In a statement posted to its dark‑web site and reiterated during an online chat with Reuters, ShinyHunters said the attack was a retaliation to a May 2026 FBI announcement that exposed the group’s tactics and warned potential victims not to pay ransoms.

The group released what it described as a screenshot of a vandalised FBI careers website and a sample of the stolen employee information. Reuters was unable to independently confirm the authenticity of the screenshot, but a notice on the FBI’s Special Agent Applicant Portal on Tuesday indicated that both the portal and the broader job site were “currently unavailable.”

While the FBI did not immediately respond to requests for comment, Reuters was able to partially verify some of the alleged data. By cross‑checking the names and postal addresses shown in the sample against credit‑bureau records and previously breached datasets supplied by dark‑web intelligence firm District 4 Labs, the outlet confirmed that at least a portion of the information matched real individuals employed by the bureau.

ShinyHunters’ claim of stealing data on “thousands” of employees has not been independently corroborated, and the extent of the breach remains unclear. The outage of the applicant portal, however, suggests that the FBI may be taking technical steps to contain the incident or investigate the alleged intrusion.

The incident arrives at a time when U.S. law‑enforcement agencies have been increasingly targeted by ransomware and extortion groups, prompting heightened scrutiny of cybersecurity defenses and the potential impact on recruitment and operational continuity.