Cybersecurity · Wednesday, 23 September 2026
A hacking gang says it broke into the FBI's jobs website and took files on its staff. It wants a warning withdrawn, not money.
ShinyHunters defaced the FBI's recruitment site and says it copied 2 to 3 terabytes of data on employees and applicants. The FBI says only that it is investigating, and nobody outside the gang has checked the data.
2 to 3 TB
of FBI data the gang says it copied, about staff, former staff and job applicants
No outside party has checked the claim.
1 week
the deadline the gang gave the FBI to act on its May warning
It asked for no ransom and made no direct threat to leak.
15 May
the date of the FBI warning the gang wants withdrawn
It said the gang harasses victims and their families.
The lead story — what happened
-
ShinyHunters, a gang that steals data from companies and threatens to publish it unless paid, says it broke into the FBI's jobs website on Monday night.
[1] [4] -
On Tuesday the site showed the gang's banner, saying it had been seized. It now shows a maintenance message.
[2] [3] -
The FBI said only that it is aware of claims about unauthorised activity on FBIjobs.gov and is investigating.
[4] [3] -
The gang says it got in through a flaw nobody knew about in Oracle PeopleSoft, business software used for hiring and staff records. No details of such a flaw have been published.
[1] [3] -
It says it then moved from the jobs site into FBI computers on Amazon's government cloud and copied 2 to 3 terabytes of data.
[1] [2] -
It claims to hold data on almost all FBI agents and on everyone who applied for an FBI job, including health details.
[3] [1] -
The Verge, citing the news site 404 Media, says the data reportedly includes phone numbers, home addresses, dates of birth and, in some cases, details of spouses.
[5] -
The gang sent BleepingComputer two sample records, one said to belong to FBI Director Kash Patel. The site did not publish them and has not checked they are real.
[1] -
The gang says it wants no money. It told The Register the attack was not about money at all.
[2] -
It wants the FBI to withdraw a warning from 15 May. That warning said the gang harasses victims and their families, and often falsely claims to hold embarrassing material.
[2] -
The FBI issued that warning after the gang broke into Canvas, a school coursework platform run by Instructure, and urged victims not to pay.
[3] [4] -
The gang gave the FBI one week to act but made no direct threat to publish the data.
[4] -
It also says it is using the same flaw against other organisations, including some of the 500 largest US companies.
[1] -
Cynthia Kaiser, a former FBI cyber official now at the security firm Halcyon, said gangs that shame police in public have historically ended in takedowns or defections.
[4]
Who is involved
-
ShinyHunters
a gang that steals company data and demands money not to publish it; it claims the FBI break-in
-
The FBI
the US federal police force, which investigates data-theft gangs; it says it is investigating the claims
-
Kash Patel
the FBI's director; one sample record the gang shared is said to be his
-
Oracle
a US business software maker whose PeopleSoft the gang says it broke through; it did not answer questions
How it unfolded
-
May the gang breaks into Canvas, a school coursework platform
[2] -
15 May the FBI warns about the gang and urges victims not to pay
[2] [3] -
June the gang uses an earlier PeopleSoft flaw against companies
[3] -
Mon 21 Sep the break-in, by the gang's own account
[1] -
Tue 22 Sep the jobs site is defaced; the FBI says it is investigating
[4] [5]
Where this points
Watch whether the FBI confirms any data was taken, and whether any of it appears online once the gang's one-week deadline passes.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
EvilTokens, an inbox-theft service, charged $1,500 to join and $500 a month.
Zyxel fixed a flaw in its network switches in June, and one group still took data from 996 of them from August.
Attackers used a key belonging to Ribon, an online-store add-on, to download shoppers' details for four days.
A judge in Los Angeles signalled he would reject part of TikTok's $400 million privacy settlement.
The rest of the day
20 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Microsoft shuts a rented inbox-theft service
Microsoft said on Tuesday that it had shut down EvilTokens, a service criminals rented to break into Microsoft work email accounts.
[9] It says the service reached more than 12,000 inboxes at more than 10,000 organisations since February.[6] Customers paid $1,500 to join and $500 a month, and about 1,000 criminals used it.[7] [6] Victims were tricked into typing a code into Microsoft's real sign-in page, which handed the attacker a working session without needing the password.[10] [8] London police arrested two men suspected of running it, and both are on bail.[7] [8] $1,500To join EvilTokens$500Every month after thatWhat a criminal paid to use EvilTokens, according to Microsoft. Why it matters — The service had an AI chatbot that read each stolen inbox to find who approves payments, then drafted fake messages to them.
[6] At least ten other services offered the same code trick by April, so its customers have other places to go.[8] -
03
Shoppers' details taken through a store add-on
BigCommerce, which hosts online shops for other businesses, has told some of its merchants that customer data was taken.
[12] Attackers stole an access key held by Ribon, an add-on that Master of Malt says was installed on hundreds of BigCommerce stores.[11] They used it from 13 to 17 September to download shoppers' names, emails, phone numbers and addresses.[11] Master of Malt, a UK online drinks seller, is one shop hit.[12] BigCommerce removed the add-on and says passwords and card numbers are kept separately and were not reached.[12] Why it matters — The shops were not broken into themselves: the key belonged to a helper app they had installed.
[11] The key kept working for a day after Ribon's developers learned it was being misused.[11] -
04
One group turned old flaws on 996 switches
GreyNoise, a firm that runs internet sensors to watch attacks, says a Chinese-speaking group took data from 996 network switches made by Zyxel, in 48 countries.
[13] A switch is the box that links the computers in an office. The same group broke into at least 49 organisations in 29 countries through a WordPress flaw.[13] At one unnamed Western government body it took 18,566 database records.[13] Zyxel had fixed the switch flaw on 16 June.[14] Why it matters — Every flaw in this campaign already had a public fix, and the victims had not installed it.
[13] [14] The US cyber-defence agency, CISA, has now ordered federal agencies to update their Zyxel switches.[14] -
05
A fifth spy group used the same browser attack
Volexity, a US security firm, said on Monday that a China-aligned spy group it calls UTA0565 used a chain of three unknown flaws in Chrome and Windows on 3 and 4 September.
[15] Other firms had already tied the same chain to four other Chinese groups.[15] UTA0565 lured victims with fake websites and with emails asking Asian government staff to support Chow Hang-tung, a jailed Hong Kong activist.[15] Microsoft disclosed the Windows flaw on 8 September.[15] Why it matters — Volexity says the attack kit was probably shared among Chinese hacking groups.
[15] It also says the reports so far come from only two firms, so the real reach is likely wider.[15] -
06
Working attacks published for four Linux flaws
Researcher Asim Manizada published working attack code on 18 September for four flaws in the Linux kernel, the core of the system most servers run on.
[16] Each flaw lets someone with an ordinary account take full control of the machine.[16] He reported them in mid-July and waited until Linux distributors had shipped the fixes.[16] No attacks using them have been reported so far.[16] Why it matters — A server with an up-to-date kernel is safe, and one running an older kernel now faces code anyone can copy.
[16] The risk is highest on shared machines where many people have accounts.[16] -
07
A SharePoint flaw was worse than its label
A researcher at Viettel Cyber Security has shown that a flaw in SharePoint Server, Microsoft's software for company intranets and shared files, lets a logged-in attacker run their own code on the server.
[17] Microsoft's advisory had called it a spoofing flaw, rated 6.5 out of 10.[17] A separate Microsoft record, updated on 11 September, calls it code execution, and the US national flaw database scores it 8.8.[17] The fix came out on 11 August.[17] Why it matters — Teams that sorted their updates by Microsoft's advisory saw a moderate problem.
[17] The researcher says SharePoint 2013, which gets no more updates, is also affected.[17] -
08
Defender's harshest critic gives his name
The researcher known as Nightmare Eclipse has spent months publishing ways to break Microsoft Defender, the antivirus built into Windows.
[18] He has now named himself as Abdelhamid Naceri.[18] He says Microsoft fired him without a clear reason and that a German labour court upheld the dismissal.[18] Over the weekend he released BigDiskBuster, which stops Defender from installing its updates.[18] Why it matters — Each release gives attackers a working method before Microsoft has a fix.
[18] The account of his dismissal is his own.[18] -
09
Judge balks at part of TikTok's $400m deal
A US federal judge in Los Angeles, George Wu, said on Friday he was inclined to reject part of TikTok's $400 million settlement over children's privacy.
[19] The US Justice Department sued TikTok and its Chinese owner ByteDance in 2024 for collecting data from under-13s without parents' consent.[19] TikTok would pay $300 million now, and $100 million more if the court ended a 2019 order that makes it keep records until 2029.[19] Wu set a hearing for Monday.[19] Why it matters — The US government says TikTok has changed owners and privacy practices since the suit was filed.
[19] The judge said he could not yet tell whether those changes would last.[19] -
10
US prosecutors look at Binance over Iran
Federal prosecutors in Manhattan are investigating whether Binance, the world's largest cryptocurrency exchange, broke US sanctions on Iran by failing to stop certain trading, Bloomberg News reported on Monday.
[20] Binance said it has zero tolerance for sanctions breaches and cooperates with law enforcement.[20] In 2023 its founder, Changpeng Zhao, stepped down and pleaded guilty to breaking US money-laundering laws in a $4.3 billion settlement.[20] The US Justice Department declined to comment.[20] Why it matters — The report rests on unnamed sources, and no charge has been filed.
[20] Earlier this month the US government sanctioned firms it says help groups backed by Iran.[20] -
11
Lawsuits follow a law firm's break-in
Greenberg Traurig, a US law firm with more than 3,200 lawyers, faces a second proposed class action over a break-in in August.
[21] The newest suit, filed on Sunday, says the firm failed to protect names, Social Security numbers and contact details.[21] Four other people sued earlier in September.[21] The firm has said its own systems were not breached, and that an outsider reached a limited number of documents and posted them on the dark web.[21] Why it matters — A notice sent to one person in California shows dates of birth and Social Security numbers were involved.
[21] Two other big law firms, Quinn Emanuel and Herbert Smith, have also reported breaches in recent weeks.[21] -
12
Banks set out rules for AI shopping agents
A group of banks including NatWest, Bank of America, ING and Capital One warned on Tuesday that AI agents that shop for people could raise the risk of scams and fraud.
[22] Tech firms such as OpenAI, Google and Meta are promoting chatbots that choose and buy products.[22] The banks' report names risks such as an agent asking for card details and typing them into websites.[22] They want it disclosed whenever an agent is involved in a payment.[22] - 1A year ago0.3%
- 2September 20262.5%
Share of John Lewis website searches that came from AI agents. Why it matters — John Lewis, a British department store chain, says searches coming from AI agents rose from 0.3% to 2.5% in a year.
[22] The banks say customers do not know who protects them if an agent spends wrongly.[22] -
13
LinkedIn wins an end to mass profile copying
A US federal judge in California on Thursday finalised a deal that requires two software firms, ProAPIs and Netswift, to stop copying data from LinkedIn, the work networking site.
[23] LinkedIn sued last October, saying the firms ran millions of fake accounts to copy profiles, posts and comments.[23] LinkedIn blocked each fake account within hours, but hundreds or thousands of new ones appeared every day.[23] The firms must also delete what they took.[23] Why it matters — Blocking accounts one at a time could not keep up, so the fix came through a court.
[23] ProAPIs says it does not offer tools to copy LinkedIn data.[23] -
14
3.2 million Burger King Russia customers listed
Have I Been Pwned, a free website where people check whether their email appears in a leak, has added 3.2 million Burger King Russia customers.
[24] The data comes from an August 2024 attack on Mindbox, the chain's marketing supplier, and reaches back to May 2018.[24] Burger King told Russia's TASS news agency that payment details were not included.[24] Detsky Mir, Russia's biggest toy retailer, was reportedly hit by the same attack.[24] Why it matters — The attack was on a supplier, not on Burger King itself.
[24] Two years later, the people in the leak can now look themselves up.[24] -
15
Canada opens a privacy probe into IDScan
Canada's privacy commissioner, Philippe Dufresne, has opened an investigation into IDScan.net, a company whose tools check ID cards in shops, bars and hotels.
[25] Reports say attackers stole data and driving licence scans for 153 million people.[25] IDScan confirmed a break-in on 4 September but did not say how many people it hit.[25] The probe will look at its security and whether it told victims properly.[25] Why it matters — IDScan learned of the theft hours after the journalist Brian Krebs reported the scans were for sale online.
[25] -
16
Password thieves now take AI helpers' keys
Gen Digital, the company behind Norton antivirus, says two password-stealing programs, Amatera and Remus, now also copy data from AI coding assistants.
[26] Remus goes after files from Claude, Cursor and OpenCode, and Amatera after Cline and Continue.[26] Those files can hold login keys, saved passwords for connected tools and the history of what the developer asked.[26] Gen says its figures count detections, not confirmed infections.[26] Why it matters — Gen says one stolen folder can give an attacker both a way into an account and notes on what is valuable inside it.
[26] -
17
Attack tools rented by the month
Several criminal tools described by security firms this week are sold by monthly subscription.
[26] VectraRAT, which lets a buyer secretly control a Windows computer and record what is typed, costs $250 a month, the firm SOCRadar says.[26] Sophos found Luciferus, an AI chatbot with its safety limits removed, advertised on a crime forum for $35 a month.[26] EvilTokens, shut down this week, charged $500 a month.[7] Luciferus, an AI chatbot with no limits$35VectraRAT, a remote-control kit$250EvilTokens, an inbox-theft service$500Monthly prices of three criminal tools, in US dollars. EvilTokens also charged $1,500 to join. Why it matters — A buyer does not need to know how to build any of it.
[26] That is how one service, EvilTokens, could serve about 1,000 criminals at once.[6] -
18
Gaming videos used to hand out malware
Palo Alto Networks' Unit 42 research team says a group it calls CL-CRI-1171 has run a hidden marketplace for at least two years, spreading other criminals' malware for a fee.
[26] It used YouTube channels with real gaming content whose links led to infected downloads.[26] A second route used fake software placed high in search results, aimed at office workers.[26] Unit 42 says infections reached companies, critical infrastructure and government bodies.[26] Why it matters — The videos were genuine and the channels chatted with viewers, which made the download links look safe.
[26] -
19
New botnet guesses its way into devices
Nozomi Networks, a firm that protects factory and device networks, describes KATARU, new malware that breaks into Linux machines and small connected devices by guessing Telnet passwords.
[26] Telnet is an old way of logging in to a machine remotely. Once inside, KATARU uses already-published Linux flaws to take full control, then waits for orders to flood websites with traffic.[26] Nozomi suspects it was put together with help from AI.[26] Why it matters — It needs no new flaw at all: weak passwords and devices that were never updated are enough.
[26] -
20
Eight years for making cash machines pay out
A US court sentenced Juan Manuel Gouveia-Aguilera, a 27-year-old from Venezuela, to eight years in prison for his part in attacks that made cash machines hand out money.
[26] The gang used Ploutus, malware loaded onto the machine itself, a crime known as jackpotting.[26] The court held him responsible for more than $3.5 million in losses.[26] US prosecutors say it is believed to be the longest federal sentence yet for a role in jackpotting.[26] Why it matters — He was convicted of bank fraud, bank burglary and computer fraud after pleading guilty, and must also repay money.
[26] -
21
US agencies publish rules for guarding login passes
NIST, the US standards agency, and CISA, the US cyber-defence agency, have published final guidance on protecting the signed tokens behind single sign-on.
[27] A token is a small digital pass that proves someone has already logged in, so they are not asked again. The report tells federal agencies and cloud providers how to check tokens, guard the secrets that sign them and spot misuse at scale.[27] Why it matters — EvilTokens worked by getting victims to hand attackers exactly this kind of pass.
[8]
Why a gang that wants to be believed breaks into a website everyone can see
The FBI told victims in May that this gang's threats are often empty, so the gang answered by defacing the FBI's own jobs site in public.
The twist
The FBI's warning did not stop the gang stealing. It made victims doubt the gang, and doubt costs an extortion gang money. So the gang put its proof on the FBI's own website, where anyone could see it.
The picture
How it works
- A gang says it holds stolen files and will publish them
- Victims pay only if they believe that threat
- In May the FBI told victims these threats are often empty
- Fewer victims believe the gang, so fewer pay
- The gang breaks into a page anyone can check
- The public proof makes its bigger claims sound true
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
Nightmare Eclipse's new Defender attack
A researcher who says Microsoft fired him unfairly publishes working attacks on its antivirus, not just complaints, and each one is something Microsoft has to answer.
-
The SharePoint flaw that was worse than its label
Microsoft's advisory called it a moderate spoofing flaw. The researcher published an attack that runs code on the server, which is much harder to leave for later.
-
The EvilTokens arrests
London police did more than warn about rented phishing services. They arrested two suspected operators while Microsoft seized 50 of the service's websites, so the next warning comes with proof behind it.
Where you've seen this
Kidnappings
a photo proving the hostage is alive is what makes a family take the ransom demand seriously
Strikes
a union's strike vote shows the employer the walkout is real before a single day is lost
Science
a result is believed once another lab repeats it, not when the first lab announces it
The catch
Proof can be partial or staged. A defaced page shows the gang reached one website, not that it holds data on every agent, and nobody outside the gang has checked its two sample records.
And the whole of it
FBI staff, job applicants, companies weighing a ransom and police deciding what to warn about are all judging the same claims with only part of the evidence. Nobody outside the gang can yet say what is in its files, and that includes us.
What is really going on
ShinyHunters says it broke into the FBI's jobs website and took data on staff and job applicants, and the FBI has said only that it is investigating.
Why it works on us — A defaced page is something anyone can see, so it makes the much bigger claim behind it, data on almost every FBI agent, feel proven when nobody outside the gang has checked it.
Who gains
-
ShinyHunters
— Analysts at Flashpoint told CyberScoop that the attack bolsters the gang's reputation as a credible threat, which is what makes victims pay.
[4] -
Microsoft
— Its court-backed seizure of 50 EvilTokens websites removed a service used against its own customers' email accounts.
[6] -
LinkedIn
— The court deal forces ProAPIs and Netswift to stop copying its members' data and to delete what they took.
[23] -
People suing Greenberg Traurig
— Two proposed class actions seek to speak for thousands of people whose data the firm held, and the newest was filed on Sunday.
[21] -
Canada's privacy regulator
— Its IDScan probe will test whether a company that checks ID cards told the people affected properly.
[25]
Who pays
-
FBI employees and job applicants
— If the claim is true, their home addresses, birth dates and some spouses' details are in a criminal gang's hands.
[5] -
Master of Malt's customers
— Their names, emails, phone numbers and addresses were downloaded through an add-on key the shop did not control.
[12] [11] -
Owners of machines that were never updated
— One group took data from 996 Zyxel switches with a flaw fixed in June, and working code now exists for four Linux flaws on older kernels.
[13] [16] -
Workplaces hit through EvilTokens
— More than 12,000 inboxes at over 10,000 organisations were opened, and the service helped criminals plan payment fraud from what it found.
[6] -
Burger King Russia's customers
— 3.2 million records from a 2024 attack on its marketing supplier can now be searched by anyone.
[24]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Whether the gang really holds data on FBI staff and applicants.
BleepingComputer has not verified the two sample records it was sent, and the FBI has said only that it is investigating.
[1] [4] -
02
Whether there is a new, unfixed flaw in Oracle PeopleSoft, and who else is exposed to it.
No details of such a flaw have been published, Oracle did not answer questions, and the gang's claim to be using it on large US companies is its own.
[3] [2] [1] -
03
When the two EvilTokens suspects were arrested, and how many of its web addresses were taken down.
The Hacker News gives 11 September for the arrests, while The Record says police carried out the warrants last Friday.
[9] [7] CyberScoop counts more than 175 disabled domains and Dark Reading more than 150.[6] [10] -
04
How many shoppers' details were taken through the Ribon add-on.
BigCommerce speaks of a small number of storefronts, Master of Malt says the add-on was on hundreds of stores, and neither gives a count of people.
[12] [11] -
05
What Judge Wu decided at Monday's TikTok hearing.
His view on Friday was only a tentative one, and no report of the hearing was available to us.
[19] -
06
Whether Binance knowingly allowed trading linked to Iran.
The report rests on unnamed people cited by Bloomberg News, the Justice Department declined to comment and no charge has been filed.
[20] -
07
How many people Greenberg Traurig's break-in reached.
The firm says it told a small number of clients, while the newest lawsuit speaks of thousands of people.
[21] -
08
Whether the four Linux flaws with published attack code are being used by criminals yet.
No attacks have been reported so far, but the code is public and older kernels remain in use.
[16]
Microsoft and its partners shut down EvilTokens, a service criminals rented to break into about 12,000 work email inboxes. London police arrested two men suspected of running it.
Also true today
- Linux kernel maintainers fixed four flaws that let an ordinary user take full control of a machine, before the researcher who found them published his attack code.
- A US federal judge finalised a deal that requires two firms to stop copying LinkedIn members' profiles through fake accounts and to delete what they took.
- A Venezuelan man was sentenced to eight years in a US prison for making cash machines hand out money, which prosecutors believe is the longest federal sentence yet for that crime.
More from Cybersecurity
Across the beats