look, the ore is kind of putting that in place already. You guys know computers, right? Conditional zero or one. I think it already covers the case where it does say real access to sensitive or personal information, but whatever. Next formal complaint. To exert pressure on victims, SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members and in some cases swatting. For this one, they are upset and they say, "We wish to state unequivocally, we have never conducted swatting attacks against corporate victims personnel, nor have we ever texted victims personal family members any threats." I mean, okay. I I mean, I get it. I guess sure it wasn't strictly shiny hunters if you were trying to split hairs on that but obviously it still enables scams continued cyber crime against those victims when their data and leaked information is exposed. The threat to the general public is still real and you enabled it and it doesn't have to be individually you as a person or just specifically that group. Like look, they conveniently skip over the line of victims receive an extortion email signed to shiny hunters. Thread actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims that frequently do not exist. They state, "We have never claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. We are not extortionists, all caps." Sure, whatever. Maybe it's not individually you, Mr. or Mrs. Shiny Hunter. But if we kind of go back in time, and I know what they're getting at here, Sextorion scammers are exploiting the Shiny Hunters data leaks. I understand that if the Shiny Hunters is reading the FBI report, taking it literally that, oh, they're calling the Shiny Hunters the ones doing extortion or swatting. Sure, it's not you as the group, but other cyber criminals using your name from what you did. It doesn't make a difference to the rest of the world because the general populace needs to know what to look out for. If the sticking point is that other cyber criminals are using the name shiny hunters and that's not the real shiny hunters, WELL, AGAIN, THEY don't know who you are. The things that you're crying about don't matter because from the perspective of the general population that the FBI report is trying to get the word out for, you're just some abstract cyber crime entity. So being pedantic on you saying we wish to state unequivocally we're not part of the comm and that certainly would do much more of the swatting. For one thing, the FBI report doesn't even mention the comm. So if your hissyfitit is saying the comm is a propaganda started by the information security industry, it doesn't matter. It's a nickname. It's a way to refer to this vague amorphous threat that exists some way somehow. Just the same way that shiny hunters is a label that sure could be you or whatever other cyber criminal extortionist scammer that just uses the name and rides off the work that you did do. Anyway, as a big believer and supporter of the US Constitution, we are exercising the first amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Hang on, hang on, hang on. We are willing to allow you a time of one week to correct or simply remove this flash report. Oh, and that's not extortion, by the way. Not not not extortion. The extortion group's not doing extortion. Listen. All right. You go Google. You go take a look in the dictionary. You check out what extortion is. Oh, the illegal act of uh getting services from someone through threats, intimidation, or force. What else we got here? Oh, verbal or written threats of future harm or embarrassment. Oh, no. It's not extortion. because this PSA is not financially motivated. You only have a week to address our demands or else we'll, you know, publish all of your employees data and information, but it's not extortion. Reading on, we recognize that certain statements within your flash report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organization in attempt to disrupt our operations and hinder clients trust in our organization, hoping nobody pays us. That's a run-on sentence, my guy. We welcome any and all journalists to inquire us to hear our side of the story. [snorts] Gonna be honest with you cyber criminals. I don't give a about your side of the story. They say make the right decision. Sure sounds like a demand. Don't be the next headline. Sure sounds like a threat. I don't know about you. Sure sounds like extortion to me. That's extortion. But no, that's not extortion. This is not extortion according to the extortion group. Now, I would like to scroll through just a couple of the public reporting articles on this because they have a little bit more insight as to both what Shiny Hunters is saying and the most recent statement from the FBI themselves. I love the subtitle here. This time it's personal. The gang wants the feds to correct the record on how it operates. We don't want money. This is not financially motivated. We just want the FBI to correct or retract the statements they made, which include these substantial false allegations. According to Mr. or Mrs. to shiny hunter. The extortion group exploited an Oracle peopleoft zero day on the FBI jobs web page which said it allowed remote code execution on the servers. Now I have seen some folks talking about CVE 2026 35273. That's a vulnerability that hit the streets way back in June and that made news headlines and the whole world was aware shiny hunters was actively exploiting that in the Peopleoft software to the extent that SIZA America's cyber defense agency the cyber security infrastructure security agency added it to its known exploited vulnerabilities catalog which usually means there is a deadline to be able to patch and get this now corrected so your systems are not vulnerable now I can't say with any certainty I don't know, we don't know. But I don't believe that that specific CVE in the June timeline was used to compromise the FBI. I'm looking at this Bleeping Computer article from Lawrence Abrams, which is hands down my favorite write up on this because Lawrence had some comms with Mr. or Mrs. Shiny Hunter, and they said this is a new Oracle Peopleoft Zeroday vulnerability. And they state they are now using that same exploit or the zero day against other organizations. I can't speak with any authority on that. I don't want to pretend. I haven't dug into the old CVE or gotten Peopleoft set up for me to be able to experiment and learn. But this gets really funny. Let me go find the spot. I'll leave links below in the video description again if you'd like to read the full thing while I'm just kind of scrolling through it. But in the statement, Shiny Hunters gave the FBI one week to correct or remove the Flash report while claiming in the same sentence the demand was not financially motivated and was not extortion. When asked whether the group would release the allegedly stolen FBI data if the agency did not make the changes to the report, they responded, "No comment." Oh, you mean extortion. When Bleeping Computer asked Mr. or Mrs. Shiny Hunter were they concerned that this would lead to increased pressure from the US government to, you know, like apprehend and arrest them, they responded, "I don't care." which actually works really well because from their message and invitation. Oh, email us an inquire to hear our side of the story. From my perspective, I don't care. Oh, and then it gets into the pissing contest with Klopp. More drama. Shiny hunters breached and defaced Klopps, the ransomware gangs data leak site. Oh, I love this. Hang on. Let me go check out that article here. Oh, where is it? Where is it? Where is it? There's another like really funny tidbit that it just so perfectly juxtaposed right beside the current Yeah. Yeah. Yeah. Yeah. When Shiny Hunters was asked what they planned to do with Klopp's stolen information, the threat actor responded, "Going to extort them." Oh, but the FBI hack, the 3 TBTE data breach of all the employees and their information and their spouses. The thing with the oneweek demand to take action, but no comment on what we'll do if you don't. That's not extortion. Look, I'm not a cyber criminal, so maybe I don't know, but what the are you thinking? How stupid can you be? Let me state the obvious here, but for the cyber crime kidlets and the little Umbreon chasing shiny hunters, the FBI is going to ruin you when you're found. These kids will be steamrolled disclosing a database of law enforcement, special agent, field agents, and their spouses. Has to be one of the like riskiest dumb decisions I've ever seen. Listen, I want to wrap this up. I know this is still breaking news. I know it's still a developing story. There's still a timeline to this. But now that I have personally seen like the data sample, the 5,000 lines here, and that's just a tiny slice of what the full data is, and it is real, it does have FBI agent names, home addresses, social security numbers, assignments, and the names of their family members. But you'll continue to see folks saying, "Yeah, it it's legit." Obviously, data breaches like this do real damage. These hurt the people that are affected. There are real victims from a crime. and some threat actor group whining, complaining, throwing their temper tantrum because uh oh, their name is getting slandered does not matter. The damage done by that adversary is just going to continually be used by other adversaries, shiny hunter name or not. And the little kids doing this, what are you thinking? You have given law enforcement all the incentive in the world to take you down. I don't know what more to tell you right now. We'll see how this thing develops. Maybe in a week what changes after the 7-day timeline. Not extortion. [laughter] Shiny hunters. I I don't Look, maybe you want to practice a little bit. Get used to the feeling of handcuffs because they are going to want you behind bars.