FBI tells staff to assume hackers stole personal data after jobs site breach

FBI tells staff to assume hackers stole personal data after jobs site breach

FBI employees told to expect the worst

The FBI has told its own employees to assume that hackers stole their personal information, according to an internal memo reported by Reuters. The warning follows a claimed breach of the bureau's jobs website, FBIjobs.gov.

The group claiming responsibility, ShinyHunters, says it holds data on almost all FBI agents and everyone who applied for an FBI job.

Key numbers and claims

  • ShinyHunters says it took 2 to 3 terabytes of data, including names, phone numbers, home addresses, and sometimes spouse details.
  • The FBI says it is investigating and has not confirmed the scale of the breach.
  • On Sept. 29, FBI Cyber Division chief Brett Leatherman posted a video on X telling the hackers "we know how to find you."
  • ShinyHunters later said it does not plan to publish the data.

What is confirmed

The FBI has confirmed it is investigating the claimed breach. The internal memo, as reported by Reuters, tells staff to assume that data on every FBI employee may be exposed. No other details about the breach are confirmed.

What is still unclear

The true scale of the data theft is unconfirmed. The group says it got in through a previously unknown flaw in Oracle's PeopleSoft, software many organizations use to run human resources. Security experts call this a zero-day, a bug the vendor does not know about and has not fixed. The FBI has not confirmed this method.

ShinyHunters also says the intrusion began Monday night, and by Tuesday, Sept. 22, visitors to FBIjobs.gov saw a banner saying the site had been seized by the group. The FBI has not confirmed that account.

The group says the trigger was an FBI advisory from May 15 warning that ShinyHunters uses harassment, including threats to family members and swatting, which is a fake emergency call that sends armed police to someone's door. The group denies that warning. It gave the bureau one week to retract it.

Leatherman pointed to a Dutch arrest from Sept. 15 in his video. ShinyHunters says the arrested man has no connection to it.

Why stolen personal data is dangerous

If the data is released, FBI employees could be doxxed, meaning their private details are exposed publicly. That could lead to threats, harassment, identity theft, or physical harm, and relatives of employees could also be at risk.

The article notes similar risks in the crypto world. Coinbase said bribed support agents leaked customer data last year and then faced a $20 million extortion demand. In France, 135 crypto-related "wrench attacks" have been recorded since 2023, and 88 suspects have been charged. In one case, attackers who beat a couple outside their Nancy apartment reportedly got their details from a January leak at Waltio, a French crypto tax platform that exposed about 50,000 users.

What happens next

The one-week window the hackers set for the FBI has passed. ShinyHunters says it will not publish the data and has called the ultimatum a marketing campaign. The memo reportedly tells staff to expect virtual briefings and to watch for suspicious texts or calls from unknown numbers.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!