WASHINGTON, Sept 23 — The FBI is investigating a claim by the hacking group ShinyHunters that it stole 2 to 3 terabytes of sensitive data from the bureau’s jobs portal, including personal information on thousands of current and former employees and job applicants.
The FBIJobs.gov portal and its Special Agent Applicant Portal were taken offline on Tuesday following the alleged breach. In a statement, the FBI confirmed it was aware of unauthorized activity affecting FBIjobs.gov and said it was actively investigating the matter in coordination with third-party providers supporting the portal. The bureau did not specify whether the breach originated from a third party or its own systems.
ShinyHunters, a cyber-extortion group known for large-scale data breaches, claimed responsibility for the attack in a post on its dark-web site. The group stated it had accessed highly sensitive data, including names, addresses, phone numbers, dates of birth, Social Security numbers, and emergency contact details for thousands of FBI personnel. It also alleged the data included details of assignments to specific field offices and units engaged in counterespionage, security, or drug cartel operations.
Hackers cite FBI’s May warning as motive
ShinyHunters said the breach was retaliation for a May 2024 FBI public service announcement (PSA) that warned organizations about the group’s tactics. The PSA stated that victims should not pay ransom or extortion demands and noted that threat actors often exaggerate or falsely claim access to sensitive information to pressure victims. The hacking group disputed the FBI’s characterization of its operations and demanded the PSA be retracted within a week or it would publish the stolen data.
Scope and verification of claims
The hackers provided a 5,000-line spreadsheet sample to media outlets, including Reuters and 404 Media, which reported they were able to individually verify details for more than 22 people by cross-referencing the data with credit records and dark-web intelligence platforms. Cybersecurity researchers told Axios the attack itself appeared legitimate, though the full scope of the breach remains unverified. The FBI has not confirmed the authenticity of the entire dataset.
Technical details and response
ShinyHunters alleged it exploited a zero-day vulnerability in Oracle’s PeopleSoft platform to gain access to the FBI’s systems, then moved laterally to AWS GovCloud servers to exfiltrate data. The group also defaced the FBIJobs.gov website with a message styled as a law enforcement seizure notice. The portal remained inaccessible as of Wednesday morning, with a notice stating it was “currently unavailable.”
The FBI has not disclosed whether the breach involved current or former employees, job applicants, or both. The bureau’s statement did not address whether the stolen data included protected health information (PHI) or details about employees’ family members, though ShinyHunters claimed such data was compromised.
Background on ShinyHunters
Active since at least 2019, ShinyHunters has been linked to high-profile breaches, including Rockstar Games, Canvas learning platform, and multiple Ivy League universities. The group typically threatens to publish stolen data on the dark web unless ransom demands are met. A French member of the group was sentenced in January 2024 for cybercrimes.
Potential implications
Cybersecurity experts warn the breach could pose long-term risks if the data is circulated among criminal networks or sold on dark-web marketplaces. Allan Liska, a threat intelligence analyst at Recorded Future, told Axios the data was likely to be repeatedly downloaded and shared with other threat actors, increasing the risk of identity theft, targeted harassment, or extortion against FBI personnel and their families.