Skip to content

Security1 publisher2 min readPublished

ShinyHunters says it defaced the FBI's careers portal over a Q2 FLASH report

ShinyHunters' September 22 darkweb post demands the bureau withdraw claims about swatting and sextortion. Flashpoint's analysts say the audience for that message is the next corporate victim deciding whether to pay.

The Watch · Security desk

Photograph accompanying ShinyHunters says it defaced the FBI's careers portal over a Q2 FLASH report
Photo: cyberdaily.au

What happened

  • ShinyHunters used its darknet leak site on September 22 to address FBI Cyber Division Assistant Director Brett Leatherman and Director Kash Patel, alleging the bureau's Quarter Two FLASH report made false allegations about the group.
  • The post denies that the group has ever conducted swatting attacks against corporate personnel, texted threats to victims' family members, or claimed to hold compromising photographs and videos.
  • The group demands the FBI withdraw what it calls defamatory statements, invokes its First Amendment rights, and says it will otherwise mount a forceful defence of its reputation by civil means.
  • ShinyHunters told Reuters it had defaced the FBI's careers website as a demonstration, and Darkweb Informer published a screenshot of it.
  • Flashpoint's analysts say the group has overstated the importance of stolen data before but is an established, legitimate threat.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision A company mid-negotiation with this group now faces a counterparty that has picked a public fight with the bureau to argue that paying is still rational. Flashpoint says persuading future victims is the aim.
  • exposure The people behind the applicant portal the group says it hit are job applicants, and Flashpoint expects the stolen data to be published because the FBI will not negotiate.
  • contradiction Flashpoint corroborates the defacement and the samples while saying the group has inflated the value of stolen data before, so the access is better evidenced than any inventory ShinyHunters claims to hold.
  • precedent An extortion crew demanding retraction of a federal intelligence product, with a threat of civil action attached, turns FLASH reporting into something the subject expects to contest.

Flashpoint's analysts treat the FBI post as a commercial move. "Reputation, not ransom, is the likely motive. The FBI publicly advises victims not to pay ransoms, so it's unlikely to pay one. What the group gains is standing as a credible threat," they said [13]. They also said "The group is fighting the FBI's narrative for business reasons," and that "Taking on the FBI directly may be meant to convince future victims that paying still makes sense" [14].

Nothing in the post, as reported, bears on the group's tradecraft or on how its members avoid arrest. The denials are narrow, and each covers behaviour that makes a corporate victim walk away from the table: swatting, texting relatives, bluffing about compromising material [5]. On the extortion itself the group made the opposite point. "We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that," ShinyHunters said [6].

FLASH reports are how the bureau circulates criminal actors' tactics, techniques and procedures [3]. Quarter Two closed on June 30, and the post went up on September 22, 84 days later [17]. According to Cyber Daily, the group was already in a fight with Cl0p over a 2025 disagreement [16].

The FBI applicant portal is down. "Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable," the bureau said [9], adding "For urgent scheduling issues, please reach out to your Applicant Coordinator. We apologise for the inconvenience." [10] Flashpoint said "The defacement and the verified samples back up this claim" [12].

The firm expects publication next. "Since the FBI will likely not engage with ShinyHunters, we expect the group to follow the same playbook it uses against corporate victims and leak the stolen data," Flashpoint said [15]. There is no vulnerability here to patch [18]. The work this creates sits with negotiation planning and with whoever watches the group's leak site.

What to watch

  • Whether ShinyHunters publishes the FBI data it claims to hold, as Flashpoint expects.
  • Whether apply.fbijobs.gov and the Special Agent Applicant Portal come back, and whether the bureau attributes the outage.
  • Whether the FBI restates or revises its FLASH characterisation of the group in later reporting.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories