Summary
- An internal memo from the FBI has advised staff to consider their personal information compromised following a breach of FBIjobs.gov.
- The hacker group ShinyHunters claims to have stolen 2 to 3 terabytes of data, including details about agents, applicants, and their spouses; the FBI is currently investigating the breach.
- Brett Leatherman, chief of the FBI Cyber Division, addressed the hackers on September 29, highlighting a recent arrest in the Netherlands and the expiration of the group's ultimatum.
The FBI has alerted its employees to the possibility that hackers may have accessed their personal data, as indicated in an internal memo disclosed this week by Reuters. The agency is operating under the assumption that the personal information of all staff members could be compromised due to a breach of its jobs website, FBIjobs.gov.
The group claiming responsibility for the breach, ShinyHunters, alleges it has gathered data on nearly every FBI agent along with information on job applicants. They estimate that the stolen data amounts to between 2 to 3 terabytes, which includes names, phone numbers, home addresses, and in some instances, details about spouses.
According to ShinyHunters, the breach began on the night of September 22, when visitors to the website saw a banner indicating it had been taken over by the group.
The hackers claim they exploited a previously unidentified vulnerability in Oracle's PeopleSoft, a widely used human resources software. This type of flaw is known as a zero-day, meaning it is unknown to the vendor and lacks a fix. The FBI has yet to verify the method of the breach.
ShinyHunters has suggested that the breach was provoked by an FBI advisory issued on May 15, which warned that the group engages in harassment tactics, including threats to the families of victims and instances of swatting, where fake emergency calls lead armed police to a victim's home.
The group has denied this assertion and has given the FBI a week to retract its warning.
ShinyHunters is not a new entity; it first became known in 2020 for selling stolen databases on hacker forums and was involved in operating BreachForums, one of the largest forums for stolen data. Last year, the group claimed to have obtained approximately 1.5 billion records from Salesforce, a well-known customer data platform.
In response, Brett Leatherman of the FBI Cyber Division released a video on X on September 29, referencing a Dutch arrest from September 15 and stating, "we know how to find you." He suggested that the hackers reach out to the bureau first, to which the group responded by asserting that the arrested individual had no ties to them.
The FBI suggests cooperation with ShinyHunters: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours. pic.twitter.com/LP90fjlsnO
— Ken Klippenstein (@kenklippenstein) September 29, 2026
ShinyHunters later claimed that the ultimatum was merely a marketing strategy and that they have no plans to release the stolen data. The internal memo also advises employees to anticipate virtual briefings and to remain vigilant for suspicious communications from unknown contacts.
The significance of home addresses is heightened by the potential for doxxing, where personal information is made public, leading to threats, identity theft, and risks to the safety of family members of affected FBI employees.
Previous incidents in the cryptocurrency sector have shown similar patterns. For instance, Coinbase reported that bribed support agents leaked customer data last year, which led to a $20 million extortion demand. France has recorded 135 crypto-related “wrench attacks” this year, resulting in the arrest of 88 suspects.
In one case, attackers assaulted a couple outside their residence in Nancy, obtaining their information from a January leak at Waltio, a French crypto tax platform that had exposed around 50,000 users’ details.
The deadline set by the hackers has since passed, and ShinyHunters has stated it will not release the data. The memo, as reported, instructs staff to assume their data has already been compromised.
