The cybercriminal group ShinyHunters claimed on Tuesday that they had breached the U.S. Federal Bureau of Investigation (FBI), stealing terabytes of sensitive personal information involving “virtually all FBI agents” and their spouses, as well as individuals who had applied for FBI positions. They also released samples purportedly from the stolen data, along with a manipulated screenshot of the FBI’s recruitment website. The alleged leaked information includes names, home addresses, and phone numbers.

Reuters reported that some identifiable matches were found in the sample data, though it could not verify whether the information was indeed obtained from FBI systems. The FBI has not confirmed whether a breach occurred or disclosed its scale. According to a source cited by 404 Media, an FBI spokesperson acknowledged awareness of potential unauthorized activity on FBIjobs.gov, and the bureau is currently investigating. On Tuesday, both the FBI’s recruitment website and agent application portal became temporarily inaccessible.

The hackers stated the intrusion began with the compromise of an Oracle PeopleSoft server—a software commonly used for human resources management—followed by access to a government cloud environment hosted by Amazon, which contains data on FBI personnel and applicants. Neither the FBI nor Amazon has publicly confirmed this account.

The attackers asserted the attack was not financially motivated. Instead, they demanded the FBI remove a cybersecurity advisory issued in May, claiming it contained false allegations against their organization. In that advisory, the FBI accused ShinyHunters-linked hackers of using threats, harassment, and even “swatting” incidents to target victims, while cautioning that cybercriminals often exaggerate the extent of data they have obtained. ShinyHunters did not specify what actions they would take if their demand were unmet. The FBI had previously issued warnings about the group in May.

If ShinyHunters’ claims are accurate, this would represent an exceptionally serious government data breach. The exposure of FBI agents’ identities, residences, contact details, and spouse information could be exploited by criminals, extremists, or foreign intelligence services to directly endanger lives. Similarly sensitive are the data of applicants—many of whom may have only submitted resumes—now at risk of being drawn into harm. Even more concerning is the reported point of entry: HR software and cloud infrastructure, underscoring vulnerabilities in government outsourcing and supply chains.

However, the FBI has not confirmed the breach, and the possibility of exaggeration remains, a common pattern in such incidents. That said, the temporary unavailability of the recruitment site suggests the investigation is not unfounded. The incident tests the FBI’s transparency: if verified, affected individuals should be notified promptly and offered protective measures; if overstated, the agency should release verifiable evidence to prevent public alarm.

The fact that the hackers are not seeking monetary gain but instead demand the removal of a security advisory indicates a shift in extortion motives—possibly reflecting retaliation, humiliation, or political intent. This adds complexity to the situation. Regardless of the ultimate truth, the episode serves as a reminder to governments worldwide: core security cannot rely solely on perimeter firewalls; personnel data, cloud services, and third-party software require the highest level of protection.

Original: toutiao.com/article/1877084565865610/

Disclaimer: This article reflects the personal views of the author.