FBI investigates hackers' claims of massive data theft
Add Axios as your preferred source to
see more of our stories on Google.

Photo: Thomas Fuller/SOPA Images/LightRocket via Getty Images
A notorious cybercrime group is claiming they stole more than 2 terabytes of data that includes detailed personal information about thousands of FBI employees and job applicants.
Why it matters: Cybercriminals and state-sponsored attackers have penetrated U.S. IT systems for years, but stealing detailed and sensitive information about FBI employees is brazen, cyber experts told Axios.
- Cybercriminals are known to trade leaked information on the dark web, a prospect that would leave the data up for grabs from the highest bidder.
Driving the news: ShinyHunters, a group that's broken into numerous institutions, said in a post on its dark-web site Tuesday that it stole "very sensitive data on almost ALL FBI agents and individuals who filed an application with the FBI for a job."
An FBI spokesperson said in a statement the bureau is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
What to watch: Cynthia Kaiser, a former top official in the FBI's cyber division, told Axios that when a hacker targets the FBI, expect the bureau "to marshal additional resources to bring them more quickly to justice."
The big picture: While the breach is likely to bring more law enforcement attention to ShinyHunters in the short term, the long tail impact is greater on the FBI employees and their families whose information was stolen, Allan Liska, a threat intelligence analyst at Recorded Future, told Axios.
- "The data is out there and has likely been repeatedly downloaded and passed around to other threat actors," Liska said.
Axios has not been able to corroborate that the data stolen is legitimate or recent, but cybersecurity researchers confirmed that the attack appears legitimate. 404 Media obtained a sample of the stolen data, which appears to include information about 5,000 alleged agents.
Zoom in: ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.
- The group also claims it broke into the FBI's criminal justice, HR and other services.
- ShinyHunters also said it seized and defaced the FBI's jobs webpage via a zero-day in Oracle's PeopleSoft platform. The site was still offline as of Tuesday afternoon.

Catch up quick: ShinyHunters says its hack is not financially motivated. Instead, the group is pushing the FBI to retract statements it made about how ShinyHunters operates.
- In a May advisory, the FBI warned the hackers "commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting."
- ShinyHunters claims this isn't true and told Axios that it believes these claims have been tied to their group because "other low-skilled threat actors" have been using the group's name in their attacks.
Threat level: Andrew Brandt, principal threat intelligence incident commander at Huntress, told Axios that a major concern is over whether ShinyHunters chooses to sell the data to other criminal or nation-state hackers.
- "It doesn't take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released," Brandt said.
