DNYUZ
No Result
View All Result
DNYUZ
No Result
View All Result
DNYUZ
Home News

What to Know About the Hacking Group ShinyHunters and Its F.B.I. Breach

September 29, 2026
in News
What to Know About the Hacking Group ShinyHunters and Its F.B.I. Breach

A criminal hacking group known as ShinyHunters revealed last week that it had stolen a vast trove of sensitive personal data from the F.B.I., potentially one of the worst breaches of sensitive government information in the internet age.

The breach may have compromised information about tens of thousands of former and current F.B.I. employees, including data like home addresses, Social Security numbers and even secretive job assignments.

In a series of cryptic statements, ShinyHunters demanded that the F.B.I. retract a public advisory the bureau had issued this spring warning of the group’s cyberattacks. In an email to The New York Times on Friday, ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request. But on Monday, it appeared to walk back that demand, saying it would not publish the data, as it typically does with the information it steals.

In a video posted online on Tuesday, the F.B.I. warned the group that it would aggressively pursue its members as it promoted the recent arrest of a suspect it said was affiliated with the group.

Here’s what to know:

What is ShinyHunters?

ShinyHunters is a loose collective of relatively young hackers who have been responsible for dozens of data breaches since about 2019. The group has typically engaged in what are known as ransom-or-release attacks, demanding millions of dollars in payments in exchange for not publishing the data its members steal.

The name of the group appears to refer to the Pokémon video games, specifically players who devote significant time and energy toward hunting for rarer shiny Pokémon.

Recent arrests offer a glimpse of ShinyHunters’ membership, suggesting that the group operates across the globe.

Sebastien Raoult, a French citizen who was then 22 years old, was convicted in 2024 of participating in some ShinyHunters attacks after being arrested in Morocco. He was extradited to the United States for trial and sentenced to three years in prison.

Others who were suspected of being part of ShinyHunters were arrested last year in France. All were young men — born between 2001 and 2004 — and were described by officials as highly isolated.

On Monday, the security journalist Brian Krebs reported that the authorities in the Netherlands had arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions tied to ShinyHunters just days before the F.B.I. breach. ShinyHunters denied on Monday that the suspect was associated with the group.

What have they been up to?

ShinyHunters has targeted hundreds of corporations, government agencies and other entities for their ransom attacks.

Cybersecurity authorities say the group often targets software and cloud service providers. Once infiltrated, those providers can allow hackers to gain access to many targets simultaneously. Several high-profile Google and Salesforce customers, for example, were breached through several waves of attacks over the past year. Those targets included the luxury goods company LVMH — the owner of Dior, Louis Vuitton and Tiffany — and Adidas.

In one of its first major attacks, the group stole the sensitive data of millions of AT&T customers from the company in 2021 and sold the trove online. The telecommunications giant initially denied that the data was authentic, but the company confirmed in a legal filing in 2024 that the hackers acquired sensitive customer records, including account numbers, passcodes and Social Security numbers. AT&T was hit with another cyberattack targeting a cloud service provider, Snowflake, in 2024. The breach exposed phone records from “nearly all” of its customers, the company said.

Among the group’s more high-profile targets this year was Rockstar Games, the studio behind the highly anticipated video game Grand Theft Auto VI, in which it stole and shared the company’s financial data. That data revealed the studio’s profit margins, including billions of dollars in revenue from players buying in-game cash.

ShinyHunters has claimed to have breached a variety of targets: Grubhub; the European Commission; the airline Qantas; the insurance company Allianz Life; Kering, the luxury goods company that owns Balenciaga, Gucci and Alexander McQueen; Harvard University, Princeton University and the University of Pennsylvania; Pornhub; and Telus, the Canadian telecom company.

The group’s attacks have significantly ramped up over the past year, officials and experts say.

In May, it said it had compromised an online learning system called Canvas that is used by thousands of schools and universities around the world, an attack that prompted the F.B.I.’s advisory in the spring. The group also said it was behind attacks against Ticketmaster in 2024, which the hackers said had compromised the information of more than 500 million customers.

What is happening with the F.B.I. breach?

Last week, ShinyHunters said it had stolen records from an online jobs portal for the F.B.I. and demanded that the F.B.I. “correct or simply REMOVE” the spring advisory.

Even as ShinyHunters has now said that it would not release the data, as it has for previous breaches, security researchers warned that even if the group did not publish the data, it could still sell it to other criminals or foreign governments.

It is also unclear just how much sensitive information the hackers stole. The group claimed to have stolen records on everyone who has applied for a job at the F.B.I., and told The Times that the people with compromised information numbered in the tens of thousands. An internal memo sent to the F.B.I. work force by bureau leaders said it was investigating the breach under the presumption that all employees had data stolen.

A sample of records shared with The Times by the hackers included particularly sensitive workplace records, including extraordinary job assignments like counterintelligence, narcotics and various desks focused on Russian, Chinese and Iranian national security threats.

In addition to personal records like names, addresses, phone numbers and Social Security numbers, ShinyHunters also said that it had stolen medical data about employees, including psychiatric records and documents related to blood and urine tests. It also said that it had additional background check files on employees.

Dustin Volz contributed reporting.

The post What to Know About the Hacking Group ShinyHunters and Its F.B.I. Breach appeared first on New York Times.

The Senate races that could surprise everyone in November
News

The Senate races that could surprise everyone in November

by Washington Post
September 29, 2026

In an unpredictable election, with an unpopular president, anything could happen. In the battle for the Senate, that means both ...

Read more
News

‘It was a big loss’: Thailand approves $122 million in emergency funding following flooding that killed at least 19 since September

September 29, 2026
News

SpaceX’s Troubled Starship Test Yesterday Is Looking Ominous for NASA’s Moon Landing

September 29, 2026
News

Wiz Khalifa Reveals Hit Song That, Ironically, Granted Him the Opportunity to Never Be Seen Again

September 29, 2026
News

MAGA senator flees to Charlie Kirk show for praise after disastrous Jack Smith attack

September 29, 2026
Josh Hawley: AI companies shouldn’t get a free pass to break things

Josh Hawley: AI companies shouldn’t get a free pass to break things

September 29, 2026
Trump revealed the seating chart for his big AI meeting. See who’s in — and who’s missing.

Trump revealed the seating chart for his big AI meeting. See who’s in — and who’s missing.

September 29, 2026
Charlie Sheen Returns to TV With ‘Happy Jack’ Comedy Series Co-Starring Dad Martin Sheen

Charlie Sheen Returns to TV With ‘Happy Jack’ Comedy Series Co-Starring Dad Martin Sheen

September 29, 2026

DNYUZ © 2026

No Result
View All Result

DNYUZ © 2026