// 1 ZERO-DAY IN THE LAST 24H→
ShinyHunters posted a retaliatory statement against the FBI over a May 15, 2026 report. The group denies swatting and sextortion allegations and claims data on nearly all FBI agents and job applicants.

Editor's note: This article is based on a single structured primary source (Malwarebytes). Quotes attributed to 404 Media originate from that source and have not been independently verified.

On September 23, 2026, the criminal group ShinyHunters published a statement on its leak site claiming an attack on the FBI. The stated motive is retaliation: the group contests a May 15, 2026 report by the FBI and IC3 containing what it calls "false allegations."

The episode inverts the traditional threat intelligence dynamic. The criminal does not merely steal data but uses the leak site as a platform to publicly dispute its own classification by a federal agency.

Key Takeaways
  • ShinyHunters published a statement on its leak site on September 23, 2026 claiming an FBI breach and a one-week ultimatum to remove an FBI/IC3 report.
  • The group denies three allegations in the report: threat exaggeration, swatting and threats to victims' family members, and sextortion.
  • According to Malwarebytes, 404 Media reportedly verified portions of a sample containing approximately 5,000 FBI agents with names, home addresses, phone numbers, and spouse details.
  • The FBI confirmed it is "aware" of claims of unauthorized activity on FBIjobs.gov and is investigating, but has not confirmed a breach or data exfiltration.
  • The group claims to have compromised four FBI services: Criminal Justice (CJ), HR, Medlink, and others.

The Statement: Structure and Recipients

The statement is addressed to Assistant Director Brett Leatherman of the FBI Cyber Division and Director Kash Patel. The group claims to have compromised services named Criminal Justice (CJ), HR, Medlink, and others.

The data in the group's possession allegedly concerns "nearly ALL FBI agents and individuals who have applied for a job with the FBI." The cited document is identified as a "2026 Quarter 2 FLASH report," though the source associates it with the public FBI/IC3 PSA of May 15, 2026.

ShinyHunters gives the FBI one week to "correct or simply REMOVE" the report. It specifies the demand "is NOT financially motivated."

"During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended." — ShinyHunters, leak site statement, September 23, 2026

ShinyHunters' Denials: Swatting, Threats, and Sextortion

The group rejects three specific allegations. The first concerns threat exaggeration. The second is the most detailed denial: "we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats."

The third appears in all caps in the original text: "WE ARE NOT SEXTORTIONISTS." These denials, published on a leak site traditionally used to sell stolen data, represent an instrumental use of the platform.

The group transforms a criminal monetization channel into a direct communication tool with a government agency. The source does not independently verify the truth of the denials, nor that of the FBI's original allegations.

Partial Sample Verification and Source Limitations

According to Malwarebytes, the group provided 404 Media with a sample containing approximately 5,000 records. The same source reports that 404 Media "reportedly verified portions of the sample," finding names, home addresses, phone numbers, and spouse details of agents.

This verification was not conducted directly by Malwarebytes nor reproduced by other outlets in the dossier. The statement also includes a claim of defacing FBIjobs.gov, though the source does not document whether such defacement is technically linked to the alleged data breach.

When contacted, the FBI responded it is "aware of claims involving unauthorized activity affecting FBIjobs.gov and is investigating." It has confirmed neither the breach nor the exfiltration.

Denial of Links to "The Com"

The statement addresses a second theme: the denial of any connection to "The Com." ShinyHunters calls this association "propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense."

This denial sits in a broader context. A November 2025 source reported the alleged merger of ShinyHunters with Scattered Spider/LAPSUS$ and links to "The Com," while noting there may have been legacy name appropriation without evidence of formal organization. That source does not cover the FBI event of September 23, 2026.

Why This Matters

The case shows how leak sites have acquired a function that transcends mere data commerce. When a criminal group addresses a statement to specific FBI leadership names, denies allegations point by point, and sets a deadline for removal of a government document, the confrontation shifts to the plane of public communication.

The one-week ultimatum and the demand to remove the FBI/IC3 report are elements the source does not qualify as measurable technical parameters. The group declared the statement "is NOT financially motivated" and invited journalists to contact it.

The FBI's response, phrased as "aware of claims," neither confirms nor denies the compromise. This formulation, reported by Malwarebytes, leaves open the question of the veracity of ShinyHunters' claims.

What Changes

The September 23, 2026 statement introduces a variant in the relationship between threat actors and institutions. The leak site becomes a vehicle for political contestation, not just data sales.

The group lists four compromised services: Criminal Justice (CJ), HR, Medlink, and others. It claims to hold data on "nearly ALL FBI agents and individuals who have applied for a job with the FBI." These assertions are not independently confirmed.

The sample of approximately 5,000 records, with the partial verification reported by Malwarebytes via 404 Media, does not prove the overall scale of the alleged compromise. The FBI has not confirmed the exfiltration of sensitive agent data.

The primary source does not document intrusion techniques, indicators of compromise (IoCs), or operational timelines. The dossier is limited to reporting the statement's content and the institutional response, without independent verification of the breach.

Information is based on the cited source and current as of publication.

Sources


Sources and references
  1. malwarebytes.com
  2. thehackernews.com