Urgent.News

What's breaking now, across thousands of outlets.

Tech

FBI data breach puts agents and families at risk

A major cyberattack on the FBI may have exposed the home addresses, Social Security numbers, family details and sensitive intelligence assignments of potentially tens of thousands of current and former employees, raising fears that the stolen information could put agents and their families at risk. Nearly a week after the hacking group ShinyHunters disclosed the breach, the FBI is still trying to…

FBI data breach puts agents and families at risk

A significant cyber assault on the Federal Bureau of Investigation (FBI) may have compromised the home addresses, Social Security numbers, family details, and sensitive intelligence responsibilities of potentially tens of thousands of present and former staff members. This information leak has sparked worries that it could endanger the agents and their families.

The hacking group ShinyHunters revealed the breach nearly a week ago, and the FBI remains uncertain about its full implications. The agency has confirmed that personal data was stolen and has advised employees to remain vigilant, both professionally and personally, according to a confidential bulletin reported by The New York Times.

The bureau stated on Monday that it is "operating around the clock to investigate the cyber incident involving FBIJobs.gov and is in constant contact with anyone who may be affected". Independent verification by Reuters of some of the stolen material has found information that could identify FBI personnel engaged in sensitive assignments, such as tracking Chinese spies, Russian intelligence, and drug cartels.

The scope of the stolen personal data is particularly alarming. According to a review by The New York Times, the records encompass names, home addresses, phone numbers, work email addresses, Social Security numbers, dates of birth, and employment specifics of current and former FBI personnel. Moreover, some records feature names and contact information for spouses and emergency contacts, including parents, siblings, and children in certain cases.

The dataset also encompasses employee identification numbers tied to the Transportation Security Administration’s PreCheck program, which could enable the tracking of agents, including those working covertly. From a national-security standpoint, the disclosure of where FBI personnel work is particularly worrisome. The files enumerate units, job titles, supervisors, and assignments involving counterintelligence, narcotics, and national-security activities focused on Russia, China, and Iran, according to The New York Times.

Reuters independently identified similar details about intelligence assignments within the material it reviewed. ShinyHunters further claims that it acquired medical records, including psychiatric evaluations and documents related to blood and urine tests. Reuters reported on Friday that it had examined documents holding sensitive psychological and medical examination data and had partially validated some of the files.

The amalgamation of personal, professional, and medical information could make the breach considerably more perilous than a typical theft of employee records. Cybersecurity experts have cautioned that foreign intelligence agencies might merge this data with information acquired from prior breaches to fabricate in-depth profiles of FBI personnel.

This information could also be abused by criminals targeting agents involved in investigations. Ciaran Martin, a former director of Britain’s National Cyber Security Centre, told The New York Times that the breach could significantly affect the operational efficiency of the FBI. The FBI assumes all employees affected, as stated in an internal FBI memo cited by Reuters, a person briefed on the matter reported.

Employees have been instructed to report unsolicited communications or threats, refrain from answering calls from unknown numbers, and take additional measures to safeguard themselves and their families. ShinyHunters initially threatened repercussions unless the FBI withdrew a public warning issued earlier this year regarding the group.

The advisory had cautioned that hackers linked to it were known to intimidate victims and their relatives using threatening or coercive methods. The group has since altered its stance, declaring it will not publish the FBI data and that "nothing will happen", Reuters reported. The exact method by which the attackers infiltrated the FBI's system is currently under investigation.

ShinyHunters has asserted that they exploited Oracle's PeopleSoft software. Google stated last week that ShinyHunters had resumed the "mass exploitation" of a critical PeopleSoft vulnerability, identified as CVE-2026-35273, across various sectors. Google's threat-intelligence analysts noted the group had adjusted its technique to evade some firewall defenses.

The corporation did not assert that the vulnerability was responsible for the FBI breach, and the FBI has not officially confirmed how its systems were compromised. Additionally, Dutch authorities have apprehended a 24-year-old man as part of an investigation into ShinyHunters. His employer identified him as Pepijn van der Stap, a previously convicted cybercriminal who had previously worked as a cybersecurity professional.

ShinyHunters rejected that he was linked to the group. The FBI's Dallas field office has been collaborating with international partners to investigate ShinyHunters, per The New York Times.

Written by urgent.news from Gulf News's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at gulfnews.com →

More in Tech

When an agent can’t give the answer, what should it do next?

When someone asks an agent to make a consequential personal decision, a refusal can be correct and still leave them stranded. While designing an evaluation for a client, I worked through that tension.

  • When an agent can't answer a consequential decision, it must decide next steps.
  • Respecting user's limit, agent can't decide for them, leaving user with no options.
  • Useful response involves offering a feasible next step, allowing user to decide.

It’s the end of the world – and I don’t feel fine

Armageddon is what will happen when billionaires, or even trillionaires, are given free rein. Could this be the final outcome of late-stage American capitalism and democracy? Imagine a human-extinction event: a rogue artificial intelligence (AI) revolution, a new world war or runaway climate change.

More from Tuesday 29 September →