HackerFeeds
All ransomware incidents
P

Ransomware group shinyhunters hits PSA - READ THIS NOW

MEDIUM
·Not Found·2026-09-22

PSA - READ THIS NOW — a not found target has been listed by the shinyhunters ransomware group on 2026-09-22. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target OrganizationPSA - READ THIS NOW
Threat Group
shinyhunters
SummaryDear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to "disrupt" our operations, an effort that ultimately proved unsuccessful. For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that. Our PSA today works to address these allegations and correct them. We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more. We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations: - "Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. " - "To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting" - " Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist." We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that. We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats. We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS . Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of "The Com". We have NEVER been apart of "The Com". "The Com" is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense. As a big believer and supporter of the U.S. Constitution - we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated. We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to "disrupt" our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation. As any human being would do. We welcome any and all journalists to inquire us at shinygroup@onionmail.com to hear our side of the story. Make the right decision, don't be the next headline. Thank you for your attention to this matter. -SH | Updated: 23 Sep 2026
Date of Breach2026-09-22
Discovery Date2026-09-22
Region
Target Domain
Business SectorNot Found
Severity
MEDIUM

Claim by shinyhunters

Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to "disrupt" our operations, an effort that ultimately proved unsuccessful. For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that. Our PSA today works to address these allegations and correct them. We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more. We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations: - "Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. " - "To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting" - " Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist." We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that. We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats. We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS . Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of "The Com". We have NEVER been apart of "The Com". "The Com" is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense. As a big believer and supporter of the U.S. Constitution - we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated. We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to "disrupt" our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation. As any human being would do. We welcome any and all journalists to inquire us at shinygroup@onionmail.com to hear our side of the story. Make the right decision, don't be the next headline. Thank you for your attention to this matter. -SH | Updated: 23 Sep 2026

Posted by the shinyhunters threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.