FBI Tells Employees to Assume Personal Data Stolen After Claimed Hack
Quick Look
The FBI instructed employees to assume their personal information was stolen after cybercriminal group ShinyHunters claimed a breach of FBIjobs.gov via a zero-day flaw in Oracle's PeopleSoft, potentially exposing names, addresses, and family details of agents and applicants.
AI-generated summary
Why It Matters
ShinyHunters is a cybercrime group active since 2020, known for selling stolen data and involvement with BreachForums. The FBI previously warned about the group's harassment tactics, including swatting and threats to family members.
The FBI has told its own employees to assume hackers stole their personal information, according to an internal memo reported this week by Reuters. The bureau is working from the premise that data on every staffer may be out, after a claimed breach of its jobs site, FBIjobs.gov.
The group claiming credit is ShinyHunters, a cybercrime crew that says it holds data on almost all FBI agents and everyone who applied for an FBI job. It puts the haul at 2 to 3 terabytes, including names, phone numbers, home addresses, and sometimes spouse details.
If the group is right, the damage reaches past agents. Anyone who applied for an FBI job could be in the files, by the group's account.
The group says the intrusion began Monday night, and by Tuesday, Sept. 22, visitors saw a banner saying the site had been seized by ShinyHunters.
The group says it got in through a previously unknown flaw in Oracle's PeopleSoft, software many organizations use to run HR. Security people call that a zero-day: a bug the vendor doesn't know about, so there is no fix yet. The FBI has not confirmed the method.
The group says the trigger was an FBI advisory. In that May 15 notice, the bureau warned that ShinyHunters uses harassment, including threats to victims' family members and, in some cases, swatting—a fake emergency call that sends armed police to someone's door.
The group denies that. It gave the bureau one week to retract the warning.
ShinyHunters is not new. It surfaced in 2020 selling stolen databases on hacker forums, and helped run one of the biggest, BreachForums. Last year it claimed about 1.5 billion records from customers of Salesforce, a popular customer-data platform.
Then the FBI hit back. Cyber Division Chief Brett Leatherman posted a video on X on Sept. 29, pointing to a Dutch arrest from Sept. 15 and telling the hackers "we know how to find you." He urged them to reach out first, and the group says the arrested man has no association with it.
ShinyHunters later said the ultimatum was a marketing campaign and that it doesn't plan to publish the data. The memo also tells staff to expect virtual briefings and to watch for suspicious texts or calls from unknown numbers.
Why would a home address matter that much? Because stolen data rarely stays on a screen. If that data is released and employees get doxxed, employees could be threatened or harmed, identity theft cases may surge and relatives of doxxed FBI employees could be at risk.
Crypto has already shown the pattern. Coinbase said bribed support agents leaked customer data last year, then faced a $20 million extortion demand. As of April, France had recorded 135 crypto-related “wrench attacks” since 2023, and had charged 88 suspects.
In one case, attackers who beat a couple outside their Nancy apartment reportedly got their details from a January leak at Waltio, a French crypto tax platform that exposed about 50,000 users.
The one-week window the hackers set has passed, and ShinyHunters says it will not publish the data. The memo, as reported, tells staff to assume their data is already out.
What to Watch
AI outlook — possibilities, not facts
FBI will implement enhanced security measures for employee data and job application systems
Likely · Within weeks
Increased monitoring for phishing attempts and social engineering targeting FBI personnel
Very likely · Within days
Open Questions
- Whether the claimed breach of FBIjobs.gov actually occurred
- What specific data was accessed or exfiltrated
- Whether ShinyHunters will release the data despite current claims
- The full extent of risk to applicants and employees' families







