ShinyHunters Claims Full FBI Employee Data Breach

Original: 'We hacked the FBI:' Hackers say they have data on all FBI employees

Why This Matters

Exposed agent home addresses and spouse data create direct physical risks and counterintelligence exposure at scale.

Hacking group ShinyHunters claims to have breached FBI-related systems using an Oracle PeopleSoft zero-day, stealing 2–3 TB of data including names, home addresses, phone numbers, and spouse details on all FBI employees and applicants. A 5,000-record sample was shared with 404 Media.

ShinyHunters, a high-profile hacking group, told 404 Media it breached multiple FBI-related services and exfiltrated data on all FBI employees and applicants. The group provided a sample of 5,000 alleged records containing names, home addresses, dates of birth, phone numbers, and in some cases spouse details. 404 Media verified that several phone numbers in the sample matched the listed names using OSINT Industries, and further cross-referencing via cybersecurity firm District 4's Darkside tool linked some numbers to DOJ personnel.

ShinyHunters said the attack, carried out on a Monday night, exploited a zero-day vulnerability in Oracle's PeopleSoft HR platform, then pivoted to AWS GovCloud servers to download between 2 and 3 terabytes of data. The group also defaced the FBI jobs website (apply.fbijobs.gov) with a message mimicking FBI seizure notices and ending with a mock Trump Truth Social sign-off.

The FBI confirmed awareness in a statement: 'The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.' The site remained offline at publication. Members of ShinyHunters' broader network have previously used hacked data to track and harass FBI agents, raising immediate concerns about agent safety and potential exploitation by foreign intelligence services.

Source

404media.co — Read original →