FBI confirms ShinyHunters breach of FBIJobs.gov portal
The Federal Bureau of Investigation has confirmed that the cybercriminal group ShinyHunters claims to have compromised the FBIJobs.gov portal, although the Bureau has not yet determined whether the breach originated…
The Federal Bureau of Investigation has confirmed that the cybercriminal group ShinyHunters claims to have compromised the FBIJobs.gov portal, although the Bureau has not yet determined whether the breach originated within its own systems or at a third-party provider. In a statement issued on Sept. 23, the FBI said it is actively and aggressively investigating the incident while working with third-party providers to reduce potential risk. The point of breach remains unresolved, a distinction that complicates the assessment of how sensitive personnel and applicant data was accessed.
ShinyHunters alleges it stole between 2 and 3 terabytes of information connected to current and former FBI personnel and job applicants. The group claims to have exploited a previously unknown vulnerability in Oracle PeopleSoft, software reportedly used by the FBI for human resources functions. While the FBI acknowledged the group's claims of compromise, it did not verify the specific technical method or the total volume of data stolen. The Bureau also noted that the Special Agent Applicant Portal, which supports individuals in the special-agent hiring process, became unavailable on Sept. 22.
Reuters reported that a spreadsheet provided by ShinyHunters to journalists contains approximately 5,000 alleged FBI personnel records. The reported data includes names, home addresses, phone numbers, dates of birth, Social Security numbers, and emergency contact information. Reuters stated it could not authenticate the entire spreadsheet but independently verified details belonging to more than 22 people by comparing them with credit records and earlier leaked data. The outlet also matched career information for eight individuals against court filings and public profiles.
404 Media separately reported that the sample contained information involving FBI employees' spouses and identified members of the FBI's Remote Operations Unit. This secretive team is involved in developing hacking tools to access target devices. Reuters found records identifying personnel connected to China-related investigations, Russian intelligence work, and electronic surveillance. The publication cautioned that it could not verify if every assignment was authentic or up to date, noting that real information can appear in multiple databases.
In response to the alleged breach, Dutch police arrested a 24-year-old Amsterdam man on Sept. 15 following a joint operation with the FBI. The arrest was announced as that of an alleged ShinyHunters leader. ShinyHunters stated that retaliation motivated the attack, citing an advisory published by the FBI's Internet Crime Complaint Center on May 15 that described the group's activities in large-scale data breaches and extortion. The group has demanded that the FBI rescind that statement while holding the allegedly stolen data.
The FBI's May advisory warned that ShinyHunters actors may use real or exaggerated claims about stolen information to pressure victims through threatening communications and harassment. The Bureau recommends that individuals verify unusual requests through independent channels and avoid engaging with threat actors. For those who applied for FBI jobs, officials advise contacting existing coordinators directly rather than using links from unexpected messages. The FBI has not yet announced whether affected individuals will be notified or offered identity protection services.
Filed via foxnews.com