FBI investigates claim by hackers they stole data on all agency staff

by | Sep 24, 2026 | Technology

FBI investigates claim by hackers they stole data on all agency staff

The FBI disclosed it is actively investigating an alleged breach after a hacking group called Shiny Hunters claimed to have obtained confidential information on thousands of bureau staff members. The group asserted it possesses data on roughly 38,000 people within the agency, encompassing current employees and individuals who have applied for positions. According to the hackers’ claims, the stolen information includes names, job titles, badge numbers, home addresses, phone numbers, and family member details.

Shiny Hunters stated the breach occurred on a Monday night and began distributing samples and screenshots of the compromised data to media outlets the following day. The BBC reviewed a portion of the materials, which appeared consistent with authentic FBI personnel records. Reuters reported that some of the stolen data contained information regarding officials’ job assignments in sensitive areas, including operations against Chinese espionage activities, Russian intelligence operations, and drug trafficking investigations.

The group claimed to have identified a vulnerability in Oracle cloud storage systems used by the FBI, allowing access to multiple platforms including the agency’s job portal, background check system, medical records database, and investigation information storage. Shiny Hunters is an international hacking collective with origins believed to trace to France. The group has claimed responsibility for previous high-profile breaches, including attacks on a major video game company in April and an education technology platform in May.

Rather than seeking financial compensation, Shiny Hunters stated its motivation centers on the FBI’s May advisory describing the group as threat actors engaged in extortion schemes. The hackers requested the agency retract or amend the characterization, threatening to release complete databases if the correction was not made within one week. In its public response, the FBI stated it was investigating whether the breach involved its own systems or those of third-party service providers, while working with external vendors to address potential risks.

A cybersecurity analyst characterized the incident as a retaliatory action, noting it underscored organizational vulnerability to the group’s capabilities. The analyst suggested the group sought to manage public perception of its activities and prevent reputational damage.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI