HACKERS CLAIM MASSIVE FBI BREACH INVOLVING EMPLOYEES AND JOB APPLICANTS

Cybercrime group ShinyHunters claims it breached systems connected to the FBI and obtained sensitive information belonging to thousands of employees and job applicants. Some information supplied by the hackers has matched existing records, but the full breach and the source of the data have not been independently verified.
WASHINGTON, A notorious cybercrime group known as ShinyHunters has claimed responsibility for a potentially significant breach involving the Federal Bureau of Investigation, alleging that it obtained sensitive personal information belonging to FBI personnel and people who applied for jobs with the agency.
The claim emerged Tuesday after ShinyHunters said it had compromised FBI related systems and stolen information involving thousands of current and former employees.
The hackers have made broader claims about possessing information on nearly all FBI agents and job applicants, although the scale of the alleged breach has not been independently confirmed.
Reuters reported that the FBI did not initially respond to repeated requests for comment about the hackers' claims.
Other reporting later quoted an FBI spokesperson saying the bureau was aware of claims involving unauthorized activity affecting FBIJobs.gov and was investigating the matter.
Some of the information allegedly obtained by ShinyHunters appears to be genuine.
Reuters checked portions of a sample supplied by the hackers against other records and found matches involving some names and address information. However, Reuters said it could not establish whether the information had actually been stolen from FBI systems.
404 Media separately reported receiving a sample appearing to contain information involving about 5,000 FBI employees. The publication said portions of the data matched information available through other records.
The allegedly compromised information reportedly includes names, home addresses, telephone numbers, dates of birth and, in some cases, information involving employees' spouses.
ShinyHunters has also made claims about obtaining other categories of highly sensitive information, but those assertions remain unverified.
The incident attracted additional attention after the FBI's job application portal was reportedly defaced with a message claiming that ShinyHunters had seized the site.
The affected portal was subsequently replaced by an FBI maintenance page.
The FBI Jobs website and Special Agent Applicant Portal were also reported as unavailable Tuesday. The main FBI Jobs website was accessible when checked later, although the status of individual application systems may differ.
ShinyHunters claims it exploited a previously unknown vulnerability involving Oracle PeopleSoft before gaining access to additional infrastructure.
The group has further claimed that it downloaded between two and three terabytes of information after gaining access to FBI managed systems, including infrastructure hosted in AWS GovCloud.
Those technical claims have not been independently verified.
If confirmed, exposure of personal information belonging to federal law enforcement personnel could create significant security concerns. Such information could potentially be exploited for identity theft, intimidation, social engineering or attempts to target government personnel and their families.
ShinyHunters has previously been associated with major data theft and extortion operations targeting corporations and other organizations.
For now, the central allegation remains under investigation.
While portions of the data supplied by the hackers appear to correspond with real individuals, there is not yet independent confirmation that ShinyHunters penetrated FBI internal systems to obtain the information or that the group possesses data on the scale it claims.
Further information from the FBI and cybersecurity investigators will be needed to establish the full scope and origin of the alleged breach.


