A high-profile hacking group claims it has breached multiple FBI-related services and stolen data “from all FBI employees and applicants.” A representative for the group, called ShinyHunters, told 404 Media that the data includes FBI agents’ names, addresses, phone numbers and information about their spouses. The data breach could be hugely significant and have all kinds of national security and counterintelligence implications. Criminals in the same ecosystem as ShinyHunters have previously used hacked data, such as phone records, to track, intimidate, and harass FBI agents investigating them. The highly sensitive data could also be a boon to foreign intelligence agencies that want to better understand how one of America’s most important intelligence and law enforcement agencies operates. And if the data fell into the hands of more criminals, FBI agents and their spouses could face serious threats to their security. “We hacked the FBI. We have data on all FBI employees and applicants,” the group’s representative told 404 Media.💡Do you work at the FBI? Do you know anything else about this trick? I would love to hear from you. Using a non-work device, you can securely message me on Signal at joseph.404 or email me at joseph@404media.co. The representative provided 404 Media with a sample that appears to contain the personal data of 5,000 FBI employees. That data included an alleged address, phone number, date of birth, and, in some cases, details about their spouse.404 The media ran some of the sample phone numbers into the open source intelligence tool OSINT Industries and found that they corresponded to people with the same name as listed in the sample file. 404 Media also searched some of the records through the compromised data tool Darkside, created by cybersecurity firm District 4. That revealed that some of the phone numbers are associated with U.S. Department of Justice personnel. ShinyHunters also defaced the FBI’s jobs website on Tuesday. That defacement says, “this site has been seized by ShinyHunters,” which is an obvious nod to the seizure notices the FBI and other law enforcement agencies typically place on sites after taking them down. The representative said ShinyHunters carried out the attack on Monday night. As of this writing, the FBI jobs website says, “Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.” The defacement adds: “All FBI data was compromised, including PII/PHI [personally identifiable information and protected health information] about current and former FBI employees and all applicant information. We have a lot more than we claim here.” The ad ended with another obvious dig at the administration, this time mocking President Trump’s Truth Social posting style: “Thank you for your attention to this matter.” After this article was published, an FBI spokesperson told 404 Media in an email: “The FBI is aware of claims of unauthorized activity affecting FBIjobs.gov and is currently investigating.” The representative said ShinyHunters said the group used a zero-day exploit on an Oracle product called PeopleSoft. From there, the group managed to access AWS GovCloud servers and the downloaded data, the representative said the exfiltrated data amounted to between two and three terabytes. Obviously, it is unlikely that the FBI will ever pay a ransom like this. “What we plan to do. not something I would call extortion, maybe coercion.” “This is not financially motivated,” they added. In a post on its leak website, ShinyHunters said the FBI made “false allegations” in a previously published report, the FBI said ShinyHunters exaggerates its claims of accessing sensitive data to make illicit payments, that the group sends threatening text messages and phone calls to victims and their families, and that it sometimes carries out hits. post, ShinyHunters said that it “allows you [the FBI] 1 week to correct” or remove the report. Update: This article has been updated to include more information from previously compromised data, a statement from the FBI, and information from a post on the ShinyHunter website. About the Author Joseph is an award-winning investigative journalist focused on making an impact. His work has led to hundreds of millions of dollars in fines, technology company closures, and much more.