Key facts
- The FBI is investigating claims by hacker group ShinyHunters of a data breach.
- ShinyHunters claims to have stolen 2-3 terabytes of data from FBIJobs.gov.
- The stolen data reportedly includes personal information of current and former employees, as well as applicants.
- The group claims the hack was motivated by a desire to correct what it sees as "disinformation" in a previous FBI advisory.
- ShinyHunters claims to have exploited a zero-day bug in Oracle PeopleSoft software.
- The FBI has not confirmed the hack but is investigating the claims and working with third-party providers.
The FBI is investigating claims made by the hacker group ShinyHunters that it successfully breached the agency's jobs website, FBIJobs.gov, and stole personal data belonging to thousands of current and former employees, as well as applicants. The group reportedly posted a message on the site's homepage declaring it had been seized.
ShinyHunters told The New York Times that approximately two to three terabytes of data were exfiltrated. This data is said to include names, home addresses, phone numbers, names of spouses, and certain medical information. According to Bloomberg, the compromised data could potentially be used for retaliation against FBI agents, with some information appearing to detail their work focus on counter-intelligence related to China, Russia, and Iran, as well as efforts against street gangs.
The group stated its motive was not financial extortion or ransom, but rather to compel the FBI to remove or edit a May advisory that characterized ShinyHunters' claims as "disinformation" intended to "disrupt" their operations. ShinyHunters expressed offense at the FBI's advisory, which also alleged the group engages in swatting attacks and sextortion threats, claims the group vehemently denies.
In a message reviewed by Ars, ShinyHunters asserted that their threats and claims are "very real" and "not exaggerated and never a bluff." The group has given FBI Director Kash Patel and Assistant Director of the FBI Cyber Division Brett Leatherman one week to comply with their demands.
Details on the exact method of access remain scarce, with ShinyHunters only indicating to The New York Times that they "weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software." Oracle has not yet commented on the alleged bug. ShinyHunters indicated plans to continue utilizing the zero-day for its operations.
The FBI has not officially confirmed the hack but has initiated an investigation. In an X post on Wednesday, the FBI stated that the point of breach is still undetermined, whether it originated from a third-party provider or the FBI's own systems. The agency is actively investigating and collaborating with third-party providers supporting the jobs site to mitigate risks. As of Wednesday, FBIJobs.gov remained inaccessible, and sources told Bloomberg that FBI personnel received an email warning them to take protective measures.
