Hackers claim they stole personal data on every FBI employee in potentially massive security breach.
America’s most famous federal law-enforcement agency may have a rather uncomfortable investigation on its hands.
FBI officials are examining claims that hackers broke into systems connected to the bureau and walked away with a vast collection of personal information belonging to employees and job applicants, according to RadarOnline.
ShinyHunters, a hacking group already known in cybersecurity circles, claims the haul stretches far beyond usernames and work email addresses.
Names, home addresses, phone numbers, dates of birth and information about employees’ spouses are allegedly among the compromised records.
“We hacked the FBI. We hold data on all FBI employees and applicants,” a ShinyHunters representative told 404 Media.
FBI officials have not confirmed that extraordinary claim. Reporting on the incident says 404 Media was, however, given a sample appearing to contain personal information belonging to roughly 5,000 FBI employees.
Hackers say almost everyone was exposed
ShinyHunters claimed responsibility for the attack Monday night before publishing a broader statement about the alleged breach.
According to the group, its target included FBI systems containing information about both current and former personnel as well as people who had applied for jobs with the agency.
The hackers claimed to have obtained data on “almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.”
Information contained in the sample reportedly included addresses, telephone numbers, birth dates and, in some cases, details concerning employees’ spouses. Independent reporting has not established that the hackers possess records covering every FBI employee, making the scale claimed by ShinyHunters important but still unverified.
Such information could present risks considerably more serious than the average corporate data leak if authentic.
Home addresses and family information belonging to federal agents could potentially be exploited for harassment or targeting, while personnel records could also be valuable to criminal organizations or foreign intelligence services.
FBI recruitment website gets a new owner for a few hours
ShinyHunters did not limit its victory lap to claims posted online.
Visitors to the FBI’s recruitment website on Tuesday were reportedly greeted by a message announcing that the page had been taken over.
“This site has been seized by ShinyHunters,” the message read.
The joke borrowed the language regularly used by the FBI and other law-enforcement agencies when they seize criminal websites.
Control eventually returned to the bureau.
FBIjobs.gov subsequently displayed a maintenance notice featuring Crisis Response K-9s and the message: “We’re sniffing out site updates for you!”
The website promised visitors it would return soon.
FBI says it is investigating
Washington has so far been considerably more restrained than the hackers.
“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” an FBI spokesperson told 404 Media.
No public confirmation has established that ShinyHunters gained access to the complete personnel database it claims to possess.
Questions also remain over precisely which FBI-connected systems were compromised, how long the attackers had access and whether sensitive operational information was exposed.
ShinyHunters reportedly claimed to have exploited a previously unknown vulnerability involving Oracle PeopleSoft, a widely used enterprise software platform. Current reporting has attributed that explanation to the hackers rather than independently establishing it as the confirmed cause of the FBI incident.
ShinyHunters says money is not the point
Ordinary ransomware logic may not explain the group’s latest operation.
ShinyHunters has insisted that its FBI attack is “NOT financially motivated.”
Asked whether the group intended to extort the bureau, a representative gave 404 Media a rather carefully chosen answer.
“What we plan to do is not something I’d call extortion, maybe coercion,” the representative said.
No public explanation has yet established exactly what that “coercion” would involve.
ShinyHunters has also linked the attack to an FBI announcement from May that discussed the group and its methods.
The bureau publicly warned about ShinyHunters activity earlier this year, describing it as a cybercriminal group and detailing attacks against a learning-management system.
ShinyHunters now appears to be presenting the alleged FBI breach partly as retaliation.
Trump gets dragged into the hackers’ message
President Donald Trump also received a brief cameo in the group’s announcement, although there is no suggestion that he was personally involved in the breach.
ShinyHunters ended its message with a phrase familiar to anyone who follows the president’s Truth Social account.
“Thank you for your attention to this matter.”
Trump frequently uses that wording at the end of his social-media posts, making the hackers’ choice an apparent jab at the president.
Their broader message was considerably less playful.
“All FBI data was compromised,” the group claimed, adding that the material included personally identifiable information and protected health information involving employees and applicants.
“We have a lot more than we claim here,” ShinyHunters warned.
Neither assertion has yet been independently confirmed in full.