A criminal hacking group known as ShinyHunters has claimed responsibility for breaching a sensitive database containing personnel information of thousands of current and former Federal Bureau of Investigation (FBI) employees and job applicants. The group announced the breach this week, describing it as a substantial compromise of the bureau’s private data, including names, home addresses, phone numbers, spouse information, and certain medical records.
The hackers said they accessed the information via an online FBI jobs portal, FBIJobs.gov, where the data was reportedly stored. They also published a message directed at FBI Director Kash Patel and Brett Leatherman, who oversees the bureau’s cybersecurity division, demanding the removal of a prior FBI advisory that warned of ShinyHunters’ tactics. The advisory, issued earlier this year, accused the group of harassing victims and their families through coercive measures. ShinyHunters gave the bureau a one-week deadline to retract the warning or face unspecified further consequences.
In response, an FBI spokeswoman confirmed the agency was aware of the claims and was investigating the incident. The bureau stated that the point of breach had not yet been determined, whether from within FBI systems or one of its third-party providers supporting the jobs website. FBIJobs.gov was taken offline following the breach, and at one point displayed a banner claiming the site had been seized by ShinyHunters.
Cybersecurity experts and current and former FBI officials familiar with the incident said the breach appeared credible and posed significant risks to public safety and national security. The exposure of detailed personnel information raises concerns about potential exploitation by foreign intelligence agencies, including those from China and Russia, as well as criminal elements seeking retaliation against agents involved in law enforcement operations.
“This data breach is a reminder that no one is immune from cyberthreats and, unfortunately, it raises serious public safety and counterintelligence risks,” said Simon Dantiki, a cybersecurity expert and former senior FBI and Justice Department official. Cynthia Ksiaze, a former FBI official who handled cyber investigations, added that the information could help criminals target agents and their families.
ShinyHunters has a history of high-profile intrusions, including attacks on the educational platform Canvas earlier this year and Ticketmaster in 2024, where it claimed to have compromised data on over 500 million users. However, some security researchers caution that the group occasionally exaggerates its accomplishments.
The FBI breach echoes the massive 2015 hack of the Office of Personnel Management, which resulted in the theft of millions of government employee records and was attributed by the U.S. government to China. That incident led to significant changes in how sensitive federal data is stored and protected.
The apparent vulnerability within the FBI’s recruitment system has raised questions about the bureau’s data protection measures. Former officials expressed surprise that such extensive, sensitive data was maintained in a manner susceptible to exploitation.
This incident follows a series of cybersecurity challenges faced by the FBI. Earlier this year, the agency detected Chinese hackers within a database related to domestic surveillance orders, and emails from Director Patel were reportedly compromised in March.
ShinyHunters has yet to reveal its full intentions regarding the stolen data. While the group said it was not motivated by financial gain, cybersecurity firm Flashpoint predicted the hackers may publicly release the information following their usual tactics against corporate victims. The group’s representatives declined to comment further on the nature of the breach or future plans. The investigation into the potential security failure and its implications remains ongoing.
