❌

Reading view

ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'

ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve their reputation and keep their “business” afloat. So it hacked the FBI to make a statement, the group told The Register. “It’s a game and it’s the world we live in,” a ShinyHunters spokesperson told us. “We are just protecting our business as any other business would do. It’s about who does their job better.” On Friday, the FBI confirmed the breach to The Register, after earlier in the week saying the bureau was investigating ShinyHunters’ claims. "The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” an FBI spokesperson told The Register. "While the point of breach is still undetermined - whether a third-party or the FBI’s enterprise - we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk." On Tuesday, the criminals told us that they broke into the bureau via yet another Oracle PeopleSoft zero-day flaw in the FBIJobs.gov portal, which remains down as of Friday. Then, they breached the FBI’s managed servers on AWS GovCloud and swiped thousands of personnel files belonging to current, former, and prospective FBI employees. “We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” the group claimed in a message posted online and addressed to FBI Director Kash Patel and Brett Leatherman, assistant director of the FBI’s Cyber Division. Sample files reviewed by journalists and security researchers appear to contain agents’ home addresses, phone numbers, email addresses, Social Security numbers, job titles, assigned field office, and emergency contact information. 'We refuted the misinformation disseminated by the FBI' According to a spokesperson for ShinyHunters, the FBI hack isn’t about the money, and the crew did not demand a multimillion-dollar extortion payment to not leak the agents’ personal details. “Our breach of the FBI was executed specifically to contest the allegations made against ShinyHunters in their May 2026 FLASH report,” a spokesperson told The Register. The FBI bulletin, published soon after the group breached ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff, said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The criminals, it continued, “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” ShinyHunters contends this is all false. By hacking the FBI and releasing its statement about the hack, “we demonstrated our technical capabilities and directly refuted the misinformation disseminated by the FBI, journalists, and industry researchers,” the spokesperson told us in an interview. “This was fundamentally a public relations and marketing initiative for our business,” they said. 'Results-driven professionals' or criminals? ShinyHunters said it believes that “future corporate partners we engage with for payment will review this documentation, reinforcing our reputation as serious, results-driven professionals focused solely on transaction and resolution.” Most people call these "future corporate partners" victim organizations, breached by the digital thieves, and threatened with data leaks unless they pay an extortion demand. The FBI intrusion “establishes our credibility, technical superiority and excellence, and capability with future corporate stakeholders, positioning us as a professional and predictable entity focused on concluding negotiations efficiently,” the spokesperson said. It also puts a huge target on the crew, and we’d bet that the FBI, already gunning to arrest ShinyHunters members, is now doubling down on those efforts. The spokesperson said they and others in the crew started off as GnosticPlayers before rebranding as ShinyHunters in 2020, and that they have since seen the “majority” of GnosticPlayers members arrested. This business, however, is a criminal operation. We asked them why they believe people will trust the words of criminals over those of law enforcement. They said it’s due to ShinyHunters’ “unique and exceptional reputation along with over five years of history in the space…We are in a unique position and due to our vast capabilities and resources, victims are more likely to resolve the situation quickly and cheaper with us instead of going down the full disclosure route.” Think of the children We also questioned how they justify doing what they do in this “business” - breaking into IT systems, stealing data, extorting victims - considering the personal toll it takes on people, especially when the stolen files contain sensitive information about children as they did in the Canvas intrusion. ShinyHunters claims that they “don't attack human beings. We attack the corporate structure. The Business. Not human beings. The money comes out of insurance pocket. Not people’s or businesses' own. Full coverage by insurance. No personal harm is being done, only business harm that they recover from within a quarter considering the type of attack.” Ransomware and other disruptive attacks are “substantially worse and costly,” they said. “There are times in the work we do sometimes we have to push the corporate to the absolute limit to get them on the table,” they continued, noting that there was an “initial issue” with the Canvas intrusion “that we cannot comment on, but it highly relates to the misinformation we are combating. It takes a lot of convincing to bring a corporate to the table to negotiate if they think you are not trustworthy and bluffing/exaggerating what you have.” While we don’t know for sure what this issue was, ShinyHunters switched to school-by-school extortion after compromising Instructure, the company that owns the Canvas online learning platform, in late April and after the initial pay-or-leak deadline passed on May 6. They injected a ransom message into about 330 Canvas school login portals, causing Instructure to take the platform offline for a day - during final exams and Advanced Placement testing for many. Meanwhile, that PeopleSoft 0day The ed-tech company ultimately “reached an agreement” with ShinyHunters, which is corporate-speak for they paid the extortion demand. Alliance Risk CEO David Vainer previously told The Register he estimates the figure sits somewhere between $5 million and $30 million. According to ShinyHunters, the PeopleSoft preauth vulnerability that they exploited in the FBI attack still doesn’t have a patch. Oracle hasn’t responded to The Register’s questions about the zero-day, or any plans for a patch. Shiny had “no comment” about whether the gang has abused the PeopleSoft bug to compromise other organizations. But they added: “the zero-day would allow us to access similar HR/Employee personal information for other corporations who are vulnerable.” They wouldn’t put a dollar amount on how much they earn from extorting businesses, but boasted: “our revenue performance significantly outperforms both our counterparts and legitimate real life businesses. We have reason to believe in a few months or soon an upcoming financial analysis or reports tracking our earnings will reflect substantial revenue growth.” And they would not comment when asked if they worried about getting arrested and criminally charged for their digital intrusions and extortion attacks. ®

  •  

Bitget blames North Korea for $387.5M crypto wallet raid

The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s wallets. Bitget initially estimated the loss at $351.6 million, but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial estimate. Blockchain intelligence company Arkham published its preliminary observations of the attack, estimating at the time that roughly $350 million was stolen and that $228 million left Bitget’s wallets in 18 minutes, between 18:58 and 19:16 UTC. Arkham said $153 million worth of XRP was taken from a wallet it identified as a Bitget cold wallet, while the stolen assets also included $66.2 million of ETH, $34.8 million of USDT, $12.9 million of USDC, and $12.8 million of Tether Gold on Ethereum. Other affected networks included Arbitrum, Optimism, BNB Smart Chain, Avalanche, and Base. However, Chen said Bitget's cold wallets and customer balances remained unaffected, while its User Protection Fund held more than $464 million worth of assets. “To be transparent about our financial position: beyond the $464M+ Protection Fund – all held in publicly verifiable wallets – Bitget holds over $1 billion in its own assets,” Chen said. “User funds are covered on a 1:1 basis.” Chen also explained that Bitget Wallet, the company’s self-custody product, operates on infrastructure separate from its exchange, and Bitget users can still make deposits and trade their tokens, despite withdrawals being temporarily suspended while additional security checks are completed. Bitget said it also engaged incident response giant Mandiant and blockchain security outfit SlowMist to help with the investigation into the attack. Chiefs at fellow exchanges rallied around Bitget in support. “MEXC stands ready to support Bitget in any way we can,” said CEO Vugar Usi. “In moments like this, the industry is stronger when we stand together.” Binance co-CEO Richard Teng also pledged Binance's support for Bitget, saying it had shared intelligence and helped trace the stolen funds. Ben Zhou, CEO of Bybit, said his company was on standby to “help in any way we can,” noting that Bitget helped it out following the $1.5 billion Bybit theft the FBI attributed to North Korea in February 2025. How and who Root cause analyses typically take some time, although according to Chen, Bitget's security team has already identified the wallet service's backend system as the source of the unauthorized transfers. “Hackers breached a key backend system of the wallet service and exploited it to forge transfer information and invoke the authorization signing process, thereby transferring funds out,” she said. “The possibility of private key leakage can be ruled out – this means a more severe risk scenario has been eliminated. Damage control has been confirmed as complete, and there is no risk of further fund outflows from the platform. “The specific intrusion methods used by the hackers are still under technical investigation, and a full report will be released upon completion of the investigation.” Chen did not go into too much detail about the alleged links to North Korean state-sponsored attackers having a hand in the attack, but said “IP behavioral patterns and on-chain signatures” suggest it was Kim’s cronies at work. It would come as little surprise if North Korea was indeed the culprit behind the attack. The regime has a knack for hacking crypto exchanges. The aforementioned hit on Bybit was perhaps North Korea’s biggest crypto haul, although similar lucrative ventures attributed to North Korean attackers have come at the expense of DMM Bitcoin and WazirX, among others. Bitget was founded in 2018, registered in the Seychelles in 2022, and operates through regional hubs across the world. Some netizens have speculated that the timing was especially inconvenient, with the transfers detected at 18:31 UTC – 02:31 on September 25 in Singapore and China, the first day of China’s three-day Mid-Autumn Festival holiday. The festival is also widely celebrated in Singapore, although it is not a public holiday there. The Register asked Bitget whether this played a role in the attack and its remediation but it did not respond. As of Friday, Bitget is offering bounties to those who help freeze or recover the stolen funds. It said eligible participants could receive 5 percent of the funds their efforts successfully freeze or recover.®

  •  
❌