Hacker Group Claims Massive Breach of FBI Data on All Employees and Applicants

ShinyHunters says it used an Oracle zero-day to access sensitive information and defaced the FBI jobs website

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources4 outlets
A hacking group known as ShinyHunters has claimed responsibility for a major breach of FBI systems, asserting that it stole personal data on every current and former FBI employee and applicant. The group provided a sample of 5,000 records to 404 Media that appeared to contain names, addresses, phone numbers, and details on spouses, which the news outlet partially verified through open-source intelligence. The FBI has not yet commented on the breach.

The hacking collective ShinyHunters said it compromised multiple FBI-related services in an attack carried out on Monday night, according to a representative who spoke to 404 Media. The representative claimed the group exploited a zero-day vulnerability in Oracle’s PeopleSoft software to gain access to Amazon Web Services GovCloud servers, from which they downloaded between two and three terabytes of data.

“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative told 404 Media. The group also defaced the FBI’s federal jobs application website, posting a message that read “this site has been seized by ShinyHunters,” echoing the seizure notices the FBI itself places on taken-down websites. The defacement added that “All FBI data was compromised including PII/PHI on incumbent and former FBI employees and all applicant information.” The message ended with a mock of President Trump’s Truth Social style: “Thank you for your attention to this matter.”

As of late Tuesday, the FBI jobs website displayed a notice stating: “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.” The FBI did not immediately respond to a request for comment.

If confirmed, the breach would have severe national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used similar stolen data—including phone records—to track, intimidate, and harass FBI agents investigating them. The highly sensitive data could also be valuable to foreign intelligence agencies seeking to understand how the U.S. law enforcement and intelligence agency operates. 404 Media reviewed a sample file containing data on 5,000 alleged employees and used the open-source tool OSINT Industries to match some phone numbers to names in the sample.

ShinyHunters typically targets organizations and then attempts to extort them, though it is not yet clear if the group has made any specific demands.

§

Analysis

Why This Matters

  • This breach, if verified, could expose the personal information of all current and former FBI employees and applicants, posing immediate physical safety risks to agents and their families.
  • The data could be weaponized by criminal networks to identify and intimidate law enforcement officers, as seen in previous attacks using stolen phone records.
  • Foreign intelligence agencies may exploit the data to map the FBI’s personnel structure, potentially compromising ongoing operations and counterintelligence efforts.

Background

ShinyHunters is a well-known hacking group that has been active in recent years, often targeting large organizations and selling stolen data on underground forums. The group has been linked to breaches of companies like AT&T, where hackers later used call records to track FBI agents. The FBI itself has faced previous data incidents, but a compromise of its entire employee database would represent an unprecedented escalation. The use of an Oracle PeopleSoft zero-day to access AWS GovCloud—a cloud environment certified for US government sensitive data—suggests a sophisticated attack vector.

Key Perspectives

ShinyHunters (the hackers): The group claims responsibility and has provided a sample of data to support its assertion. Its defacement of the FBI jobs website appears designed to taunt the agency and amplify the breach’s impact. The group’s typical modus operandi involves extortion, though no demands have been made public. The FBI: The agency has not commented on the claimed breach. A spokesperson did not respond to 404 Media’s request for comment. The FBI will likely be conducting an internal investigation and may brief congressional intelligence committees. Critics and Security Experts: If the data is authentic, critics will question how a federal agency handling sensitive personnel information could be vulnerable to a zero-day exploit in a widely used Oracle product. The incident raises concerns about the security of government cloud infrastructure and the adequacy of patch management.

What to Watch

  • Whether the FBI confirms the breach and provides details on the scope and timeline of the compromise.
  • If ShinyHunters or affiliated actors begin posting or selling the stolen data on underground forums, escalating the threat to affected individuals.
  • Oracle’s response regarding the PeopleSoft zero-day vulnerability and whether a patch is released.
  • Possible congressional hearings or executive orders regarding cybersecurity of federal HR systems.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.