Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > ShinyHunters Site Goes Dark as FBI Cyber Investigation Intensifies

ShinyHunters Site Goes Dark as FBI Cyber Investigation Intensifies

By: Morgan Cipher — Senior Privacy Journalist

Last updated: October 2, 2026

Human Written
ShinyHunters Site Goes Dark as FBI Cyber Investigation Intensifies
  • The hacker group ShinyHunters’ website went offline on September 30, one day after its FBI deadline expired.

  • The group claimed it stole sensitive data linked to thousands of FBI staff and job applicants.

  • Reuters said it could not confirm why the site went down or whether the FBI played any role.

The website belonging to hacker group ShinyHunters went offline on Wednesday, September 30. This happened shortly after a one-week deadline the group had set for the FBI ran out.

The group had spent the past week making bold claims about a major breach. ShinyHunters said it had broken into the FBI’s job recruitment website and taken sensitive records. According to the group, the stolen files contained information on current agents, former employees, and job applicants.

Reuters confirmed that the site went down. But the news agency made one thing clear: the site going dark does not mean the FBI took it down. Reuters said it could not figure out why the website became unavailable. The FBI did not confirm whether it had taken any action against the site either.

ShinyHunters Made the Claims on September 22

ShinyHunters first went public with its claims on September 22. The group said it had grabbed data on almost every FBI agent and job applicant. It also made a demand. ShinyHunters told the FBI to correct or remove a May 2026 advisory. That advisory had described the group as a cybercriminal organization involved in large-scale data theft and extortion.

Reuters looked at a sample of the files ShinyHunters released. The sample contained personally identifiable information, job-related details, and medical records. The news agency was able to match some of the information against other records. However, it could not confirm where the data came from. Reuters also could not verify that hackers pulled it directly from FBI systems.

The FBI acknowledged that something had happened. The bureau confirmed it was aware of unauthorized activity affecting FBIJobs.gov. But at first, the FBI stopped short of saying hackers had gotten inside its internal systems.

Later, the FBI said it was “actively and aggressively investigating” the incident. On September 29, FBI Cyber Division Assistant Director Brett Leatherman spoke out publicly. He urged ShinyHunters members to reach out to the bureau. He also sent a warning, saying the FBI knows how to find them.

This came right after Dutch authorities arrested a man connected to the group. According to Reuters, Leatherman’s message was direct: contact the bureau, because investigators already have a trail.

The Hackers Said They Never Planned to Publish the Data

Here is where things get more complicated. After all the noise ShinyHunters made, the group later changed its story. ShinyHunters said it had no real plans to release the stolen data at all. According to Cybernews, the group described the whole ultimatum as a marketing move, not a genuine threat to go public with the files.

That statement raises more questions than it answers. The group had set a public deadline. It had released sample data. Other recent attacks have also shown how compromised third-party services can expose large numbers of victims, including the Brevo Cloudflare key attack that affected more than 100,000 websites. Then it said the threat was never real. None of that has been independently confirmed or explained further.

A Suspect Was Arrested in the Netherlands

While the standoff played out online, law enforcement was moving on the ground. Dutch authorities arrested a 24-year-old man from Amsterdam suspected of links to ShinyHunters. Police seized data storage devices during the operation. Officials also said they had not ruled out more arrests. A court in Rotterdam ordered the suspect to be held for another 90 days. That extension suggests investigators are still building their case and gathering evidence.

The Guardian and CBS News both covered the initial breach claims. Neither outlet found confirmation that the FBI’s core internal systems were compromised. The breach, as reported, appears tied to FBIJobs.gov specifically.

As of now, the ShinyHunters website is down. The FBI’s investigation is ongoing. Dutch police have one suspect in custody. The full story behind the data, where it came from, and how the website disappeared still has no confirmed answers. Reuters was clear on that. What the site going offline means, exactly, remains an open question.

Share this article

You might also like

Russian Hackers Use New RedFlick Attack to Deliver CosmicPulse Backdoor

Russian State Hackers Use New RedFlick Technique to Deploy CosmicPulse Backdoor

Russian state-linked hackers known as Star Blizzard have started using a new attack method called RedFlick to deliver a dangerous…

October 2, 2026
Russian-Speaking Forum Buyer Seeks Unique WordPress Admin Credentials

Dark Web Buyer Seeks WordPress Admin Access to High-Traffic Websites

A forum actor is seeking valid WordPress administrator access, with unique credentials and higher-traffic sites reportedly attracting more interest. The…

October 2, 2026
Hacker Claims Over 300,000 Mexican Tuberculosis Records are for Sale

Hacker Claims Mexico’s Tuberculosis Database is for Sale with 305,000 Patient Records

Someone on a cybercrime forum claims to hold 305,852 tuberculosis records from Mexico’s national disease tracking system, and is selling…

September 30, 2026

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.