The FBI is now investigating claims from a hacker group that thousands of current and former employees’ personal data was stolen after the group exploited a previously unknown bug found on an agency jobs website.
On Tuesday, 404 Media reported that ShinyHunters took down the agency site, FBIJobs.gov, then posted a banner on the homepage that said “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”
About two to three terabytes of data were taken, ShinyHunters told The New York Times. None of the data has been leaked yet, but it included “names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information, and other data.” According to Bloomberg, the data could be used to potentially retaliate against agents, with one sample appearing to include “potentially sensitive professional information on the FBI employees’ work focus such as counter-intelligence work on China, Russia and Iran, as well as work against street gangs.”
The group’s motive was not to extort the FBI or seek a ransom, it claimed. Instead, the strike was meant to force the FBI to either remove or edit a May advisory warning about ShinyHunters that the group said circulated “disinformation in an attempt to ‘disrupt’ our operations.”
Screenshot of the ShinyHunters message,
In a message posted on the dark web that was reviewed by Ars, ShinyHunters said it was “severely offended” that the FBI alleged that they sometimes use “exaggerated claims” to extract payments from victims. “We wish to state unequivocally our threats and claims are very real,” the group said. “Not exaggerated and never a bluff.”
ShinyHunters was also upset that the FBI claimed the group conducts swatting attacks against corporate workers and makes sextortion threats. That “never” happens, ShinyHunters said.
To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or presumably risk a breach of sensitive employee data.
FBI warns employees to be safe
Not many details have been released on how ShinyHunters got access to the data. ShinyHunters would only tell NYT that “it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.” So far, Oracle is silent on that bug, reports said, while ShinyHunters said it plans to continue using the zero-day for its “businesses’ normal operations.”
The FBI has not confirmed that the hack occurred, but it has begun probing the claims. On Wednesday, the FBI said in an X post that “the point of breach is still undetermined—whether a third-party or the FBI’s enterprise.” Until more information is known, the FBI said, “we are actively and aggressively investigating this matter and working closely” with third-party providers that support the jobs site “to mitigate any and all risk.”
As of Wednesday, the jobs site remained inaccessible, as sources inside the FBI told Bloomberg that all personnel received an email warning them to “take steps to protect themselves while the investigation continues.”
ShinyHunters has not said what will happen if the FBI misses the deadline, but cybersecurity experts told the NYT that most likely the data will be leaked online.
“We cannot comment on what we will do if the FBI does not comply with our request,” ShinyHunters said in an email to the NYT. “We reiterate we are not extorting the FBI and this is NOT financially motivated.”
“Our intention, goal, and motive is solely to set the record straight,” the group said.
Ashley Belanger Senior Policy Reporter
Ashley is a senior policy reporter for Ars Technica, dedicated to tracking social impacts of emerging policies and new technologies. She is a Chicago-based journalist with 20 years of experience.






