Skip to main content

FBI investigates hackers’ claim of stolen personnel data

FBI investigates hackers’ claim of stolen personnel data
— Foto: BBC World

The ShinyHunters group says it accessed sensitive information on about 38,000 FBI personnel and applicants. The agency said it was investigating whether its systems or a third-party provider had been breached.

ru

The FBI is investigating a reported cyber breach after the hacking group ShinyHunters claimed it had stolen sensitive information on thousands of bureau personnel, according to the BBC.

The group says it holds data on about 38,000 people, including FBI employees and individuals who applied to join the agency. The alleged records include names, job roles, badge numbers, home addresses, telephone numbers and information about spouses.

In a statement on “X”, the FBI said it was aware of the claim and was “actively and aggressively investigating the matter”. The bureau said it was also working with third-party providers supporting “FBIJobs.gov” to assess and mitigate potential risks.

Hackers claim access to several FBI systems

ShinyHunters said it breached the FBI’s servers on Monday night and began contacting journalists the following day, sharing samples and screenshots of the alleged stolen data. The BBC said it had reviewed a small portion that appeared to be genuine.

According to Reuters, some of the information reportedly includes officials’ job assignments, including work involving Chinese spies, Russian intelligence and drug cartels.

The hackers claimed they exploited a vulnerability in the Oracle cloud storage system used by the FBI. They said the breach affected several systems, including “FBIJOBS”, “FBI BEAST”, which conducts background checks on employees and applicants, “FBI MedLink”, which stores medical records, and “FBI BICS”, which contains investigation-related information.

Group issues a one-week ultimatum

In a message posted on the dark web, ShinyHunters said it had not targeted the FBI for financial gain. Instead, the group demanded that the agency withdraw an advisory about it, saying it was offended by the FBI’s description of the group.

The FBI advisory called ShinyHunters “threat actors” and said they often make real or exaggerated claims about access to sensitive or personal information in an effort to obtain payments from victims. It also said the group targeted major technology, financial and retail companies, sometimes stealing millions of customer records.

ShinyHunters said the FBI had one week to correct or remove what the group described as false allegations, or it would release the full databases.

The FBI did not respond to multiple BBC requests for comment. The agency has not confirmed whether its own systems were compromised or whether a third-party provider was breached.

This article was processed automatically and checked by the editorial team.

Author

Editorial board

All their articles ›

Related news

Loading next story…