A high‑profile hacking group called ShinyHunters claims to have breached several FBI‑related services and stolen data on “all FBI employees and applicants.” The group’s spokesperson told 404 Media that the leak contains agents’ names, home addresses, phone numbers and spouse details. A sample file covering roughly 5,000 FBI staff was provided; OSINT checks matched the listed phone numbers to individuals with the same names, and some numbers were linked to U.S. Department of Justice personnel.
ShinyHunters also defaced the FBI jobs portal on Tuesday, displaying a message that the site had been seized by the group and stating that all incumbent, former and applicant PII/PHI had been compromised. The site is currently unavailable.
The group says the hack leveraged a zero‑day exploit in Oracle PeopleSoft, which gave them access to AWS GovCloud servers where they exfiltrated about 2‑3 TB of data. While ShinyHunters usually extorts victims, they described this operation as “coercion” rather than financial extortion. The FBI has not commented.
If the data falls into the hands of criminals or foreign intelligence services, it could endanger agents and their families and have far‑reaching national‑security implications.
Review