Hacking group ShinyHunters says it breached FBI systems and exfiltrated sensitive personal data on thousands of current agents and job applicants. The group posted a sample of names, home addresses and phone numbers and claims to have pulled terabytes after exploiting an Oracle PeopleSoft server used for HR and recruitment, then pivoting into an Amazon-hosted government cloud that housed agents’ and applicants’ records. The intrusion reportedly included a defacement of the FBI jobs portal and took the agency’s applicant services offline.
ShinyHunters frames the attack as retaliation over a report it calls false rather than as a financially motivated extortion, and is demanding the FBI remove that report while not specifying what it will do with the data if ignored. The exposed personal details present a major counterintelligence and safety risk: foreign spies and criminal actors can use the information to coerce, blackmail or otherwise target agents and their families. Officials have not publicly responded. This is the second significant FBI system compromise this year, following a breach of a wiretap-management system and a separate leak of the FBI director’s personal email.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.