Hackers demand FBI retract advisory rather than seek payment

Shiny Hunters, an international collective of hackers believed to have originally started in France, claims to have breached FBI servers on Monday night and to have begun contacting reporters on Tuesday to share samples and screenshots of what the group says is stolen personnel data on all bureau staff — approximately 38,000 people — including anyone who applied to join the agency.

The group says the data includes every agent’s name, role, badge number, home address, phone numbers and spouse information. The BBC reported that a small portion of the data it reviewed appears to be genuine.

In a statement posted on X, the FBI said it was aware of the claim and that the agency was “actively and aggressively investigating the matter.” The bureau did not respond to multiple requests for comment from the BBC. In a separate statement on X, the agency said it was trying to determine whether the hackers had breached its systems or those of a third party. “We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk,” the post said.

According to Reuters, some of the stolen data contains details about officials’ job assignments, including sensitive work against Chinese spies, Russian intelligence and drug cartels.

Shiny Hunters says it exploited a vulnerability it claims to have found in the Oracle cloud storage system used by the FBI to reach multiple bureau systems: FBIJOBS, the agency’s hiring portal; FBI BEAST, which does background checks on employees and applicants; FBI MedLink, which holds agents’ medical records; and FBI BICS, which holds investigation information.

The group has previously taken credit for a breach at Rockstar Games in April and a “highly disruptive” hack on education platform Canvas in May.

In messages posted on the dark web, the group said it did not hack the FBI system for money. Instead, the cybercriminals asked the agency to retract an advisory it had issued about the gang, saying the group was “offended” by the bureau’s characterization. The FBI’s public-service announcement described Shiny Hunters as “threat actors” who often “use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims” and “target major companies across tech, finance, and retail, often stealing millions of customer records at once.”

Shiny Hunters said it would give the bureau one week to correct or remove what it says are false allegations or it would publish the full databases.

In a statement to the BBC, cybersecurity expert William Wright of Closed Door Security described the operation as a “retaliation attack” and said it demonstrated that “no organisation is safe from the group.” Wright said “the group clearly wants to control the narrative around their activities, ensuring nothing is said that could dent their reputation.”