ShinyHunters Claims Massive FBI Cyber Breach and Exposes Personnel Data

The hacking group ShinyHunters claims to have breached FBI systems, stealing personal data of thousands of employees and disrupting recruitment portals using an Oracle vulnerability.

Now14Author: Efrat Bryner
Source
ShinyHunters Claims Massive FBI Cyber Breach and Exposes Personnel Data
Photo: Now14 / הגנת סייבר | צילום: שאטרסטוק

An unprecedented cyberattack has shaken the US intelligence and law enforcement community as the notorious hacking group ShinyHunters claimed responsibility for breaching systems linked to the Federal Bureau of Investigation (FBI), allegedly stealing sensitive personal data of thousands of employees, agents, and job applicants. While the federal agency has not yet issued an official response, preliminary analysis of a leaked data sample indicates that at least some of the information is entirely authentic.

The breach was first uncovered by the technology news site 404 Media, which received a sample file containing the details of approximately 5,000 FBI personnel. The database included full names, private residential addresses, phone numbers, dates of birth, and in some cases, information regarding the spouses of bureau personnel. Independent checks conducted by the outlet verified that specific phone numbers indeed belonged to individuals listed, with some directly linked to employees at the US Department of Justice. "We hacked the FBI," a representative of the group stated, claiming possession of data on all current staff and candidates.

Defacement of Recruitment Portal and Vulnerability Exploitation

Simultaneously with the data exfiltration, the hackers disabled the bureau's recruitment and application portal, replacing its landing page with a seizure notice mocking the FBI's traditional banners used when shutting down criminal websites. According to a ShinyHunters representative, the intrusion was made possible by exploiting a severe security flaw in Oracle's PeopleSoft software, which allowed lateral movement into secure government cloud servers.

The hackers claim to have exfiltrated between two and three terabytes of data, emphasizing that their primary objective is political coercion rather than financial extortion. The irony of the incident is highlighted by the fact that just last May, the FBI issued a severe warning regarding ShinyHunters, designating them as a sophisticated cybercrime network known for extortion and harassing victims' families.

"We hacked the FBI. We hold information on every single employee and candidate," a representative of the ShinyHunters hacking group declared.

Strategic Implications and Intelligence Risks

ShinyHunters is widely recognized as one of the most prominent and aggressive cyber syndicates globally, previously claiming high-profile corporate breaches and the takeover of darknet infrastructure belonging to rival ransomware operations like Cl0p.

If the scope of the leak is verified, it will represent one of the most severe data security failures in the history of the bureau. Exposing the personal identities of field agents, intelligence personnel, and their families poses not only a physical security risk from domestic criminal elements but also creates an invaluable intelligence asset for foreign adversarial intelligence services such as Russia, China, or Iran, which seek to map the human infrastructure of America's premier law enforcement body.

Related News