According to a report by Reuters this week, FBI has informed its employees that they should assume that hackers have stolen their personal information. The organization is working on the premise that its recruitment website FBIjobs.gov has been compromised, believing that the data of each employee may have been leaked.
The hacker group ShinyHunters claims responsibility for this. The gang stated that they have access to the data of nearly all FBI agents as well as those who have applied for FBI jobs, with a volume of about 2 to 3TB. The data includes names, phone numbers, home addresses, and sometimes information about spouses as well.
If what this gang claims is true, it's not just the agents who will be affected. According to them, anyone who has applied for the FBI job could appear in these documents.
The gang claimed that the intrusion occurred on Monday evening, and by Tuesday, September 22, visitors noticed that the website pages were displayed to be under the control of ShinyHunters.

The gang also claimed that they entered the system through a previously unknown vulnerability in Oracle PeopleSoft. PeopleSoft is software used by many organizations to operate their human resources systems. Security experts refer to such vulnerabilities as zero-day vulnerabilities, which are ones that the manufacturers are not yet aware of and therefore have no fix for yet. The method of intrusion in FBI has not been confirmed yet.
The gang stated that the triggering event was a notice published by FBI on May 15th. At that time, FBI warned that ShinyHunters would use harassment tactics, including threatening the victims' families, and in some cases, they would also use “swatting” – that is, false emergency calls – to lure armed police to the doorsteps of certain households.
ShinyHunters denied this claim and gave FBI one week to withdraw that warning.
ShinyHunters is not a newly emerged gang. It came to light in 2020 when they sold stolen databases on hacker forums and also helped operate a large hacker forum, BreachForums. Last year, the organization claimed to have obtained approximately 1.5 billion records of Salesforce customers. Salesforce is a widely used customer data platform.
Subsequently, FBI responded. FBI, the head of the network department, Brett Leatherman, posted a video on X on September 29th, mentioning an arrest that occurred in the Netherlands on September 15th, and said to the hackers, "We know how to find you." He urged them to contact FBI first, while the gang stated that the arrested man had nothing to do with them.
ShinyHunters subsequently stated that this ultimatum was merely part of a marketing campaign, and claimed no intention to make these data public. The memo also advised employees to expect online briefings and to be wary of suspicious text messages or calls from unfamiliar numbers.
Why is a home address so important? Because stolen data rarely stays only on screens. If this data is made public and employees are subject to online stalking (also known as "human flesh search"), they may face threats or harm, and there could be a surge in cases of identity theft. Relatives of those employees who are targeted by such searches may also be at risk.
Similar patterns have occurred in the encryption industry before. Coinbase mentioned that last year, bribed customer service staff leaked customer data, which led to the company facing a ransom demand of 20 million US dollars. As of April, France has recorded 135 cryptocurrency-related "latchkey attacks" since 2023 and has charged 88 suspects.
In one case, the assailant beat a couple outside an apartment in Nancy, and it is alleged that their personal information came from a French encrypted tax platform Waltio during a data breach in January. That incident exposed the personal details of approximately 50,000 users.
The time limit set by the hackers has passed, and ShinyHunters indicates that these data will not be made public. According to reports, the memo requires employees to assume that their data has already been leaked.











