FBI Jobs Site Defaced by ShinyHunters, Claims Agent Data

The FBI’s online job portal was briefly taken down after the theft‑and‑extortion crew ShinyHunters replaced the applicant page with a seizure banner. The group claims to have stolen personal details of roughly 5,000 FBI employees and applicants, and has issued a demand to the bureau to retract a Ma…

By Felo News Desk · Published

The FBI’s official job portal, fbijobs.gov, was temporarily defaced on Tuesday after the hacking collective ShinyHunters replaced the applicant page with a banner that read, “This site has been seized by ShinyHunters.” The banner also claimed the group had obtained home addresses, phone numbers, and family information for almost every FBI agent and anyone who had applied for a position with the bureau.

Who is ShinyHunters?

ShinyHunters is a theft‑and‑extortion hacking crew that the FBI publicly warned companies about in May. The group has a history of leaking data from a variety of targets, including a 2016 leak that continues to be used to harass FBI agents. Their tactics often involve sending threatening texts, phone calls, and, in some cases, swatting. In the current incident, ShinyHunters has also claimed to have exploited a zero‑day vulnerability in Oracle’s PeopleSoft software to gain initial access to the FBI’s systems.

What Data Did They Claim to Steal?

According to ShinyHunters’ leak site and communications with reporters, the group says it has data on about 5,000 FBI employees and applicants. The sample they released included rows with addresses, phone numbers, dates of birth, and, in some cases, spouse names. While outlets that examined the data found that some of the information appears authentic, none of the evidence proves that the bureau’s entire personnel database was emptied during the attack.

  • Sample included 5,000 alleged FBI employees and applicants.
  • Data fields: address, phone number, date of birth, spouse name.
  • Some phone numbers matched U.S. Department of Justice personnel in a District 4 archive of older breaches.
  • Reuters cross‑checked names, addresses, and Social Security numbers against credit‑bureau records and found at least ten apparent hits, including FBI Director Kash Patel.
  • No confirmation from the FBI, Oracle, or Amazon that the PeopleSoft vulnerability was exploited.

How the Group Claims They Got In

ShinyHunters’ representative told 404 Media that the intrusion began Monday night and was enabled by an unknown bug in Oracle’s PeopleSoft software. From there, the group allegedly moved laterally to Amazon’s GovCloud, downloading between two and three terabytes of data. The group also said they used the jobs site as the entry point and that they were able to access different services and FBI databases. None of this chain of events has been verified by the FBI, Oracle, or Amazon.

What the FBI Has Said

The bureau confirmed that it is aware of the claims regarding unauthorized activity affecting fbijobs.gov and is currently investigating. By Tuesday afternoon, the parody banner had disappeared, and the Apply and Special Agent Applicant Portal pages were marked as “currently unavailable.” The FBI’s statement emphasized that the incident is under investigation and that they are working to restore the site.

Potential Motives and Demands

ShinyHunters has stated that the intrusion is not financially motivated. Instead, they claim to be seeking to coerce the bureau into retracting a May report that, in their view, made false allegations. The group’s letter on their leak site is addressed to FBI Director Kash Patel and Assistant Director Brett Leatherman of the cyber division. They also threaten to release additional data if the bureau does not comply with their demands.

Broader Context and Implications

This incident is part of a larger trend of personal data leaks that affect government employees. Earlier this month, a dark‑web shop listed more than 153 million U.S. and Canadian driver’s license scans for sale, including IDs tied to government officials. The ShinyHunters group has a history of targeting identity‑protection firms, telecom companies, and even adult‑content platforms, often using the stolen data to harass victims or to pressure them into paying ransoms.

Security experts warn that once sensitive personal data is stolen, it can be used indefinitely. Cynthia Kaiser, a former senior FBI cyber official now at Halcyon, noted that the FBI tends to marshal additional resources when a group attacks the bureau directly. She also highlighted that older leaks, such as the 2016 ShinyHunters breach, continue to be used to harass agents.

What Happens Next?

Investigators are treating ShinyHunters’ claims as credible and are conducting a thorough review of the alleged breach. The FBI has not yet confirmed whether the data was extracted from live systems or from a backup. The bureau is also evaluating the potential impact on its personnel and will likely issue guidance on how agents can protect themselves from harassment. The outcome of the investigation will determine whether the group’s demands are met and whether any legal action will be taken against the hackers.

Until the FBI releases a full statement, the extent of the breach remains uncertain. However, the incident underscores the importance of robust cybersecurity measures for government agencies and the ongoing threat posed by sophisticated hacking collectives.

Key facts

  • FBI jobs portal defaced by ShinyHunters with a seizure banner
  • Group claims to hold personal data on ~5,000 agents and applicants
  • Investigators treat the claim as credible but no proof of live system breach
  • ShinyHunters alleges a zero‑day PeopleSoft vulnerability was used
  • FBI is investigating and has not confirmed the data extraction path
  • The incident underscores the risk of personal data leaks for government employees

Why it matters

The breach highlights the vulnerability of federal personnel data and the potential for personal information to be weaponized against government employees. It also raises concerns about the effectiveness of current cybersecurity defenses within the FBI.

Frequently asked questions

What is ShinyHunters’ history of hacking?

ShinyHunters is a theft‑and‑extortion crew known for leaking data from various targets, including identity‑protection firms, telecom companies, and adult‑content platforms. They often use harassment tactics such as threatening texts, phone calls, and swatting.

Has the FBI confirmed the data was stolen from live systems?

No. The FBI, Oracle, and Amazon have not confirmed that the PeopleSoft vulnerability was exploited or that data was extracted from live FBI systems.

What is the FBI’s current response?

The FBI has acknowledged the incident, is investigating, and has temporarily taken down the affected pages on its job portal.

What could agents do to protect themselves?

Agents should monitor for suspicious activity, report any harassment, and follow any guidance issued by the FBI on protecting personal data.

Sources

  • [1] gizmodo.com — originally reported as “Hackers Defaced the FBI Jobs Site and Say They Have Agents’ Home Addresses”

More from World

Felo News, House 42, Bridge Colony, Kot Lakhpat, Lahore, Pakistan
+92 308 4354717 · felopronews@gmail.com