According to a Reuters investigation, the hacking group ShinyHunters claimed to have breached the FBIJobs.gov portal and stolen data on a large number of current and former FBI employees. The hackers said the full haul could amount to two to three terabytes, but released only a 5,000‑row sample spreadsheet as proof.
What the stolen data contains
The leaked spreadsheet includes highly sensitive personally identifiable information:
- Names, addresses, phone numbers, dates of birth, Social Security numbers, and emergency contact details for what the hackers claim are thousands of FBI personnel.
- Details of assignments to specific field offices (e.g., Baltimore, Newark).
- In some cases, granular information about unit assignments involved in high‑stakes work, such as:
- China‑focused units: 14 staffers tied to the “China criminal enterprise unit,” “China tech transfer analysis unit,” and “China intelligence section.”
- Russia‑focused roles: 9 staffers, including the “Russia Operations Section” and “Russia Critical Infra and Tech Threat.”
- Iran/Hezbollah‑focused intelligence roles: 3 staffers.
- Surveillance and technical operations: 18 staffers listed in “data intercept,” “telecom intercept,” “clandestine technical operations,” and “covert access” roles.
- Human intelligence (HUMINT): 11 staffers, including the “Humint program management section.”
Why it matters
Former FBI counterintelligence operative Eric O’Neill called the trove “a foreign intelligence service goldmine,” noting that adversaries like China would be highly interested in identifying the agents working against them. Former Army investigator Trevor Hilligoss highlighted the particular danger posed by the inclusion of emergency contacts (often spouses or children), who may have less awareness of operational security.
The exposure of undercover or covert identities could put agents at physical risk, as has happened in past cases when covers were blown.
The FBI’s response
The FBI acknowledged awareness of “a cyber‑criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information.” The bureau said the cause of the breach was undetermined and that it was “actively and aggressively investigating the matter.”
Verification and authenticity
Reuters could not authenticate the entire dataset, but independently verified more than 22 individuals’ details by cross‑referencing credit records and prior dark‑web leaks via the intelligence platform District 4 Labs. The outlet also matched career titles or roles for eight people against court filings, news coverage, LinkedIn profiles, and social media posts. However, it could not confirm that all job assignments in the leak were current or accurate.
Who is ShinyHunters?
ShinyHunters has previously claimed high‑profile breaches, including Rockstar Games (maker of Grand Theft Auto) and the education platform Canvas, which disrupted U.S. schools. The group said it targeted the FBI in retaliation for an unflattering FBI statement issued in May, which characterized the group’s claims as exaggerated to extort victims. ShinyHunters insists its threats are real and said it was trying to prevent the sample data from circulating further.
Bottom line
While the full scope and authenticity of the stolen data remain unconfirmed, the sample reviewed by Reuters contains verifiable, highly sensitive information that, if genuine and up‑to‑date, could pose serious risks to FBI personnel and ongoing operations—especially if foreign intelligence services or hostile actors gain access. The FBI continues its investigation.
Source: Reuters
Buy me a Ko-fiSupport this blog ❤️
