A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, phone number, and information on their spouse.
The data breach could be massively significant and may have all sorts of national security and counterintelligence implications. Criminals from the same ecosystem as ShinyHunters have previously used hacked data like phone records to track, intimidate, and harass the FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies who want to better understand how one of the most important law enforcement and intelligence agencies in the U.S. operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their safety.
“We hacked the FBI. We hold data on all FBI employees and applicants,” the representative of the group told 404 Media.
💡
Do you work at the FBI? Do you know anything else about this hack? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.
The representative provided 404 Media with a sample appearing to contain the personal data of 5,000 FBI employees. That data included an alleged address, phone number, date of birth, and in some cases details on their spouse.
404 Media put some of the sample phone numbers into open source intelligence tool OSINT Industries and found they did correspond to people with the same name as listed in the sample file. 404 Media also searched some of the records through compromised data tool Darkside, made by cybersecurity company District 4. That revealed some of the phone numbers are associated with U.S. Department of Justice personnel.
ShinyHunters also defaced the FBI jobs website on Tuesday. That defacement says, “this site has been seized by ShinyHunters,” which is an obvious nod to the seizure notices the FBI and other law enforcement agencies often put on sites after taking them down. The representative said ShinyHunters carried out the hack on Monday night. At the time of writing, the FBI jobs website says, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.”
The defacement adds, “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”
The announcement ended with another obvious jibe at the administration, this time mocking President Trump’s Truth Social post style: “Thank you for your attention to this matter.”
After publication of this article, an FBI spokesperson told 404 Media in an email “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
The representative said ShinyHunters said the group used a zero day exploit in an Oracle product called PeopleSoft. From there, the group managed to access AWS GovCloud servers and downloaded data. The representative said the exfiltrated data totalled between two and three terabytes.
Typically, ShinyHunters hacks targets and then attempts to extort them. The group threatens to publicly release more compromised data if the victim organization or company doesn’t pay a hefty fee. Obviously, it is unlikely that the FBI would ever pay a ransom like this.
When asked if ShinyHunters was going to attempt to extort the FBI, the representative said, “what we plan to do is not something I’d call extortion, maybe coercion.”
“This is not financially motivated,” they added.
In a post on its leak website, ShinyHunters said the FBI made “false allegations” in a previously published report. Previously, the FBI said that ShinyHunters exaggerates its claims of access to sensitive data to illicit payment, that the group sends threatening text messages and phone calls to victims and their families, and sometimes performs swattings. In the post, ShinyHunters said it is “allowing you [the FBI] a time of 1 week to correct” or remove the report.
Update: this piece has been updated to include more information from previously compromised data, a statement from the FBI, and information from a post on ShinyHunter's website.
About the author
Joseph is an award-winning investigative journalist focused on generating impact. His work has triggered hundreds of millions of dollars worth of fines, shut down tech companies, and much more.