Compliance · · 3 min read
FBI investigates alleged theft of employee data from jobs website
The FBI is examining claims that ShinyHunters exploited an unknown software flaw to access sensitive information linked to current and former personnel.
The FBI is investigating an alleged breach of its employment website after the hacking group ShinyHunters claimed it obtained a large volume of personal information belonging to current and former agency workers, applicants and their relatives.
The group said it accessed FBIJobs.gov by exploiting a previously unknown vulnerability in Oracle PeopleSoft, software used for human-resources and financial administration. The FBI has not confirmed that the intrusion took place or established how its systems may have been entered. Ars Technica reported that the agency has nonetheless opened an investigation and is working with companies that help operate the jobs site.
The website was still unavailable on Wednesday. Bloomberg reported that FBI personnel had been warned by email to take protective measures while the inquiry continued.
What the hackers claim to have taken
ShinyHunters told The New York Times that the stolen material amounted to between two and three terabytes. It said the haul had not yet been published online, but described it as including names, residential addresses, telephone numbers, spouses’ names and some medical details connected to agents, former employees and job applicants.
The information may also contain details about the professional areas in which some FBI employees work. Bloomberg reported that one sample appeared to refer to personnel involved in counter-intelligence matters concerning China, Russia and Iran, as well as investigations into street gangs.
That combination of personal and professional information could create risks beyond ordinary identity theft. It could expose employees’ families, reveal where people live and provide clues about sensitive assignments. Bloomberg reported that the material might be used to target or retaliate against agents, although the FBI has not confirmed the authenticity or scope of the alleged files.
The group’s public claims surfaced after 404 Media reported that ShinyHunters had disrupted the jobs site and placed a message on its homepage declaring that the site had been seized. The page was subsequently unavailable, according to the reporting cited by Ars Technica.
A dispute over an FBI warning
ShinyHunters said the operation was intended to pressure the FBI over an advisory issued in May. The group objected to the agency’s description of its activities, particularly suggestions that it sometimes inflates claims in order to obtain payments from victims.
The hackers also rejected the FBI’s assertion that they carry out swatting attacks against corporate employees or use sextortion threats. ShinyHunters said those allegations misrepresented its conduct and demanded that the advisory be withdrawn or revised.
The group gave FBI Director Kash Patel and Brett Leatherman, assistant director of the agency’s Cyber Division, one week to respond. It has described the action as a campaign to correct the FBI’s account of its activities rather than a demand for money. ShinyHunters has not explained what it would do if the deadline passed, but cybersecurity specialists told The New York Times that publishing the alleged data would be the most likely outcome.
The breach remains unverified
A central question is whether the group reached FBI systems directly or entered through a company that supports the employment portal. In a post on X, the FBI said investigators had not determined the point of entry and were examining both possibilities. The agency said it was taking steps to reduce potential risks while the investigation proceeded.
The technical details remain limited. ShinyHunters has said it used a zero-day vulnerability in PeopleSoft, meaning a flaw that had not previously been discovered or addressed. Oracle, which supplies the software, had not publicly commented on the alleged vulnerability in the reports cited by Ars Technica.
ShinyHunters also said it intended to keep using the flaw in what it called its normal business operations. That claim could have implications beyond the FBI if the vulnerability exists in versions of PeopleSoft used by other organisations, though the reporting does not establish whether any other systems were affected.
For now, the alleged theft, the size of the dataset and the identities of anyone whose information may be included all remain unconfirmed. The FBI’s investigation must establish whether data was removed, determine whether a third-party provider was involved and assess whether the material could endanger employees or their families. Until those questions are answered, the missing jobs site and the hackers’ warnings are evidence of an unfolding incident, not proof of the full breach they describe.