sözaltı news Politics
Politics
EN AZ

Cybercriminal group claims to steal thousands of FBI employee records

politico.com 23.09.2026 00:08 3 views
The FBI said it was probing a suspected hack, after the cybercriminal group ShinyHunters claimed to have breached its systems.

Cybercriminal group claims to steal thousands of FBI employee records The FBI said it was probing a suspected hack, after the cybercriminal group ShinyHunters claimed to have breached its systems. The suspected hack follows another major breach of a sensitive FBI system this year. | Yuri Gripas/AFP via The FBI said it is investigating a possible breach into its online jobs portal, after a prolific cybercrime group publicly claimed to have stolen personal information of FBI personnel. Confirmation of an ongoing investigation came hours after a cybercriminal group known as ShinyHunters posted a message online claiming it had stolen “very sensitive” data on “almost all” FBI agents, as well as those who had applied for jobs at the bureau.

The group provided a sample of stolen data affecting 5,000 supposed FBI agents to 404 Media, which first reported on the alleged hack. The sample data set included agent names, home addresses, phone numbers and information on agents’ spouses, the outlet said. Two people with knowledge of the breach said investigators believe the group’s claims are credible, and amount to a significant counterintelligence failure.

Identifying information on even a handful of agency personnel could be used to threaten or harass active FBI agents or their families, and would be of interest to foreign intelligence services and violent criminal gangs. The FBI’s job website also appeared to have been affected by the breach, with the site on Tuesday afternoon featuring a “system unavailable” banner. In April, hackers linked to China broke into an FBI wiretap system, in one of the most serious intrusions inside agency systems in years, POLITICO reported at the time.

In the post, ShinyHunters did not specify what systems or databases it claimed to have breached, how much data it stole, or what time period the data covered. The first individual with knowledge of the breach said they appeared to have used a vulnerability in Oracle PeopleSoft, an application commonly used in human resources departments. A representative for the group claimed to 404 Media that they hacked into PeopleSoft using a previously unknown software vulnerability — or zero-day — though the first person with knowledge of the breach said investigators had not yet determined if that was the case.

In June, ShinyHunters used a then-unknown zero-day bug in a campaign of attacks targeting organizations running PeopleSoft. But Oracle later fixed the bug, so it is possible the group reused the same exploit on a system the FBI failed to patch or ShinyHunters found a different way altogether into the system. Investigators are still trying to determine that, the first person said.

ShinyHunters is a prolific cybercriminal group, and has been increasingly active this year. The FBI in May put out a public service announcement outlining the hacking group and its tactics, which was released after ShinyHunters attacked the Canvas learning system, leaving thousands of schools and universities temporarily offline. The statement from ShinyHunters took issue with the PSA, and claimed that the breach was carried out to force the FBI to “correct or simply remove” the alert, strongly denying any claims that ShinyHunters carried out sextortion schemes against victims.

Extract — continue reading at the source.

Read full story