Spreadsheet with FBI employee data stolen by hackers exposes counterintelligence agents
File obtained by the ShinyHunters group lists names, addresses and functions of thousands of servers, including sectors focused on China, Russia and Iran.
Quick Look
A spreadsheet with data from thousands of FBI employees, allegedly obtained by the hacker group ShinyHunters, exposes information from agents involved in sensitive operations against China, Russia, Iran and Hezbollah, according to a Reuters analysis.
AI-generated summary
Why It Matters
The ShinyHunters group claimed to have hacked FBI systems and stolen employee data to pressure the agency following statements made in May.
A spreadsheet of FBI employee data, allegedly stolen by the hacker group ShinyHunters, contains information about agents involved in operations related to China, Russia, Iran, Hezbollah, surveillance and human intelligence, according to a Reuters analysis.
The file has around 5 thousand lines and, according to the hackers, represents only a small part of a 2 to 3 terabyte data set that would be in the group's possession. The spreadsheet includes names, addresses, telephone numbers, dates of birth, Social Security numbers and emergency contacts assigned to thousands of FBI employees.
According to Reuters, the data also indicates the offices and units in which certain employees work, including sectors linked to intelligence, security and counterintelligence activities.
Among the information found is 14 employees related to activities involving China, including members of units identified as “China criminal enterprise unit”, “China tech transfer analysis unit” and “China intelligence section”.
Another nine employees appear associated with Russia-related functions. Among them are two members of the so-called “Russia Operations Section” and an employee linked to threats to Russian infrastructure and technology.
The spreadsheet also lists three people with intelligence activities focusing on Iran or Hezbollah. Another 18 employees are identified in roles related to data interception and telecommunications technologies, clandestine technical operations, covert access and surveillance by video, audio or electronic means.
There are also 11 employees associated with the so-called HUMINT, an acronym in English for intelligence obtained from human sources.
FBI says it is investigating hacking
In a statement, the FBI said it is aware that a group of cyber criminals claims to have compromised the FBIJobs.gov portal and obtained employees' personal information.
The agency said the cause of the possible leak has not yet been determined and that it is investigating the case.
ShinyHunters said Tuesday it broke into FBI systems and stole data from current and former employees. The group said it is keeping the information as a way of pressuring the agency to withdraw a statement it made in May about the hackers.
Reuters was unable to authenticate the entire spreadsheet. However, the agency claims to have individually confirmed information from more than 22 people by comparing the leaked data with credit records and information from previous leaks obtained by dark web intelligence platform District 4 Labs.
Reuters also verified the professional information of eight people by comparing the data with court cases, news reports, public LinkedIn profiles and social media posts. Still, the agency emphasizes that it was not possible to confirm whether all functions assigned to employees are authentic or up to date.
Experts point out risk for agents
For Eric O’Neill, a former FBI counterintelligence agent, the allegedly stolen data could have great value for foreign intelligence services. He told Reuters that countries interested in FBI operations could seek information about employees involved in those activities.
Trevor Hilligoss, a former United States Army investigator who worked with the FBI, drew particular attention to the identification of employees linked to human intelligence. According to him, the exposure of this information may represent an additional risk for people working in confidential functions.
The leak also includes emergency contacts. Hilligoss highlighted that this information may involve employees' spouses or children, who may have less knowledge about operational security procedures.
Hackers say they have more data
ShinyHunters told Reuters that it has other files in addition to the published spreadsheet. The group had previously said it had obtained documents related to vetting employees and candidates, hiring background investigations and sensitive medical data from agents.
Reuters, however, was unable to verify what else was in the hands of the hackers.
The FBI said in May that ShinyHunters had, on some occasions, made exaggerated claims about accessing sensitive or personal information to pressure victims into paying. The group denies that its threats are false and claims that the FBI statement was one of the reasons for attacking the agency.
What to Watch
AI outlook — possibilities, not facts
Official FBI investigation into the cause of the leak
Very likely · Within weeks
Open Questions
- What was the exact cause of the break-in and leak?
- Does the group really have 2 to 3 terabytes of data?






