ShinyHunters claims breach of FBI personnel data in retaliatory strike

The hacking collective ShinyHunters claims to have exfiltrated sensitive data belonging to FBI employees and job applicants, surfacing the breach by defacing a bureau recruitment site. The group asserts this operation is a direct retaliation against an FBI public advisory from May that labeled their tactics as exaggerated.

Today, 06:18
751 0
ShinyHunters claims breach of FBI personnel data in retaliatory strike

The group provided samples to researchers containing personal details of 5,000 individuals, including home addresses, phone numbers, and information regarding spouses. Verification efforts by independent outlets confirmed that some of these phone numbers align with Department of Justice personnel. ShinyHunters alleges they bypassed security via a zero-day vulnerability in Oracle PeopleSoft software, eventually accessing FBI-managed servers on AWS GovCloud. They claim to have siphoned between two and three terabytes of data from systems including human resources and the Criminal Justice Information Services.

The FBI confirmed it is investigating unauthorized activity affecting the FBIjobs.gov portal but has not verified the scope of the exposure. Cybersecurity firm CyPro noted that the hackers failed to provide specific technical evidence to substantiate the PeopleSoft exploit, leaving the full extent of the compromise unconfirmed. The group demands the FBI retract its May 15 advisory, which described ShinyHunters as using harassment and swatting to extort victims. This incident follows a pattern of aggressive activity from the collective, which recently hijacked the leak site of the Cl0p ransomware gang. For those potentially affected, the fallout extends beyond the bureau’s internal feud, as the exposure of home addresses and family details creates significant risks for identity theft and physical targeting.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!