FBI Vows to Hunt ShinyHunters Over Theft of Employee Data
The FBI is investigating a breach involving FBIJobs.gov after ShinyHunters claimed to steal sensitive employee data, while current and former employees criticize the bureau’s communication and prepare for possible exposure.
“You know how to find us, and we know how to find you,” Leatherman said, adding that he suggested the group reach out first while the choice was still theirs. The FBI says it is aggressively investigating the breach and how hackers obtained sensitive FBI employment information, including whether they entered through third-party software or the FBI’s own internal systems. An FBI spokesperson told NPR in an emailed statement that the bureau is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted.
It remains unclear how much information was stolen, though media organizations and threat intelligence researchers have verified the authenticity of some stolen materials. Late last week, a defacement message was posted on the FBI’s jobs website in which ShinyHunters took credit for the attack, and the site was temporarily taken down.
Current and former FBI employees familiar with the matter, who spoke to NPR on condition of anonymity because they feared reprisal for discussing an ongoing investigation, said many employees first learned of the breach from media reports. They suggested the data tranche could contain as many as several terabytes of text files, including FBI job applications, promotion details, information on sensitive job postings, family details, medical data and more. Those employees, particularly retired ones, said frustration is growing with FBI leadership, including FBI Director Kash Patel, over the lack of communication about the breach, who is affected and how the FBI plans to protect current and former employees. Some retired employees who worked undercover might need protection services such as relocation assistance or name changes if their data is exposed publicly.
The FBI told NPR it sent multiple bureau-wide communications within 24 hours of public reporting of the breach and that the FBI treats the security of its own information and the safety of its workforce as top priorities. One former senior FBI official told NPR the breach could be on par with the 2015 compromise of tens of millions of sensitive government employee records from the Office of Personnel Management. The U.S. government attributed that breach to the Chinese government and described it as a widespread espionage operation designed to identify potential targets for intelligence gathering.
Unlike the OPM breach, there is more concern in this instance that the stolen materials will fall into the wrong hands or be weaponized by ShinyHunters or by criminal, terrorist or nation-state organizations seeking to pilfer the files. ShinyHunters has said it never intended to leak the files, despite giving a Sept. 30 deadline for the FBI to amend previously published press releases about the group that it argued were inaccurate. That does not necessarily prevent further theft or exploitation of the data. The bureau and its former employees are bracing for impact and assume the stolen materials may be irretrievably compromised, according to the former senior FBI official.
Experts argue that ShinyHunters members, whom many threat intelligence researchers have previously identified as a loose collective of young hackers around the world, should also brace themselves for the FBI’s response. Cynthia Kaiser, the former FBI deputy director of the cyber division who currently leads ransomware research at cybersecurity company Halcyon, described the hackers as reckless for targeting the FBI, particularly knowing the FBI has a clear policy of not paying a ransom or negotiating with criminal actors. “When any threat actor targets the FBI directly, they should expect that the FBI is going to marshall additional resources to bring them quickly to justice,” she wrote in a social media post.
While the FBI has promised to seek the information to make arrests against ShinyHunters hackers after this breach, it is unclear how imminent those actions might be. The FBI’s video also featured a recently announced arrest of one alleged member of ShinyHunters in Amsterdam by the Dutch National Police, an operation the FBI thanked its Dutch partners for leading. However, that arrest preceded the ShinyHunters theft of FBI personnel data, according to the former senior FBI official familiar with the matter.
Editor's Summary
The FBI is investigating a breach involving FBIJobs.gov after ShinyHunters claimed to have stolen sensitive employee data, and the bureau has vowed to hunt down those responsible. Current and former employees have criticized the FBI’s communication and warned that undercover retirees could require relocation or name changes, while officials compare the incident’s potential severity to the 2015 OPM breach. The FBI has promised arrests, but the timing is unclear, and ShinyHunters says it did not intend to leak the files.