WASHINGTON – The FBI said Wednesday that it was investigating a criminal hacking group's claims that it had stolen “very sensitive data” belonging to thousands of agents and applicants and that it had compromised the bureau's jobs website.
“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information," the FBI said in a statement. It said that while the “point of breach” was undetermined, "we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”
Recommended Videos
The jobs website, the main portal for prospective employees to learn about the FBI and initiate the application process, remained offline as of Wednesday afternoon.
A message that circulated online from a hacking group known as ShinyHunters claimed responsibility for the hack.
“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” said the ShinyHunters message, which was directed to FBI Director Kash Patel and Brett Leatherman, the assistant director in charge of the bureau's cyber division.
The claims could not immediately be verified, and an email to an address associated with ShinyHunters was not immediately returned.
The hackers are seeking retribution over an FBI advisory
Miriam Wugmeister, a lawyer specializing in data, privacy and cybercrime who tracks hacking outfits like ShinyHunters, said that based on the group's past practices, there was reason to believe the hackers' claims, “so I think it’s likely that they were able to compromise this website and they got some data.”
She said that though the data that appeared to be compromised was the type of personal information that is routinely accessed during a breach, the hack nonetheless had alarming national security implications given that it could expose agents and their families to extortion, swatting and other harassment and because the identities of spouses were also said to have been obtained.
“Even if the agents and the analysts and the employees are sophisticated, you worry about their families too,” she said.
In its message, ShinyHunters said it would give the bureau one week to correct or remove what it said were false allegations contained in an FBI public advisory from May that described the organization as a “cyber criminal group specializing in large-scale data breaches and extortion.”
That advisory characterized ShinyHunters as “threat actors” who often "use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims," commonly harass or threaten victims and “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”
ShinyHunters said in its message to the FBI that it was “offended” by those characterizations and demanded that the FBI remove those claims. It did not say what would happen if the FBI did not do so within a week.
“This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated,” the hacking group's message said.
ShinyHunters has a reputation for “causing trouble and being disruptive,” Wugmeister said, as evidenced by the group’s involvement in a hack last spring of Canvas, an online system that thousands of schools and universities use. The breach created chaos as students tried to study for finals and prompted the FBI’s advisory that ShinyHunters is now objecting to.
There have been other cyber incidents concerning the FBI
The hack was first reported by 404 Media, an online technology publication that said a representative of ShinyHunters shared what appeared to be a sample of personal data of 5,000 FBI employees, including an address, phone number and some information on spouses.
The publication said the ShinyHunters representative said the group carried out the hack through an apparent vulnerability in Oracle PeopleSoft software, commonly used by companies and government agencies for large-scale data processing and huma resources purposes. The FBI said in its statement that it had not determined whether the “point of breach” involved a “third-party or the FBI’s enterprise.”
The FBI, the nation's premier federal law enforcement agency, has been a common target for hackers.
In March, the FBI disclosed that it was investigating “suspicious activities” on an internal system that contains sensitive information related to surveillance operations and investigations. Also that month, a pro-Iranian hacking group claimed to have hacked an account of Patel's and posted online what appeared to be years-old photographs of him, along with a work resume and other personal documents dating back more than a decade.
The FBI described the compromised information as “historical in nature” and said it involved "no government information.”

