ShinyHunters Hacked the FBI’s Jobs Site. What Does Its Attack Spree Reveal?
In May, the FBI warned the public about ShinyHunters after the group claimed an attack on Canvas, a learning platform used by schools and universities. Students and educators across the country lost access, some in the middle of final exams.
Four months later, the FBI was warning its own employees. ShinyHunters claimed it had stolen sensitive data from the bureau’s jobs site and called the hack payback for that May warning. An internal memo said officials were assuming every FBI employee’s information had been exposed.
The FBI breach was the loudest of several attacks that month. ShinyHunters also claimed to have seized the dark web site of Cl0p, a rival extortion group, and turned it into an extortion target. Meanwhile, Google threat researchers documented a renewed campaign against companies and schools using Oracle PeopleSoft.
Then the FBI spoke to the hackers directly. On September 29, after Dutch police arrested a man the FBI called “one of the alleged leaders” of ShinyHunters, FBI Assistant Director Brett Leatherman posted a blunt video message: “You know how to find us, and we know how to find you.”
While ShinyHunters’ recent attacks have put it in the spotlight, the lesson for defenders is familiar: an attacker can get in by using sophisticated social engineering, a cloud app, or a software vulnerability. But what happens next depends on the access and connections available after the first foothold. ShinyHunters’ cyberattacks over the last several years show why organizations need to identify open ports, limit lateral movement, and contain suspicious activity before a single compromise can spread.
Who is behind ShinyHunters?
ShinyHunters first became known in 2020 for stealing and selling large amounts of customer data. Today, it’s part of a loose network of cybercriminals whose partnerships and tactics cross borders. Google Threat Intelligence Group tracks several clusters tied to the ShinyHunters brand of extortion. Researchers have also found overlapping tactics and signs of collaboration with Scattered Spider. That includes voice phishing, or vishing, calls that impersonate IT support to get into cloud apps. These overlaps blur the lines between threat groups. That makes it harder to tell who carried out an attack.
The FBI warns that ShinyHunters can pressure victims and their families with threats and, sometimes, false emergency calls that send police to their homes. The group may also exaggerate its access or the amount of data stolen.
Timeline of ShinyHunters' attacks
- 2020: ShinyHunters gained attention by selling large sets of stolen data. These included records from Tokopedia and Unacademy, an education platform.
- 2024: The group claimed it stole data on 560 million Ticketmaster customers. AT&T also lost customer call and text records and reportedly paid a hacker to delete them. Both incidents involved data held in Snowflake customer accounts. Investigators found that attackers used stolen logins.
- 2025: In a campaign targeting Salesforce customers, attackers posed as IT support staff. They called employees and tricked them into approving an app that allowed the attackers to steal data.
- Early 2026: Researchers found that attackers used phone calls and fake sign-in pages to steal passwords and security codes for access to sensitive data.
- May 2026: ShinyHunters claimed an attack on Canvas that knocked the platform offline for schools across the country. The FBI warned the public on May 15.
- May–June 2026: In a separate campaign, Mandiant found that attackers used a flaw in Oracle PeopleSoft to breach schools and universities.
- August 2026: Banking technology provider Jack Henry confirmed a ShinyHunters attack that began with voice phishing. The company said its core banking platforms weren’t accessed or disrupted and that it wouldn’t pay the extortion demand.
- September 2026: ShinyHunters claimed it took over Cl0p’s site and demanded payment from the rival crime group. Days later, it claimed an attack on the FBI’s jobs site, which the bureau said it was investigating. On September 25, Mandiant reported another wave of PeopleSoft attacks across several industries.
The Cl0p episode shows the pattern in miniature. ShinyHunters said it found a file upload flaw in the software behind its rival’s site. From there, it claimed to take Cl0p’s source code, logs, and the keys to its dark web address. Then it demanded payment. One weak spot opened the door to everything behind it.
What happens after the foothold?
In its PeopleSoft investigation, Mandiant found that attackers tried passwords to reach other internal servers. Breaking in gave them a starting point. Open connections gave them places to go. In the September wave, Mandiant saw the group install tunneling tools that let it explore internal networks and move laterally from the PeopleSoft server.
For Christer Swartz, director of industry solutions at Illumio, the entry method is only the start of the story. “Eventually, a threat will land,” Swartz said. “And it will look to move across the environment.” A server may need access to a database, for example, but it may have little reason to contact a long list of peer servers. That difference can help defenders spot an attacker looking for a way to move. Swartz outlined three ways defenders can limit that reach.
Visualize the movement
A stolen password can make an attacker look like a legitimate user. Their next actions may tell a different story. A server that usually talks to one database might suddenly try to reach several nearby systems. Repeated failed connections could signal someone guessing passwords. A large data transfer could also warrant a closer look. “It’s key to be able to see all movement,” Swartz said. Knowing which connections are normal helps teams spot changes and decide where to investigate.
Close unnecessary paths
Visibility also helps teams determine which connections a system needs. Segmentation can then restrict the rest, giving an attacker fewer routes to other systems and critical assets. “Shut down all sessions that are not needed,” Swartz said.
Allowed connections also need attention. An attacker may use a valid account and a legitimate path, so defenders must watch how those connections are used.
Contain suspicious activity
Teams don’t always know the full scope of a breach when they first detect it. Seeing a compromised server trying to reach other systems can help them decide what to isolate. Swartz said teams need a clear reason to quarantine a system. A login with valid credentials may not look suspicious “until it starts behaving strangely.”
Containment can interrupt that movement while responders investigate. If attackers also hold cloud sessions or access through connected apps, teams need to revoke that access too.
One foothold shouldn’t become a wider breach
Leatherman told ShinyHunters the FBI knows how to find them. Inside their own networks, defenders need to be able to say the same thing. ShinyHunters’ next target may be a school, a bank, or another rival gang, and its way in will likely be new. The question that follows stays the same: once attackers land, how far can they go? Teams that can see how their systems connect, close the paths they don’t need, and isolate a compromised system fast will have a better answer. That’s how one foothold stays a foothold instead of becoming the next headline.
Attackers will find ways in. What matters is how far they can go once they’re there.
Illumio helps you visualize attack paths, limit lateral movement, and contain threats before they spread.



