The theft by a criminal hacking group of reams of sensitive personal data involving potentially tens of thousands of former and current F.B.I. employees is emerging as one of the worst breaches of sensitive government information, leaving the bureau rushing to protect its personnel as a deadline looms.
Nearly a week after the group, known as ShinyHunters, revealed it had pilfered intimate details about bureau personnel from the agency’s jobs portal and threatened to leak them online, F.B.I. investigators are still piecing together how the breach took place and the total damage.
The hack appears to have swept up home addresses, Social Security numbers, secretive job assignments and much more, according to a New York Times analysis of some of the records. Some are already comparing it to China’s breach of more than 20 million records from the Office of Personnel Management over a decade ago, considered so catastrophic that officials and lawmakers vowed to never let something like it happen again.
Many F.B.I. employees first learned about the hack when news reports about it surfaced on Tuesday, according to current and former officials. The next day, F.B.I. staff received an email reminding them that October is cybersecurity awareness month, which struck some as tone deaf in light of the breach, one of those people said.
On Friday, bureau leaders, in an internal memo to its rank and file, declared the hack a cybersecurity incident and acknowledged its employees had personal information stolen.
“We are operating under the premise that the threat actor is also exfiltrating PII of all F.B.I. employees,” according to the memo, which was described by someone who had seen it, using the abbreviation for personally identifiable information.
The memo said the agency would offer virtual briefings in the weeks ahead and instructed employees to remain vigilant at home and at work, report any unsolicited contacts or threats, avoid answering calls from unknown numbers and set up voice mail accounts with A.I.-generated voices. “Bureau leadership remains committed to supporting the safety of you and your family,” it said.
Still, many past and present personnel remain in the dark about whether their data has been purloined. In recent days, some have anxiously asked Times reporters whether their names are contained in the hacked data, wondering whether they needed to take steps to protect themselves or their families.
In a statement on Monday, the agency said it was “working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple bureau-wide communications within 24 hours of public reporting.”
It added, “The F.B.I. treats the security of its information and the safety of its work force as top priorities, and our investigation is ongoing.”
In announcing its hack, ShinyHunters said it had targeted the F.B.I. as retribution for a public advisory the bureau had issued in the spring warning that the group was known to harass victims and family members with threatening or coercive maneuvers. In their note, the hackers demanded that the F.B.I. “correct or simply REMOVE” the advisory or risk further consequences.
In an email to The Times, ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request, even as the hackers themselves appeared to acknowledge that the bureau was unlikely to acquiesce.
“It does not matter at all, whatsoever, if the F.B.I. removes or corrects their statement on us or not, we got what we wanted REGARDLESS,” the group wrote. “We were never extorting them into removing or correcting it in the first place. We know very well the F.B.I. won’t and we never cared whether they changed it or not.”
It remains to be seen if ShinyHunters will follow through with its threat to leak the data. It is also unclear just how much sensitive information the hackers stole. The group claimed publicly to have stolen records on everyone who has applied for a job at the F.B.I., and told The Times that the people with compromised information numbered in the tens of thousands.
Ciaran Martin, the former head of Britain’s cyberdefense agency, said the F.B.I. hack likely had “huge impact on the operational capability” of the bureau and could rank as one of the most consequential data breaches in history — graver even than the Office of Personnel Management burglary.
“Losing the data on 20 million federal employees to the Chinese was bad,” Mr. Martin said. “But you knew the Chinese weren’t going to sell or publish it.”
From Sensitive Jobs Assignments to T.S.A. PreCheck
A sample of records that the hackers have shared with The Times and other news organizations includes newer hires as well as retired ones, with birth dates ranging from the early 1940s to the mid 2000s. The most recent date references in the spreadsheet were from late April, suggesting the stolen files are at most only months old.
Current and former U.S. officials said that at least portions of the sample, and potentially all of it, appeared to be authentic.
A Times review of the sample found that it contained a range of private personal data, including:
-
The names, home addresses, phone numbers, work emails, Social Security numbers and birth dates and hire dates of current and former F.B.I. personnel.
-
Names and numbers for spouses and other emergency contacts, including in some cases parents, siblings and even children.
-
Employee identification numbers that are used for the Transportation Security Administration’s PreCheck program, which could aid spies in tracking travel itineraries of agents, including those that work undercover.
-
Names of the units in which F.B.I. personnel are employed and their job titles, as well as the names of supervisors. While some list mundane departments, others reveal extraordinarily sensitive assignments including counterintelligence, narcotics and various desks focused on Russian, Chinese and Iranian national security threats. F.B.I. agents in those roles are generally expected to zealously protect their work in such fields to avoid putting a target on their back.
Additionally, ShinyHunters said that it had stolen medical data about employees, including psychiatric records and documents related to blood and urine tests. It also said that it had additional background check files on employees.
Former bureau officials and security experts said the hacked data prompted no end of worries. The data could also make it far easier for violent criminals to seek revenge against F.B.I. agents who sent them to prison. When they submit paperwork against criminal suspects, F.B.I. agents sign their names to the records but are typically trained to not let delicate personal information easily emerge online.
“It doesn’t take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released,” said Andrew Brandt, a threat intelligence researcher at the cybersecurity company Huntress. “The bigger worry is ShinyHunters selling the data to other criminal or nation-state groups who could put it to more damaging use, rather than dumping it themselves.”
Security experts said that given the breadth of the records, they would be of enormous value if they were acquired by foreign spies, who could then use the material to build elaborate dossiers on F.B.I. agents — including those who may be undercover or later assigned to such a post — and track them for years, if not decades. Aided by artificial intelligence, spies or hackers could also combine the information with other exposed data that is already in their hands or that is easily acquired on the dark web.
“Breaches do not exist in a vacuum,” Justin Sherman, a senior associate at the Center for Strategic & International Studies, wrote in a recent essay arguing that different exposed data sets can be combined and analyzed by hostile spy services.
A History of Security Lapses
The hack is just the latest in a string of embarrassing security failures for the F.B.I.
Two years ago, government investigators learned that Chinese spies had compromised vast segments of the nation’s telecommunications infrastructure in a hacking campaign known as Salt Typhoon. Among the most startling revelations was that the breach included sensitive wiretap networks at Verizon and AT&T that process court-authorized surveillance orders for the F.B.I. to monitor domestic criminal suspects.
China has denied involvement, but U.S. intelligence officials considered the compromise a counterintelligence failure of the highest magnitude, with national security implications that could last for years. It prompted such alarm within the F.B.I. that field offices were told to check if informants had been potentially compromised and, if necessary, take steps to ensure their safety.
The bureau still does not understand the full scale or scope of Salt Typhoon and its exposure from it, according to current and former U.S. officials. But the F.B.I. received another blow this spring when suspected Chinese hackers were found again inside a network it maintains for domestic surveillance orders.
In the case of ShinyHunters, it was not Chinese spies but a notorious gang of cybercriminals who hit the F.B.I. Already, bureau leadership had warned staff that hackers linked to ShinyHunters who infiltrated AT&T in 2024 may have stolen months of call and text logs belonging to some of its agents, which also fanned concerns about whether its informants had been exposed, as Bloomberg reported last year.
Cybersecurity investigators and law enforcement officials say ShinyHunters is a loose collective of young hackers operating across the globe. They are seen as highly skilled — and audacious — English-speaking hackers who extort their victims for millions of dollars and brag about their exploits. In their recent correspondence with The Times, the hackers have favored British spellings of certain words.
A French citizen charged with participating in some ShinyHunters attacks was arrested in Morocco in 2022, extradited to the United States and sentenced to three years in prison. Other suspected members were arrested last year in France.
On Monday, a security journalist, Brian Krebs, reported that authorities in the Netherlands had arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions tied to ShinyHunters just days before the F.B.I. breach. ShinyHunters said in response on Monday that the Dutch suspect “has no association with us.”
The F.B.I.’s Dallas field office has been leading an investigation into ShinyHunters and working with international partners to hunt down other members, according to people familiar with the matter who were not authorized to speak publicly.
It is not clear exactly how ShinyHunters pulled off the F.B.I. hack. The group said it had used a zero-day, or previously undiscovered, coding flaw within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.
But some security researchers said the story may be more complicated. On Friday, Google revealed in a blog post that its threat intelligence teams have recently seen ShinyHunters renewing a campaign of “mass exploitation” against victims using a bug with Oracle PeopleSoft that was publicly disclosed with a patch in June. The post does not mention the F.B.I. breach, but a person familiar with the matter said investigators believe the known bug was involved in the ShinyHunters theft of personnel files.
The flaw was considered important enough that the Cybersecurity and Infrastructure Security Agency promptly added it to a catalog of high-risk known vulnerabilities that federal agencies are instructed to quickly address.
“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA said at the time.
A Deadline Approaches
In response to questions from The Times, ShinyHunters said in an email that the F.B.I. had not contacted the group and that it would hold firm to its Tuesday deadline.
The hackers said that the severity of the breach was “SIGNIFICANTLY” worse than publicly known but did not explain in what way. Cybersecurity researchers who have followed the collective have said it has a track record of sometimes embellishing its activities but so far, in this breach, its claims have been largely corroborated.
“We have no intention to reveal the true impact, we will leave that to the F.B.I.,” ShinyHunters said. “If they lie, we will not correct them.”
The group also said that it was aggrieved by the F.B.I.’s advisory and that the hack was “all about protecting our business.”
“This is happening so we are heard and acknowledged,” ShinyHunters said. “We may sound like children whose feelings are hurt, sure, but in our game, reputation is all that matters.”
The post Embarrassing Breach at F.B.I. Fuels Fears of Harm to Its Employees appeared first on New York Times.




