READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FBI Still Cannot Say How ShinyHunters Got Into Its Jobs Portal, Employees Complain of Silence

FBI Still Cannot Say How ShinyHunters Got Into Its Jobs Portal, Employees Complain of Silence
Sixteen days after ShinyHunters defaced FBIJobs.gov and claimed data on nearly every FBI employee and applicant, the bureau has not said whether the breach started inside its own systems or at a vendor. Dutch police arrested an alleged ShinyHunters leader on Sept. 15, a week before the defacement, so the arrest did not prevent the hack. Current and former employees are complaining that FBI leadership has told them too little about what was taken.

The FBI still has not said whether hackers got into its jobs portal through its own network or through a contractor.

The breach became public on Sept. 22, when apply.fbijobs.gov and the Special Agent Applicant Portal went dark. The site displayed a message styled as a law enforcement seizure notice: "This site has been seized by ShinyHunters." A group representative told 404 Media the defacement happened Monday night, Sept. 21.

The FBI's public statement was brief. "While the point of breach is still undetermined, whether a third-party or the FBI's enterprise, we are actively and aggressively investigating this matter and working closely with those third-party providers that support fbijobs.gov to mitigate any and all risk."

What the hackers claim

ShinyHunters says it holds data on all current and former FBI employees and every applicant. It told 404 Media it got in through a zero-day flaw in Oracle's PeopleSoft software, then moved into AWS GovCloud servers and pulled between two and three terabytes. Those are the group's own claims. Neither the FBI nor Oracle has confirmed the method.

Some of the material has checked out. A sample shared with Reuters contained agents' names, home addresses, Social Security numbers, assignments and, in some cases, family members' names. 404 Media reviewed a sample covering 5,000 purported agents and matched phone numbers to names using commercial data tools. Researchers and media organizations have verified the authenticity of some of the stolen material, NPR reported. CNN, citing sources who have seen the data, reported that it includes personnel working in sensitive units focused on China and Russia.

Jason Pack, a retired FBI supervisory special agent, told Fox News Digital there is "no indication they have the keys to the kingdom," meaning classified investigative systems. He warned that pairing names with assignments hands scammers and foreign intelligence services a map of who to target and approach.

A grudge over an FBI advisory

This was not the group's usual play. ShinyHunters normally breaks in and demands payment. This time a representative told 404 Media, "This is not financially motivated."

The group said it targeted the bureau over a May FBI public service announcement describing its methods. That notice told victims not to pay and warned that the group exaggerates its access, harasses victims and their relatives, and has made false emergency reports to provoke armed police responses. ShinyHunters called those claims false and gave the bureau one week to correct or remove the notice.

Many at the FBI and in the cybersecurity industry read that as a threat to leak the data, CNN reported. The group now says it never planned to publish any of it, though it has leaked stolen data from other victims in the past.

The arrest that came too late

On Tuesday, Sept. 29, the FBI announced that Dutch authorities had arrested "one of the alleged leaders of ShinyHunters." Dutch authorities said the suspect is 24 and was arrested Sept. 15, and that they found additional information on his laptop. He will remain in pretrial detention for at least another 90 days.

Brett Leatherman, assistant director of the FBI's cyber division, said the alleged leader and co-conspirators breached more than 140 organizations since last year. In a video, he told the group: "You know how to find us, and we know how to find you."

The dates matter. The arrest came six days before the FBI site was defaced. Whatever the Dutch operation disrupted, it did not stop this intrusion. No source has said whether the detained suspect was involved in the FBI breach.

Employees say they were left guessing

The sharpest complaints come from inside the bureau's own ranks. Current and former employees told NPR, on condition of anonymity, that many learned of the breach from media reports. They also voiced frustration with FBI Director Kash Patel and leadership over the lack of clarity on who is affected and how they will be protected. NPR reported that the data could include job applications, promotion details, sensitive job postings, family details and medical records.

"Management is lost," a former agent in touch with former colleagues told CNN. "They're not providing any clear advice to agents." Employees also said the security resources on offer were underwhelming. Retired undercover personnel could need relocation help or even name changes if their data goes public, according to NPR's sources.

The FBI disputes the characterization. A spokesperson said potentially affected employees "have received communication and notification multiple times within the last week, as recently as Saturday." The bureau told NPR it sent bureau-wide communications within 24 hours of public reporting and that it "treats the security of its own information and the safety of its workforce as top priorities."

One former senior FBI official told NPR the breach could be comparable to the 2015 theft of tens of millions of sensitive government employee records from the Office of Personnel Management. That is one anonymous official's comparison, not a measured finding. The FBI has not given a count of affected people.

Three things remain open. The FBI has yet to say whether the entry point was its own enterprise network or a third-party provider that supports FBIJobs.gov. It has not said how many people are affected. And whether ShinyHunters follows through on, or abandons, any threat to publish the data is unknown. The Dutch suspect's detention runs at least 90 more days from late September.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
The Hacker NewsFBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
center-left
NPRFBI hunting the hackers who stole its employees' sensitive data
left
CNNFBI grapples with fallout from massive data breach | CNN Politics
right
Fox NewsFBI says source of its jobs portal breach still unknown as hackers allege employee data compromised
right
Epoch TimesFBI Investigates Alleged Breach of Its Own Applicant Portal
right
BreitbartHacking Group 'ShinyHunters' Claims Massive FBI Breach, Theft of Agents' Personal Data
unknown
cyberboxsecurity.com.brThreat Intelligence