Most cybercriminals who break into a federal law enforcement agency want money or secrets. The group that says it broke into the FBI last week wants a correction.
On September 22, the extortion crew ShinyHunters claimed it had stolen data on nearly every FBI agent and everyone who had applied for a job with the bureau, and it defaced the FBIJobs.gov portal with the Pokémon mascot it uses as a calling card. TechCrunch reported that 404 Media checked names, home addresses, and phone numbers in a sample against public records and found them genuine. The group’s price was not a ransom. It demanded that the FBI retract or amend a public warning it issued about the group in May.
That looks like a war of ego, and some researchers read it exactly that way. But look at what the May warning actually said, and the attack reads less like wounded pride and more like a business defending its only real asset.
What the FBI said, and what the group says it did
The warning in question is a May 15 public service announcement from the FBI’s Internet Crime Complaint Center, issued after ShinyHunters hit Instructure, the company behind the Canvas learning platform. It said the group commonly pressures victims with threatening calls and texts to them and their families, in some cases swatting. It also said that extortionists may claim to hold compromising material that frequently does not exist, and it advised victims not to pay.
ShinyHunters denies the harassment allegations. Its spokesperson told The Register the group was “just protecting our business,” and claimed it got in through a previously unknown flaw in the Oracle PeopleSoft software behind the jobs portal before moving into FBI-managed servers on Amazon’s government cloud. That route is the group’s account, not an established fact. The FBI has confirmed it is investigating, but told NBC News the point of breach is still undetermined, whether at a third-party provider or inside its own systems.
The group gave the bureau a week. As that window closed on Monday, it told Cybernews it had never intended to publish the data and had never used the word “deadline.” The FBI’s warning is still online, with no sign of an edit, as of this writing.
Why a warning is a threat to an extortion business
Extortion only works if the victim believes two things: that the criminal really has the data, and that paying will make it go away. Every payment is a bet on the attacker’s credibility. That is why the Canvas case matters. In May, Instructure said it had reached an agreement with the group and that the stolen data, tied to roughly 275 million records across 8,809 institutions, had been destroyed. The terms were not disclosed, and there is no way to verify destruction. A deal like that is only as good as the reputation of the people on the other side of it.
The FBI’s announcement went after both halves of that bet. It told future victims that the group’s claims may be inflated and that paying is a mistake. For most criminal groups, a line like that is background noise. For a group whose payday depends on victims believing it, it is a direct hit on the sales pitch.
And the market is already hostile. As we reported in August, Chainalysis figures showed only 28 percent of identified ransomware victims paid in 2025, down from nearly 79 percent in 2022. When most targets already refuse, the gangs that survive are the ones whose threats still feel real. Seen that way, breaking into the FBI’s own hiring system and handing verified samples to reporters works as the loudest possible rebuttal to the claim that the group bluffs. The decision not to publish fits too: it keeps the demonstration from turning into a hostage crisis that would bring the full weight of federal law enforcement down on its members.
The case that it was just ego
The strongest counterargument is that this was a reckless decision, not a calculated one. CyberScoop framed the attack as ShinyHunters trading profit for “publicity and bravado,” and one researcher it spoke to put the motive more bluntly: the group’s feelings were hurt. French police arrested four suspected members in June 2025, and provoking the one agency whose job is hunting them is not what a careful operator would do.
Both readings can be true at once. Criminal groups are run by people, and pride is part of how a brand like this one holds a loose network of associates together. But the fact that the group demanded a correction instead of cash, then publicly walked back any plan to publish, suggests it understood what was at stake. The group’s product is its credibility, and the FBI’s warning was aimed squarely at it.
The part that should worry everyone else
Set motive aside and the damage remains. Cynthia Kaiser, a former senior FBI cyber official, told NBC News the data could be used to target or physically harm agents and their families. Once personal records like these are copied, there is no taking them back, whatever the thief promises.
It is also the second serious intrusion at the bureau this year. In March, the FBI was investigating a hack of its wiretap and surveillance systems. If the group’s account of the entry point holds up, the lesson for every organization is uncomfortable: the hiring portal, the least glamorous system most companies run, can hold the most complete file on their people. By the group’s account, the FBI’s held home addresses, Social Security numbers, and emergency contacts. It should be defended like the crown jewels it is.
Related reading: 79% of Ransomware Victims Used to Pay. Now It’s 28%. · OpenAI Waited 84 Days to Tell Australia Its Agent Broke Into a Health Portal · Passkeys Won. The Password Still Isn’t Dead.
