A hacking group calling itself ShinyHunters claims to have breached multiple FBI-related systems, exfiltrating what it says is comprehensive personnel data for current and former employees and applicants. The group provided a 5,000-record sample containing names, home addresses, phone numbers, dates of birth and some spouse information; open-source checks on phone numbers matched the listed names and linked some numbers to Department of Justice personnel. Attackers also defaced the FBI jobs site, posting a seizure-style message that said all PII and protected health information was compromised and that far more data exists. ShinyHunters said it exploited a zero-day in Oracle PeopleSoft, pivoted to AWS GovCloud, and downloaded roughly two to three terabytes of data.
The claimed breach raises acute counterintelligence and safety risks: exposed contact and personal data can enable tracking, harassment or targeting of agents and their families and could be valuable to foreign intelligence or criminal networks. ShinyHunters typically pursues extortion but stated this incident is “not financially motivated” and framed future actions as coercion rather than a ransom demand; the FBI has not publicly commented. If verified, the scale and sensitivity of the disclosed files would represent a major security compromise with significant operational and personnel consequences.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.