FBI Investigates ShinyHunters Claim of Data Theft Affecting 38,000 Employees
The FBI is investigating claims by the cybercriminal group ShinyHunters that it stole confidential information belonging to all of the agency’s employees—approximately 38,000 people.
ShinyHunters claims it obtained personal information about every FBI employee, including names, roles, badge numbers, home addresses, phone numbers and marital information.
Professor Ciaran Martin, the former director of the UK’s National Cyber Security Centre, said that if the claims are confirmed, the breach would be “as serious as it gets in terms of data breaches.”
FBI says investigation is underway
In a statement published on X, the FBI said it was aware of the allegations and was “actively and aggressively investigating this matter.”
The hackers said they broke into FBI servers on Monday night and began contacting reporters on Tuesday, sharing samples and screenshots of the alleged stolen data.
The BBC has reviewed a small portion of the information, which appears to be genuine.
Some of the data reportedly includes details about officials’ job assignments, including sensitive work involving Chinese spies, Russian intelligence and drug cartels, Reuters reported.
ShinyHunters claims access to multiple FBI systems
ShinyHunters is an international hacking group believed to have originally started in France. It has been linked to several high-profile breaches, including highly destructive attacks on Rockstar Games in April and the education platform Canvas in May.
The group claims it identified vulnerabilities in the Oracle cloud storage system used by the FBI and compromised multiple systems. These allegedly include FBIJOBS, FBI BEAST—which conducts background checks on employees and applicants—FBI MedLink, which stores investigators’ medical records, and FBI BICS, which stores investigative information.
In messages posted on the dark web, ShinyHunters said it did not hack the FBI’s systems for money.
Instead, the cybercriminals are demanding that authorities rescind an advisory issued about the group in May. ShinyHunters said it was “offended” by the way it was characterized.
That FBI public service announcement describes ShinyHunters as a “threat actor” that often “uses real or exaggerated claims of access to sensitive or personal information to induce payments from victims.”
“They target large companies in the tech, financial, and retail industries, often stealing millions of customer records at a time,” the advisory said.
ShinyHunters said it gave the agency one week to correct or remove the allegedly false claims, or it would release its complete database.
FBI assessing whether a third party was breached
The FBI did not respond to multiple requests for comment from the BBC.
However, the agency said on X that it was working to determine whether the hackers penetrated FBI systems directly or accessed information through a third party.
“We are actively and proactively investigating this matter and are working closely with third-party providers supporting FBIJobs.gov to mitigate any risks,” the post said.
Experts describe alleged breach as retaliatory
Cybersecurity experts told the BBC that the incident appeared to be a “retaliatory attack” and demonstrated that “no organization is safe from this group.”
“This group clearly wants to control the discourse around its activities and prevent anything from being said that might damage its reputation,” said William Wright of Closed Door Security.
Andrew Brandt of cybersecurity firm Huntress said the incident could prompt the FBI to pursue and prosecute members of the hacking group.
“ShinyHunters should be pretty confident that they won’t get caught blackmailing government agencies like this,” he said.
Source: www.bbc.co.uk


