‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.
A prominent hacking collective, ShinyHunters, claims it has infiltrated various FBI systems and obtained data on all FBI personnel. According to the group's spokesperson, the stolen information encompasses FBI agents' names, home addresses, phone numbers, and details about their spouses. This data breach could have serious implications for national security and counterintelligence.
Past incidents involving ShinyHunters show that they have utilized hacked data to track, intimidate, and harass FBI agents who were investigating them. The sensitive data could also be valuable to foreign intelligence agencies seeking to understand the inner workings of a crucial U.S. law enforcement and intelligence agency. If the data were to fall into the wrong hands, FBI agents and their spouses might face significant threats to their safety.
In a statement to 404 Media, a ShinyHunters representative confirmed the hack and provided details about the stolen data. The spokesperson reportedly obtained a sample containing the personal information of 5,000 FBI employees, which included alleged addresses, phone numbers, dates of birth, and sometimes details about their spouses.
ShinyHunters also defaced the FBI jobs website on Tuesday, declaring the site seized by the group. The spokesperson stated that ShinyHunters conducted the hack on Monday night and that the FBI jobs website is currently unavailable. The defacement also claims that the FBI data, including Personally Identifiable Information (PII) and Protected Health Information (PHI), on both current and former FBI employees, as well as applicant information, has been compromised.
The spokesperson added that ShinyHunters has access to significantly more data than they are currently sharing. The FBI has not yet responded to inquiries regarding the breach. The spokesperson explained that ShinyHunters used a zero-day exploit in Oracle's PeopleSoft product to gain access to AWS GovCloud servers, where they downloaded between two and three terabytes of data.
The group typically hacks targets and then attempts to extort them by threatening to release more compromised data unless a significant ransom is paid. However, the spokesperson clarified that this is not financially motivated and that the group prefers to use coercion instead.
Written by urgent.news from 404 Media's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.