Cybercriminal group ShinyHunters has claimed responsibility for a major breach of the United States Federal Bureau of Investigation, alleging that it stole sensitive information belonging to thousands of FBI agents and job applicants.
The group made the claim on its dark web leak site, saying it had obtained “sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job,” according to TechCrunch.
The alleged breach was first reported by 404 Media after the publication received a sample of the stolen information, including names, home addresses and phone numbers of FBI agents and their spouses.
The publication said it verified some of the information against public records.
According to 404 Media, the hackers claimed they initially breached an Oracle PeopleSoft server, a system commonly used by human resources departments and recruiters to manage applicants’ personal information.
The hackers then allegedly used access to compromise an Amazon-hosted government cloud environment containing data belonging to FBI agents and applicants.
ShinyHunters reportedly told 404 Media that it had stolen terabytes of information, although the group did not disclose what it planned to do with the data.
The hackers said the attack was not financially motivated and instead demanded that the FBI remove a report they claim contains false allegations about the group.
The alleged theft could expose the FBI to significant security and counterintelligence risks if the information is authentic. Detailed personal information about agents and their families could potentially be used for coercion, extortion or targeting by foreign intelligence services.
The FBI has not been quoted as confirming the alleged breach in the information provided.
