A hacking group named ShinyHunters claims to have breached multiple FBI-related services and stolen data on all FBI employees and applicants. A representative of the group stated to 404 Media that the data includes names, home addresses, phone numbers, and information about spouses of FBI agents. The breach may have significant national security and counterintelligence implications, as similar groups have previously used hacked data to track and intimidate FBI agents. The data could also be valuable to foreign intelligence agencies seeking insights into the operations of the FBI.
The representative provided a sample containing personal data of approximately 5,000 FBI employees, which included addresses, phone numbers, and dates of birth. 404 Media verified some phone numbers through open-source intelligence tools, confirming they corresponded to individuals listed in the sample. Additionally, some numbers were linked to U.S. Department of Justice personnel.
On Tuesday, ShinyHunters defaced the FBI jobs website, stating, "this site has been seized by ShinyHunters," and claimed that all FBI data, including personally identifiable information (PII) and protected health information (PHI), had been compromised. The group asserted that they had more data than what was publicly disclosed.
An FBI spokesperson confirmed awareness of the claims regarding unauthorized activity affecting FBIjobs.gov and stated that an investigation is underway. The representative from ShinyHunters indicated that they exploited a zero-day vulnerability in an Oracle product called PeopleSoft to access AWS GovCloud servers, resulting in the exfiltration of two to three terabytes of data.
Typically, ShinyHunters engages in extortion after hacking, threatening to release more data unless a ransom is paid. However, the representative claimed that their actions were not financially motivated, referring to it as "coercion" rather than extortion. They also stated that the FBI had made "false allegations" in a prior report about the group’s activities, which included sending threatening messages and performing swattings. ShinyHunters has given the FBI one week to correct or remove the report.
This article has been updated to include additional information from previously compromised data, a statement from the FBI, and details from a post on ShinyHunters' website.