FBI investigates apparent theft of its personnel data by hackers

A high-stakes cyber conflict has emerged after notorious hacking collective ShinyHunters claimed responsibility for a massive breach of multiple U.S. Federal Bureau of Investigation systems, threatening to leak sensitive personal and operational data if the agency does not reverse a damaging public characterization of the group.

The international hacking crew, which first gained notoriety for a string of high-profile breaches against major corporations and public platforms over the past year, says it exfiltrated confidential records for roughly 38,000 current and former FBI personnel, along with every individual who has submitted a job application to the bureau. According to the group’s claims, the stolen dataset includes granular personal information: full names, official job roles, government badge numbers, home addresses, personal contact numbers, and even family details such as the names of employees’ spouses. Beyond personnel records, the hackers assert they accessed systems that store sensitive investigative information, employee and applicant background check data, and agents’ confidential medical records.

ShinyHunters says it exploited an unpatched security flaw in the Oracle cloud storage infrastructure that the FBI uses to host multiple internal and public-facing platforms. Among the compromised systems are public-facing hiring portal FBIJOBS, background check system FBI BEAST, medical record repository FBI MedLink, and investigation management tool FBI BICS. The breach is alleged to have taken place on the night of Monday this week, with the group reaching out to multiple news outlets starting Tuesday to share sample data and screenshots as proof of the intrusion. Reporters from the BBC have verified a small subset of the released data, which appears to be authentic. Reporting from Reuters also notes that some of the leaked samples include details of sensitive FBI operational assignments, including work targeting Chinese intelligence operatives, Russian spy networks, and transnational drug cartels.

Unlike most criminal hacking groups that target government and corporate systems for financial extortion, ShinyHunters says this breach was not carried out for profit. Instead, the collective says it launched the attack in retaliation for an FBI public service advisory that labeled the group as malicious “threat actors” and detailed its pattern of stealing sensitive personal data to extort payments from targeted organizations. The hackers say they were offended by the bureau’s characterization of their operations, and have issued a one-week ultimatum: the FBI must retract or correct the “false allegations” in the advisory, or the full stolen dataset will be published publicly on the dark web.

In an official statement posted to the social platform X shortly after the claims emerged, the FBI confirmed it is aware of ShinyHunters’ assertions and is “actively and aggressively investigating the matter.” The agency added that it is still working to determine whether the breach targeted FBI-owned systems or a third-party service provider, noting it is collaborating closely with vendors that support the FBIJobs.gov hiring portal to mitigate potential risks. The FBI declined to issue any additional comment in response to multiple requests from the BBC.

Cybersecurity analysts say the incident marks a significant escalation in the group’s activities, and highlights that even the most well-resourced U.S. law enforcement agencies are not immune to advanced criminal hacking operations. William Wright, a cybersecurity expert at Closed Door Security, described the incident as a deliberate retaliation attack, noting that the group’s core goal is to control public narrative around its activities and protect its reputation among cybercrime circles. “This demonstrates that no organization, no matter how advanced its security posture, is safe from this group when they set a target,” Wright explained.

ShinyHunters is a loosely organized international hacking collective that is believed to have originated in France. The group has built a reputation over the past year for high-profile intrusions against high-value targets: in April 2024, it claimed responsibility for a major breach of game developer Rockstar Games, and in May it carried out a disruptive hack against popular global education learning platform Canvas.