
Hackers claim to hold sensitive information on 38,000 bureau personnel and are demanding a retraction of an FBI advisory.
AI-generated summary
The FBI issued a public service announcement in May characterizing ShinyHunters as threat actors who use exaggerated claims to extort victims. ShinyHunters is an international hacking collective.
The FBI says it is investigating a reported breach of its system after a cybercrime group claimed to have stolen sensitive information on thousands of bureau personnel.
The hackers, Shiny Hunters, say they now hold private data on all the bureau staff - around 38,000 people - including anyone who applied to join the investigative agency.
The group says it has every agent's name, role, badge number and personal details including home address, phone numbers and spouse information.
In a statement posted on X, the FBI said it was aware of the claim and the agency was "actively and aggressively investigating the matter".
The criminals claim to have breached the FBI's servers on Monday night and began contacting reporters on Tuesday sharing samples and screenshots of the stolen data.
The BBC has seen a small portion of the data which appears to be genuine.
According to Reuters, some of the data contains details about officials' job assignments, including sensitive work against Chinese spies, Russian intelligence and drug cartels.
ShinyHunters is an international collective of hackers, believed to have originally started in France. It has been behind a number of high-profile breaches including on Rockstar Games in April and a highly disruptive hack on education platform Canvas in May.
The group claims to have found a vulnerability in the Oracle cloud storage system used by the FBI to breach multiple systems including FBIJOBS, FBI BEAST, which does background checks on employees and applicants, FBI MedLink, which holds agent's medical records and FBI BICS, which holds investigation information.
In its message on the dark web, the group said it did not hack the FBI system for money.
Instead, the cybercriminals are asking the agency to retract an advisory that it issued in May about the gang, saying it was "offended" by its characterisation.
That FBI's public service announcement, external described ShinyHunters as "threat actors" who often "use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims".
"They target major companies across tech, finance, and retail, often stealing millions of customer records at once," the advisory said.
ShinyHunters said it would give the bureau one week to correct or remove what it says are false allegations or they would publish the full databases.
The FBI did not respond to multiple requests for comment from the BBC.
In its statement on X, the agency said it was trying to determine whether or not the hackers had breached its systems or a third party.
"We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk," the post said.
In a statement to the BBC, a cybersecurity expert said it was a "retaliation attack", which demonstrated that "no organisation is safe from the group".
"The group clearly wants to control the narrative around their activities, ensuring nothing is said that could dent their reputation," said William Wright of Closed Door Security.
AI outlook — possibilities, not facts
ShinyHunters will publish full databases if the FBI does not retract the advisory.
Possible · Within weeks

Within the scope of the fund investigation carried out by the Istanbul Chief Public Prosecutor's Office, 2 private jets determined to belong to Muhammed Yarız and Emre Tezmen and a luxury yacht determined to belong to Pusula's boss Serdar Turhan were seized. The total market value of the seized vehicles is estimated to be approximately 1 billion 8 million TL.
British police have arrested a 37-year-old right-wing extremist activist in the south of England on suspicion of intentionally damaging a refugee boat in the English Channel. According to media reports, it is Daniel Thomas, a companion of Tommy Robinson, who had previously published a live video of his action.

Aydın Provincial Police Department carried out simultaneous operations at 5 addresses throughout the province within the scope of the fight against smuggling and counterfeiting. During the operations, 490 liters of ethyl alcohol, 9 bottles and 35 liters of liquor, 107 alcohol flavors, 81 thousand 600 full and 402 thousand 600 empty tubes, 137 kilograms of loose tobacco and 5 cigarette rolling machines were seized. H.K., E.B., M.K. and B.S. 4 suspects named were caught; B.S. While they were released on condition of judicial control, others were arrested and sent to prison.

Last Tuesday in Modena, around fifty young students broke into an MD supermarket on Via Rainusso, looting shelves of drinks, food and other products while some filmed the action to publish it on social media. The raid, which lasted about ten minutes, created agitation among customers and employees. Mayor Massimo Mezzetti condemned the episode, underlining the need to address juvenile deviance with responsibility, reparation and re-education, and stated that the minors responsible will be identified and held accountable for their actions.

Between September 15 and 20, 11.75 million XRP was stolen from 6,678 accounts linked to the D'CENT mobile application. Attackers used the AccountDelete function of the XRP Ledger to siphon funds after a private key compromise.

In the Alli District of Çarşamba district, 4 people presented themselves as religious officials to Erol Keskin, who was preparing for the pilgrimage, and made him sign documents saying, 'The Presidency of Religious Affairs sent you cargo because you are going to go on pilgrimage.' Approximately 10 days after Keskin went abroad, the enforcement notice for 17 million TL was received. During the gendarmerie operation upon the complaint of his son Murat Keskin, A.O., O.Y., G.Y. and I.K. caught.