deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (hnrss.org)

ShinyHunters claim FBI breach exposing data on all employees and applicants

ShinyHunters say they used an Oracle PeopleSoft zero-day to steal terabytes of FBI personnel data and defaced the agency's jobs site; the FBI says it is investigating the claims.

ShinyHunters claim FBI breach exposing data on all employees and applicants

What ShinyHunters claims

The hacking group ShinyHunters says it compromised several services connected to the FBI and made off with data covering "all FBI employees and applicants." A representative of the group told 404 Media that the stolen records include agents' names, home addresses, phone numbers and information about their spouses.

The claim arrived alongside visible evidence of an intrusion. According to 404 Media, the FBI's jobs website was defaced on Tuesday with a banner reading "this site has been seized by ShinyHunters" — a deliberate echo of the seizure notices U.S. law enforcement agencies attach to domains they take down. The defacement went further, asserting that all FBI data had been compromised, including personal and protected health information on current and former employees plus applicant records, and that the group holds far more than it is currently revealing. The message closed with "Thank you for your attention to this matter," which 404 Media read as a jab styled after the president's Truth Social posts. When the outlet published its story, the jobs portal was showing a notice that the application site and the Special Agent Applicant Portal were unavailable.

A partial verification

A representative provided 404 Media with a sample file said to contain personal data on 5,000 FBI employees, including addresses, phone numbers, dates of birth and, in some cases, spouse details. To test it, 404 Media ran some of the phone numbers through the open-source intelligence service OSINT Industries and found they belonged to people with the same names as those listed in the file. The outlet also checked records through Darkside, a compromised-data lookup tool built by cybersecurity company District 4, which indicated some numbers are associated with U.S. Department of Justice personnel.

Those checks support the authenticity of individual records, but they cannot confirm the group's central claim — that it holds data on the entire FBI workforce and every applicant.

The claimed route in

The representative said the intrusion took place on Monday night and began with a zero-day exploit in Oracle's PeopleSoft, the long-established enterprise HR software. From that foothold, the group says it reached AWS GovCloud servers and downloaded between two and three terabytes of data. These technical details come from the group itself and have not been independently confirmed.

The FBI's response and the group's demands

After the article was published, an FBI spokesperson told 404 Media by email: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." The agency has not confirmed any data theft.

ShinyHunters is known for breaching targets and then pressing them for payment under threat of releasing stolen data. Asked whether it would attempt that against the FBI, the representative drew a distinction: "what we plan to do is not something I'd call extortion, maybe coercion," adding that the operation "is not financially motivated."

In a post on its leak site, the group also pushed back against an earlier FBI report that described ShinyHunters as exaggerating its access to sensitive data in order to extract payments, sending threatening calls and messages to victims and their families, and occasionally carrying out swattings. The group called those allegations false and gave the bureau one week to correct or remove the report.

Why it matters

If the claims hold even in part, this could become one of the most consequential U.S. government data exposures in years. As 404 Media notes, criminals from the same ecosystem have previously used hacked phone records to track, intimidate and harass the FBI agents investigating them, and a trove of home addresses and family details would be valuable to foreign intelligence services seeking to understand how the bureau operates. Agents and their spouses could face direct threats to their safety, and former employees and applicants — people who may have no idea their information sat in these systems — could be swept up too.

The incident also points to a broader structural risk: if the group's account is accurate, a vulnerability in legacy HR software served as the doorway into government cloud infrastructure, and an extortion-focused crew had no hesitation about aiming at an agency that will never pay a ransom.

  • #security
  • #data-breach
  • #fbi
  • #shinyhunters
  • #oracle-peoplesoft

Related posts