Video summary
The video presents a developing story regarding a major data breach attributed to the cybercriminal group known as Shiny Hunters, who allegedly hacked the Federal Bureau of Investigation and compromised sensitive employee information. The narrator confirms that while the specific data samples shown are synthetic for safety, the breach is real and involves a massive dataset containing names, addresses, phone numbers, and details about the spouses of FBI agents and applicants. This incident marks a significant escalation in cybercrime, with Shiny Hunters—a group active since 2019 known for supply chain attacks and ransomware—claiming to have stolen terabytes of data from the FBI's job application portal and other internal systems. The breach has exposed critical personnel information, including social security numbers and assignments, which poses a severe threat not only to current agents but also to their families.
Upon accessing the group's leak site, Shiny Hunters issued a public safety announcement that frames their actions as a response to what they claim are false allegations made by the FBI in a recent flash report. In a lengthy monologue displayed on their website, the hackers demand that the FBI correct or remove these alleged inaccuracies within one week, asserting that their threats are not financially motivated and therefore do not constitute extortion. They specifically deny accusations of using swatting tactics or sending threatening messages to families, arguing that they are merely exercising their right to free speech and combating disinformation. However, the narrator points out the inherent contradiction in their stance, noting that holding data hostage until demands are met is the definition of extortion, regardless of whether money is explicitly requested.
The video critically analyzes the group's behavior, highlighting how their public complaints mirror tactics often used by scammers to deflect blame while simultaneously threatening victims with data leaks. The narrator expresses deep concern over the group's decision to target law enforcement agencies, arguing that leaking such sensitive information provides other criminals with a ready-made resource for identity theft and fraud. Furthermore, the group's attempt to breach the leak site of another notorious ransomware gang, Kloppe, is cited as evidence of their chaotic and dangerous nature. The narrator concludes that while Shiny Hunters may view themselves as victims of slander, their actions have given law enforcement a clear target and have already caused irreparable harm to thousands of individuals, making them a prime candidate for arrest once the FBI completes its investigation.
Read the full video transcript
Yesterday, there was breaking news that
the Federal Bureau of Investigations was
hacked and that all their employee data
was breached by a cyber criminal group
called Shiny Hunters. I've received a
sample of the breach data, but obviously
I can't show that to you. This is all
fake data. What I'm showing you here is
all synthetic data just so you get a
feel and can visualize what this looks
like because obviously I just can't show
you. But I can personally confirm after
going through and verifying the data
set, it looks legit. I've looked all
across public sources and other
information to validate and it's real.
Breached FBI data. So, this is still
breaking news and I want to tell you the
story. So, yesterday I was doom
scrolling on Twitter forward/x when I
saw this post from my good friend VxDB.
He says, "Shiny hunters just defaced the
FBI jobs page." You can see the picture
here, URL in the address bar.
apply.fbiji.gov.
This site has been seized by shiny
hunters. Down below, all FBI data was
compromised, including sensitive PII and
PHI on incumbent and former FBI
employees and all applicant information.
They say, "We have a lot more than what
we claim here. Thank you for your
attention to this matter, shiny
hunters." Now, I saw this fly by in the
morning around 9:53 Eastern time, and
VXDB later added another news article
that was uh discussing this further, but
I thought I was quick enough to tune
into this. I went to go check the FBI
apply site, and like 8 minutes after,
there's a Oh, we're sniffing out site
updates for you with scheduled
maintenance. If you were to go take a
look at the FBI jobs.gov website right
now, at least at the time recording, it
is a 503 service temporarily
unavailable. But soon after in the
morning yesterday, the news started to
break. I think, hey, shout out 404 media
was able to break the news on this. We
hacked the FBI. Hackers say they have
data on all FBI employees. And a sample
of 5,000 alleged agents include names,
addresses, phone numbers, and details
even on their employees spouses. That
5,000line sample of the full data set is
the data dump that I've received, by the
way, and it does include wives and
husbands and spouse information. So,
this is a wild situation, and you've got
everybody chirping about this thing. So,
I'm going to try and approach this video
in a couple different ways. I'd like to
read what Shiny Hunters has said, and I
want to see some of the other news and
commentary online and kind of give my
piece all throughout. In case you aren't
familiar, Shiny Hunters is a wildly
prolific cyber crime and hacking group.
So much so that they apparently even
have their own Wikipedia page. This says
they are an extortion group that's been
active since 2019. They've caused a
significant number of data breaches via
supply chain attacks, zeroday
exploitation of vulnerabilities, voice
and phone call fishing like social
engineering, and they exfiltrate data
like a data breach and demand a
ransomware payment or some other action.
If the targets don't pay the ransom, the
stolen information is often leaked or
sold on the dark web. Shiny Hunters is
believed to be affiliated with the comm,
a large international network of cyber
criminals. They like the he he hahas.
Getting a little bit of jokes with O
Umbreon as their logo and mascot of
shiny Pokemon from the Pokemon video
game, hence the name shiny hunters. I'll
leave a link to all this for you down
below. But if you take a look at the
notable data breaches here, let me zoom
out. They have done quite a bit of
damage. Some big names in here, of
course, some of the most recent ones, P
school, Canvas. Other ones that made
wild headline news were Snowflake,
Rockstar Games, and the most recent
addition, the FBI. So, let's jump onto
tour and try to connect to their dark
web leak site so that we could then see
what was their message, their PSA or
public safety announcement about the FBI
breach. And I am going to make fun of
all the high school drama from all this
cyber crime shenanigan crap. This is
their leak site, though. Hey, super
quick. Sponsor of today's video,
Minimal. It's no question that AI has
changed the security landscape. Faster
execution and all the wild superpowers
it gives you come from AI agents running
with full [music] access, which is
inherently a security risk. It's its
greatest strength and greatest weakness
that your robot is running around with
all of your user permissions, your SSH
keys, AWS credentials, browser cookies,
everything. So, Minimal finds the right
through line. Minimal is a hermetic
sandbox for AI agents. It's a single
Rust binary. No Docker Damon and no
virtual machine to configure. It takes
just one command and your AI agent only
gets the project that it needs to work
on and nothing else. That way you're not
living in YOLO mode and you're not one
mistake away from having your data
Xfilled or your dev box exploited.
Minimal makes every environment
reproducible and includes a software
bill of material for every system
dependency. Get the best of both worlds
between agent isolation and speed. Get
identical machine agnostic sandboxes
wherever you use AI. Get Minimal with my
link [music] below in the video
description. jh.live/minimal.
Huge thanks to Minimal for sponsoring
this video. So, let's jump onto tour and
try to connect to their dark webb leak
site so that we could then see what was
their message, their PSA or public
safety announcement about the FBI
breach. And I am gonna make fun of all
the high school drama from all this
cyber crime shenanigan crap. This is
their leak site, though, and it's a
little tough to read. Their site kind of
sucks. There's a popup banner. Welcome.
It's very simple. When you pay us, your
data is deleted, and you move on with
your life. When you don't pay us, you
get posted here, among other things. Can
I click out of this? Can I please? Oh my
god. All right, it's finally gone. Now,
I am going to redact all the other
victims listed here on this leak site
because that's real victim data, right?
Just out of polite courtesy. The one
that we care about is this PSA. Read
this. Now, this also kind of sucks
because it's a big long thing that we
kind of got to scroll through. So, I'm
going to try and take all of this out
and just throw in a text editor for us
to be able to read. And here is what the
uh love letter says. Dear FBI, during
quarter two of this year, the Federal
Bureau of Investigation made substantial
false allegations regarding our
organization in a flash report. We have
been severely offended. Oh. Oh, no. Did
your little feelings get hurt? We were
very disappointed to see an agency of
your standing would resort to such
circulation of disinformation in an
attempt to disrupt our operations. An
effort that ultimately proved
unsuccessful. [laughter] For us to
properly address and correct these
unfounded allegations, we were compelled
to adopt a forceful and assertive
posture to ensure our response was fully
acknowledged. This PSA today does just
that. We have compromised the FBI. We
hold very sensitive data on almost all
FBI agents and individuals who filed an
application with the FBI for a job.
Whether it be a special agent or any
other role within your agency, the
following FBI services were compromised.
criminal justice, HR, Medlink, and more.
Once again, that aligns with the
5,000line sample that uh I've received.
And there is the listing of their
individual job titles and their role in
the FBI. Again, obviously not getting
into specifics of the data, but there
are maybe roughly a thousand
individually named special agents and
intelligence analysts and all the other
specific roles in the organization. even
just this slice of the data that they
had. While there's no way for me to
confirm beyond the sample that I have,
the articles reporting on this from the
journalists that reached out to Shiny
Hunters to talk with them said that they
told him, "Hey, they have two terabytes
or three terabytes of data. The sample
that I have is like one meg." Anyway,
back to Shiny Hunters like long whiny
monologue. This is where it gets banana
town. We're willing to allow you a time
of 1 week to correct or simply remove
the 2026 quarter 2 flash report on us
that includes several false allegations.
Wait, you couldn't have just like
deleted it yourself? You said you had
all this access and you defaced the
website, but you you didn't do what you
wanted in the first place. This is the
reference report from the FBI uh Q2 of
2026 on shiny hunters. And this was
after the instructure and like canvas
hack, but they discuss the damage that
shiny hunters did and they talked
through it. So we will put these maybe
side by side and we'll do a sweet
exercise in reading comprehension. So
shiny hunters temper tantrum on the
lefth hand side, FBI report on the right
hand side. They were whining about
threat actors often use their real or
exaggerated claims of access to
sensitive or personal information to
prompt payment from victims. I mean
that's just true. Uh I see that right
there. I think the point that Shiny
Hunters is trying to make when they say,
"Oh, we wish to state unequivocally our
threats and claims are very real, not
exaggerated and never a bluff. This PSA
today is living evidence of that." Okay,
Claude. To be clear, they put the line
copy paste verbatim. Threat actors often
use their real or exaggerated claims. So
look, the ore is kind of putting that in
place already. You guys know computers,
right? Conditional zero or one. I think
it already covers the case where it does
say real access to sensitive or personal
information, but whatever. Next formal
complaint. To exert pressure on victims,
SH actors commonly use harassment
strategies, sending threatening text
messages and phone calls to victims and
their family members and in some cases
swatting. For this one, they are upset
and they say, "We wish to state
unequivocally, we have never conducted
swatting attacks against corporate
victims personnel, nor have we ever
texted victims personal family members
any threats." I mean, okay. I I mean, I
get it. I guess sure it wasn't strictly
shiny hunters if you were trying to
split hairs on that but obviously it
still enables scams continued cyber
crime against those victims when their
data and leaked information is exposed.
The threat to the general public is
still real and you enabled it and it
doesn't have to be individually you as a
person or just specifically that group.
Like look, they conveniently skip over
the line of victims receive an extortion
email signed to shiny hunters. Thread
actors may falsely claim to have
sensitive or compromising information,
including embarrassing photographs or
videos of victims that frequently do not
exist. They state, "We have never
claimed to have sensitive or
compromising information, including
embarrassing photographs and videos of
victims. We are not extortionists, all
caps." Sure, whatever. Maybe it's not
individually you, Mr. or Mrs. Shiny
Hunter. But if we kind of go back in
time, and I know what they're getting at
here, Sextorion scammers are exploiting
the Shiny Hunters data leaks. I
understand that if the Shiny Hunters is
reading the FBI report, taking it
literally that, oh, they're calling the
Shiny Hunters the ones doing extortion
or swatting. Sure, it's not you as the
group, but other cyber criminals using
your name from what you did. It doesn't
make a difference to the rest of the
world because the general populace needs
to know what to look out for. If the
sticking point is that other cyber
criminals are using the name shiny
hunters and that's not the real shiny
hunters, WELL, AGAIN, THEY don't know
who you are. The things that you're
crying about don't matter because from
the perspective of the general
population that the FBI report is trying
to get the word out for, you're just
some abstract cyber crime entity. So
being pedantic on you saying we wish to
state unequivocally we're not part of
the comm and that certainly would do
much more of the swatting. For one
thing, the FBI report doesn't even
mention the comm. So if your hissyfitit
is saying the comm is a propaganda
started by the information security
industry, it doesn't matter. It's a
nickname. It's a way to refer to this
vague amorphous threat that exists some
way somehow. Just the same way that
shiny hunters is a label that sure could
be you or whatever other cyber criminal
extortionist scammer that just uses the
name and rides off the work that you did
do. Anyway, as a big believer and
supporter of the US Constitution, we are
exercising the first amendment and
actively combating disinformation. This
is not a ransom, coercion, or extortion.
Hang on, hang on, hang on. We are
willing to allow you a time of one week
to correct or simply remove this flash
report. Oh, and that's not extortion, by
the way. Not not not extortion. The
extortion group's not doing extortion.
Listen. All right. You go Google. You go
take a look in the dictionary. You check
out what extortion is. Oh, the illegal
act of uh getting services from someone
through threats, intimidation, or force.
What else we got here? Oh, verbal or
written threats of future harm or
embarrassment. Oh, no. It's not
extortion. because this PSA is not
financially motivated. You only have a
week to address our demands or else
we'll, you know, publish all of your
employees data and information, but it's
not extortion. Reading on, we recognize
that certain statements within your
flash report appear to stem from biased
public reporting by certain journalists
who have previously and intentionally
propagated false narratives about our
organization in attempt to disrupt our
operations and hinder clients trust in
our organization, hoping nobody pays us.
That's a run-on sentence, my guy. We
welcome any and all journalists to
inquire us to hear our side of the
story. [snorts]
Gonna be honest with you cyber
criminals. I don't give a about
your side of the story. They say make
the right decision. Sure sounds like a
demand. Don't be the next headline. Sure
sounds like a threat. I don't know about
you. Sure sounds like extortion to me.
That's extortion. But no, that's not
extortion. This is not extortion
according to the extortion group. Now, I
would like to scroll through just a
couple of the public reporting articles
on this because they have a little bit
more insight as to both what Shiny
Hunters is saying and the most recent
statement from the FBI themselves. I
love the subtitle here. This time it's
personal. The gang wants the feds to
correct the record on how it operates.
We don't want money. This is not
financially motivated. We just want the
FBI to correct or retract the statements
they made, which include these
substantial false allegations. According
to Mr. or Mrs. to shiny hunter. The
extortion group exploited an Oracle
peopleoft zero day on the FBI jobs web
page which said it allowed remote code
execution on the servers. Now I have
seen some folks talking about CVE 2026
35273.
That's a vulnerability that hit the
streets way back in June and that made
news headlines and the whole world was
aware shiny hunters was actively
exploiting that in the Peopleoft
software to the extent that SIZA
America's cyber defense agency the cyber
security infrastructure security agency
added it to its known exploited
vulnerabilities catalog which usually
means there is a deadline to be able to
patch and get this now corrected so your
systems are not vulnerable now I can't
say with any certainty I don't know, we
don't know. But I don't believe that
that specific CVE in the June timeline
was used to compromise the FBI. I'm
looking at this Bleeping Computer
article from Lawrence Abrams, which is
hands down my favorite write up on this
because Lawrence had some comms with Mr.
or Mrs. Shiny Hunter, and they said this
is a new Oracle Peopleoft Zeroday
vulnerability. And they state they are
now using that same exploit or the zero
day against other organizations. I can't
speak with any authority on that. I
don't want to pretend. I haven't dug
into the old CVE or gotten Peopleoft set
up for me to be able to experiment and
learn. But this gets really funny. Let
me go find the spot. I'll leave links
below in the video description again if
you'd like to read the full thing while
I'm just kind of scrolling through it.
But in the statement, Shiny Hunters gave
the FBI one week to correct or remove
the Flash report while claiming in the
same sentence the demand was not
financially motivated and was not
extortion. When asked whether the group
would release the allegedly stolen FBI
data if the agency did not make the
changes to the report, they responded,
"No comment." Oh, you mean extortion.
When Bleeping Computer asked Mr. or Mrs.
Shiny Hunter were they concerned that
this would lead to increased pressure
from the US government to, you know,
like apprehend and arrest them, they
responded, "I don't care." which
actually works really well because from
their message and invitation. Oh, email
us an inquire to hear our side of the
story. From my perspective, I don't
care. Oh, and then it gets into the
pissing contest with Klopp. More drama.
Shiny hunters breached and defaced
Klopps, the ransomware gangs data leak
site. Oh, I love this. Hang on. Let me
go check out that article here. Oh,
where is it? Where is it? Where is it?
There's another like really funny tidbit
that it just so perfectly juxtaposed
right beside the current Yeah. Yeah.
Yeah. Yeah. When Shiny Hunters was asked
what they planned to do with Klopp's
stolen information, the threat actor
responded, "Going to extort them." Oh,
but the FBI hack, the 3 TBTE data breach
of all the employees and their
information and their spouses. The thing
with the oneweek demand to take action,
but no comment on what we'll do if you
don't. That's not extortion. Look, I'm
not a cyber criminal, so maybe I don't
know, but what the are you thinking? How
stupid can you be? Let me state the
obvious here, but for the cyber crime
kidlets and the little Umbreon chasing
shiny hunters, the FBI is going to ruin
you when you're found. These kids will
be steamrolled disclosing a database of
law enforcement, special agent, field
agents, and their spouses. Has to be one
of the like riskiest dumb decisions
I've ever seen. Listen, I want to wrap
this up. I know this is still breaking
news. I know it's still a developing
story. There's still a timeline to this.
But now that I have personally seen like
the data sample, the 5,000 lines here,
and that's just a tiny slice of what the
full data is, and it is real, it does
have FBI agent names, home addresses,
social security numbers, assignments,
and the names of their family members.
But you'll continue to see folks saying,
"Yeah, it it's legit." Obviously, data
breaches like this do real damage. These
hurt the people that are affected. There
are real victims from a crime. and some
threat actor group whining, complaining,
throwing their temper tantrum because uh
oh, their name is getting slandered does
not matter. The damage done by that
adversary is just going to continually
be used by other adversaries, shiny
hunter name or not. And the little kids
doing this,
what are you thinking? You have given
law enforcement all the incentive in the
world to take you down. I don't know
what more to tell you right now. We'll
see how this thing develops. Maybe in a
week what changes after the 7-day
timeline. Not extortion. [laughter]
Shiny hunters. I I don't Look, maybe you
want to practice a little bit. Get used
to the feeling of handcuffs because they
are going to want you behind bars.