The hacker group ShinyHunters claims it breached the FBI’s systems and stole large amounts of personal data in the process. The FBI has not confirmed the extent of the alleged data breach but is investigating unauthorized activity involving its job recruitment systems.
According to ShinyHunters, the group stole data from current and former FBI employees, as well as people who have applied for jobs with the U.S. investigative agency. The group cites two to three terabytes of data and claims to have information on virtually all FBI employees and job applicants.
404 Media verified a portion of the allegedly stolen material. The hackers provided a sample containing data on approximately 5,000 FBI employees, including names, home addresses, phone numbers, dates of birth, and, in some cases, information about partners.
Several phone numbers turned out to be linked to individuals with the same names as those in the file. Other data could be linked to employees of the U.S. Department of Justice. This supports the authenticity of some of the data, but not the claim regarding the size of the haul.
Job site hijacked
On Tuesday, ShinyHunters also managed to “deface” the FBI’s job site. A message appeared stating that the site had been taken over by the hackers, parodying the warnings that U.S. law enforcement agencies post on compromised websites. The FBI subsequently reported that both Apply.fbijobs.gov and the Special Agent Applicant Portal were unavailable.
The group claims to have exploited a zero-day vulnerability in Oracle PeopleSoft. This software is used for human resources and recruitment, among other things, and may therefore contain a significant amount of personal data. From within PeopleSoft, the attackers reportedly accessed servers on AWS GovCloud. This technical sequence of events has not been confirmed by the FBI, Oracle, or AWS.
No financial motive
ShinyHunters is known for attacks in which it uses stolen data to extort organizations. Just last month, the group attempted to breach the security firm ReliaQuest via social engineering and MFA abuse. This time, however, the group says it is not acting for financial gain.
The reason appears to be an earlier FBI report in which ShinyHunters is accused, among other things, of exaggerating the amount of stolen data to pressure victims into paying. The group is also alleged to have threatened victims and their family members and to have engaged in swatting. ShinyHunters is demanding that the FBI correct or remove the report within a week.
If the scale of the theft is confirmed, the information involved is highly sensitive. Home addresses, phone numbers, and details about partners could be misused to identify or put pressure on FBI employees.
This is not the first security incident involving the FBI this year. TechCrunch points to an earlier breach of a system for real-time wiretaps and surveillance warrants. In March, the Iran-linked hacker group Handala also hacked and leaked FBI Director Kash Patel’s personal email account.