0x1e5db1d81e5d…1e5db1db
FBI Tells Staff to Assume Hackers Hold Their Personal Data
The FBI has told employees to assume hackers stole their personal data after ShinyHunters claimed a breach of FBIjobs.gov via an Oracle PeopleSoft zero-day, with 2–3 TB at stake.

Outputs
An internal FBI memo, reported by Reuters, tells employees to assume their personal data was stolen in a claimed breach of FBIjobs.gov by ShinyHunters.
ShinyHunters claims 2–3 terabytes of data on agents, job applicants and some spouses, obtained through a zero-day flaw in Oracle's PeopleSoft; the FBI has not confirmed the scale or method.
FBI Cyber Division Chief Brett Leatherman responded on Sept. 29, citing a Sept. 15 Dutch arrest and telling the group 'we know how to find you.'
The FBI has instructed its own employees to assume hackers stole their personal information, according to an internal memo reported by Reuters. The guidance follows a claimed breach of the bureau's recruitment portal, FBIjobs.gov, by the cybercrime group ShinyHunters, which says it holds 2 to 3 terabytes of data covering agents, job applicants and, in some cases, spouses.
The FBI says it is investigating the incident and has not confirmed the scale of the breach or the claimed intrusion method. The bureau is nonetheless operating on the worst-case premise: that data on every staffer is already compromised.
The exposure, if the group's claims hold, extends well beyond current employees. Anyone who has applied for an FBI job could be in the stolen files. ShinyHunters says the dataset includes names, phone numbers, home addresses and spouse details.
The group claims the intrusion began on Monday, Sept. 22, when visitors to FBIjobs.gov saw a banner stating the site had been seized. ShinyHunters attributes the breach to a previously unknown flaw — a zero-day — in Oracle's PeopleSoft, HR software widely deployed across large organizations. Because the vendor is unaware of a zero-day, no patch exists at the time of exploitation. The FBI has not verified this account.
ShinyHunters says its motive was retaliation. A May 15 FBI advisory warned that the group uses harassment tactics against victims, including threats to family members and, in some cases, swatting — placing a fake emergency call that sends armed police to a target's address. The group denies those allegations and gave the bureau one week to retract the advisory.
The group is a known quantity in cybercrime circles. It surfaced in 2020 selling stolen databases on hacker forums and helped operate BreachForums, one of the largest underground marketplaces of its kind. Last year it claimed roughly 1.5 billion records from customers of Salesforce.
The FBI responded publicly. Cyber Division Chief Brett Leatherman posted a video on X on Sept. 29, referencing a Sept. 15 arrest in the Netherlands and telling the hackers: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours." ShinyHunters says the arrested man has no association with the group. It later described its ultimatum as a marketing campaign and said it does not plan to publish the stolen data.
The internal memo, as reported, also directs staff to expect virtual briefings and to treat suspicious texts and calls from unknown numbers with caution.
The operational stakes are concrete. If the dataset is released and FBI employees are doxxed, staff could face threats or physical harm, identity-theft cases may surge, and relatives of exposed personnel become secondary targets.
The crypto sector has already demonstrated how stolen personal data converts into physical crime. Coinbase disclosed last year that bribed support agents leaked customer data, and the company then faced a $20 million extortion demand. France had recorded 135 crypto-related "wrench attacks" since 2023 as of April, with 88 suspects charged. In one case, attackers who assaulted a couple outside their apartment in Nancy reportedly obtained their details from a January breach at Waltio, a French crypto tax platform that exposed roughly 50,000 users.
The one-week deadline ShinyHunters set for the FBI's retraction has now passed. The group says it will not publish the data, but the bureau's memo leaves no room for optimism: staff should assume their information is already in hostile hands, and the investigation into the claimed PeopleSoft zero-day remains open.
via reuters.com (Original)
More from Daniel Okafor
Show full bio
Correspondent covering industry trends and analytics at Mempool Brief.
435 articles