Current and former FBI agents have expressed shock, fear, and anger following a hack that appears to have exposed the private and personal information of the agency's entire workforce. The hacking group ShinyHunters is threatening to publish the stolen databases and documents within four days unless its demands are met. Agents are worried that their personal information could become available online to criminals and hostile nation-state hackers, potentially leading to targeted attacks, phishing attempts, scams, or demands for bribes. Some agents are also concerned about physical attacks from individuals they have investigated, with discussions including 'violence-as-a-service' attacks from online gangs.
ShinyHunters claims it breached FBI systems on Monday and posted details on its darknet site. While the FBI has not commented on specific demands, it acknowledged the breach on Wednesday and stated it was "aggressively investigating" how it occurred. Samples of the alleged stolen data shared by ShinyHunters with reporters appear genuine and include names, addresses, phone numbers, badge numbers, job titles, and information about spouses, as well as sensitive medical information. This data could expose family members who are normally insulated from the career's inherent risks.
Experts suggest that some of the data may have already begun circulating in online groups, potentially causing harm even before the main publication. There are also concerns about national security implications, such as staff becoming targets for recruitment by hostile foreign intelligence services. Many agents are reportedly angry at the FBI for the security failures, especially as ShinyHunters is not considered a highly sophisticated group. The FBI has advised staff to sign up for a service to remove personal information from data broker websites, a response some feel is inadequate. The group's demand is unusual, as it is not asking for money but rather for the FBI to retract an advisory published in May that it claims "offended" them.