It is reported that the Federal Bureau of Investigation (FBI) has informed its agents and support staff that their personal information was stolen in a recent cyberattack targeting the bureau's recruitment application portal.
This is the first time that the agency has admitted that the personal information of agent FBI was compromised in this data breach incident. FBI had not previously confirmed a data leak publicly, only stating last week that they were aware of a hacker group claiming to have launched a cyberattack, but whether the data was stolen "remains uncertain."
According to a report by journalist Ken Dilanian on the weekend, FBI subsequently announced in an internal notice that a "cybersecurity incident" had occurred, informing employees that their names, addresses, job titles, and social security numbers had been leaked.
Subsequent confirmation from multiple media outlets indicated that some of the stolen data also included medical information, such as records related to blood and urine samples, as well as psychiatric reports.
A hacker group named ShinyHunters previously told TechCrunch that they "possessed the data of most people from FBI", and claimed that a "large amount" of information from those who applied through the FBIJobs.gov portal was obtained. The hackers invaded by exploiting a vulnerability in a Oracle PeopleSoft server, which stored a large amount of human resources information, including agents and current employees who applied through that portal.
Hackers told TechCrunch that they are not seeking a monetary ransom, but rather demand the correction of a report previously published by FBI; they claim that the report distorts their activities.
In a blog post written for Lawfare, national security expert Justin Sherman referred to this data breach as an "anti-intelligence disaster" by the U.S. government. He warned that the theft of these data will "expose thousands of FBI personnel to additional risks such as profiling analysis, phishing attacks, and contact with foreign intelligence services."
Although FBI has informed its employees, it is still unclear whether the agency has reported this incident to the U.S. Congressmember who has supervisory responsibilities over FBI. According to federal law, when an intrusion meets the criteria of a "significant event," Congress must be notified—for example, if a data breach involves the theft of personal identification information and "is likely to cause demonstrable harm to U.S. national security."
At present, it seems that lawyer FBI may be assessing whether this standard applies. If disclosure is necessary, this would be the second time this year that FBI has reported a data breach incident to members of Congress. Earlier this year, suspected Chinese hackers infiltrated a monitoring system, exposing information about the subjects of surveillance and investigation by FBI.
FBI spokesperson did not respond to TechCrunch's request for comment on Monday, nor did the White House spokesperson reply to an email asking whether the agency had announced any major events.
Representatives from the offices of several members of Congress responsible for overseeing FBI also did not provide an immediate answer.
ABC News reports that since 2017, the recruitment website of FBI has been the main channel for applying to join the organization. As of the time of this article's publication, the portal is still closed.
If you work at FBI and have received a notification regarding this data breach, please do not hesitate to contact us. You can reach this journalist via Signal using the secure contact information zackwhittaker.1337, or you can send an email to zack.whittaker @ techcrunch.com.












