A group of international hackers known as Shiny Hunters has breached the FBI’s internal jobs portal, exposing tens of thousands of current and former employees’ deeply personal information—including spouses’ and children’s names, addresses, and secret job titles tied to foreign intelligence operations. Unlike traditional ransomware attacks, these hackers targeted the FBI as a form of revenge, claiming the agency misrepresented them as criminals in a public advisory. They exploited a previously unknown zero-day vulnerability in Oracle PeopleSoft to gain access and threatened to leak the data unless the FBI retracted its statement. Though the hackers abruptly reversed their threat just before a deadline, the data remains in their possession and has been shared with media and security researchers. This breach highlights systemic failures in government cybersecurity, echoing the 2015 OPM data breach and revealing inadequate encryption and outdated data retention practices. Former FBI officials express alarm, noting that agents—often working behind the scenes—now face real threats to their privacy and family safety. Despite an arrest of a key suspect in the Netherlands, the incident reveals that the FBI’s systems remain dangerously vulnerable, and the stolen data could be sold to foreign intelligence agencies. The attack marks a profound breach of trust between government employees and their institutions, raising urgent questions about the protection of personal data in high-security agencies.
From New York Times, I'm Michael Barrow. This is the Daily. A little over a decade ago, after hackers broke into the U.S. government and stole the personnel records of millions of federal workers, U.S. officials found that it would never happen again. It just did. This time, to the FBI. Today, my colleague, Cybersecurity reporter Dustin Volts tells the story of this devastating attack, the group behind it, and what now happens to the hypersensitive data that those hackers have stolen. It's Wednesday, September 30th. Dustin, welcome back to the Daily. Thank you. Good to be here. Good to have you. You cover the world of hacking, cyber attacks, and this hack is a doozy. So can you just describe the scale of what just happened at the FBI? It is a doozy, and I think more important than the scale, which could be tens of thousands of current and former FBI employees affected here, I think this scope of it is what's really important, because hackers were able to break into a government jobs portal the FBI uses, and not just steal names and phone numbers and emails, but far more sensitive details about these officials, including their spouses' names, in some cases, their children's names, their addresses, their secretive job titles, and even details that could be used to help a hacker follow them during their travels. Let me just zero in on one of these staggering things you just said, job titles at the FBI. What kind of job titles were revealed in this hack? So the FBI is a pretty secretive organization. A lot of the work that he was public, but a lot of it is behind the scenes. And so the job titles might not be classified, but they are very, very sensitive, and they might reveal things such as an agent working in counterintelligence against foreign spies or working on a China desk or a Russia desk. And these are FBI officials that you sort of never really hear about. You never meet, and they spend oftentimes decades of their lives working behind the scenes to try to pursue various alleged criminals. So this hack access information so detailed that the hackers who now have it can see which people within the FBI are assigned to which of our foreign adversaries. That's very intrusive. It is. And it's not just their job titles. It's also in many cases, they're supervisors. And in many ways, you almost can build a map of the FBI's workforce and see what people are doing, learn more about their investigations, and potentially respond in other ways, depending on what your pursuit or interests are. Right. And your pursuit could be to end such an FBI investigation. Your pursuit could be to seek revenge on an FBI agent to extort them. Who knows? This information would seem to arm you to do any number of those things. Absolutely. One of the top concerns that I've been hearing for the past week from a number of former FBI officials that I've spoken to, including senior officials who worked on cybersecurity issues, is that these are going to be FBI agents who maybe put violent criminals behind bars, maybe prosecuted the mafia, and are now, if the data surfaces publicly expose to forms of retaliation, I think it's important for people to understand that these types of FBI agents zealously guard their privacy. They do everything they can to make sure their addresses are not listed. These people are not on social media. And now you have this database that is out there that reveals all sorts of intimate details. So given the scale of what you're laying out here, how does this stack up against previous hacks into the United States government? So about 12 years ago, US officials this morning are blaming Chinese hackers for another serious data breach that Chinese government hacked the office of personal management, also known as OPM, and stole more than 20 million records of US government employees and contractors, as well as something like 5 million fingerprints. As one official told us, Charlie, this is bad. There is no way to put lipstick on this pig. And that was kind of considered a historic hack of epic magnitude that the Chinese intelligence services would be dining out for for years, if not decades. Why wasn't this information encrypted? The encryption is one of the many tools that systems can use. I looked at my colleagues at DHS for their response. No, I want to know from you why the information wasn't encrypted. It was a huge deal, and it prompted all sorts of congressional hearings. The status quo is unacceptable when leadership has to resign. Resipation from the director, this was during the Obama administration. And a lot of vows to better protect data, put it behind lock and key to make sure this never happened again. Obviously, they failed. They failed. And a lot of officials are telling me that this current hack could be as bad or in some ways worse than what happened with the OPM breach because of the granularity of the data at issue. And because of who took it, we'll talk about that who took it. What do we know about the hackers who did this? Why? They did it. And precisely how they did it. So the hackers in this case are not a foreign intelligence agency. Instead, they are a loose collective of young criminal hackers believed to be operating in countries around the world. And these hackers go by the name Shiny Hunters. Hackers often have very interesting names. Analysts say that this one seems to be a reference to the popular video game Pokemon in which gamers go after it because it's extremely rare and exotic Shiny Pokemon. Got it. So the Shiny Hunters are out there not to just get everyday paydays, but to score big hits to bring home big game. And they are breaking into hundreds of organizations to extort them in some cases for payments of millions of dollars. So they're basically in the business of ransomware. Yes, but it's not a traditional ransomware group. Instead of breaking into an organization and locking up their files and demanding payment, what they do instead is they break into an organization, steal all of that data and then threaten to do things with it like publish it online unless they're given a payment via Bitcoin in oftentimes as little as 72 hours. And they go after all sorts of companies, no matter how big, AT&T, ticket master, educational software used by students around the country and the world. I mean, these are just a few names that stick out. So this was seem to be a real departure from this group's normal MO of going after companies, threatening to release things, getting paid. The FBI is not ticket master and it's not an education software company. So why target the premier law enforcement agency of the United States? That's a great question. It is certainly audacious to go after the FBI and it really surprised a lot of people. It surprised me. It surprised a lot of security researchers and it's certainly surprised, I think, the FBI and a lot of former officials who work there. The hackers said when they disclosed this hack that essentially they were doing this as a form of revenge. For what? They said they were seeking retribution from the FBI for a public service advisory that the Bureau issued back in May of this year where they warned that the shiny hunters hackers are very, very serious in doing a lot of damage and in that they detailed their tactics. The FBI said that they engage in harassment and intimidation of victims to try to secure payment such as such as revealing private photos that they've stolen from victims, launching swatting attacks where local law enforcement is called into the address of a victim to scare them maybe with guns drawn all sorts of harassment type activities that the shiny hunters group says, hey, look, we extort victims, but we don't do those kinds of things and the FBI needs to correct the record. So basically they're mad that they're not being seen by the FBI for the honorable thieves. They see themselves to be. They feel like the FBI has incorrectly maligned them as something even worse than they are. Yes. They view themselves as honorable thieves. At least some of them do. They talk about their work as if it's almost a business that they are running and they are very good at what they do. And in this case, what they did or what they've claimed to have done is to find a zero-day computer flaw. This is a type of flaw that is unknown to the world that has not been previously disclosed to attack a Oracle PeopleSoft product that is used for helping with HR and financial records and data management for companies.
And what they have said is that they use this zero day to compromise the FBI to get this historic and current data from the jobs portal and walk away with it. And so the world learns about this hack last Tuesday when the group posts on its dark web forum that they have hacked the FBI. And in their statement, which calls out Director Caspital, as well as a cyber leader of the FBI, they say we need you to fix this public service alert or else, essentially. And in that statement, they also include conveniently a email to contact them. So being a reporter, as I, and what to do, I reached out to them. I sent them a note and said, hi, I hear that you have hacked the FBI. What a funny position to be in. It was, I honestly did not expect them to respond at all, but they were eager to do so and got back to me, I think, within about 10 minutes. Wow. And that's when they sent me a sample of data that they said was from the hack of the individuals who had their data compromised. They sent you essentially a sample of the hack material to prove that they've done what they say they have done. Yes, it was sort of like a, you know, we've stolen a lot of stuff and here's a receipt and they shared that information and said, you know, we have a deadline for the FBI to retract or remove this public statement. Tuesday, September 29th. And the officials and security experts that I spoke with were very much under the impression that they were going to leak some or all of the data that they had obtained online. They would publish all this very sensitive FBI personnel data if the FBI didn't meet their demand. Yes. So the clock is ticking. I am emailing with the hackers. I ask them point blank, what are you going to do if the deadline passes and the FBI does not comply? They say no comment. But meanwhile, the fear and anxiety is growing in the security community within the FBI that come the deadline. They could do something very dramatic and just publish FBI names and titles and family member names all of the data online for the whole world to see. And then on Monday, a day before the deadline comes to pass, the hackers reach out with a new message that twists the story on its head. We'll be right back. So Dustin, what did these hackers say right before this deadline that ultimately ends up really changing the whole direction of the story? So the hackers reach out in a lengthy email and tell me we have a clarification. We are not going to publish this FBI data online. We are not going to do it. And anybody who thought otherwise was mistaken. So essentially nothing to see here. Let's all move on. I mean, how do you understand such a complete backing down from their normal tactics? And a sudden claim that the thing everyone feared seemingly quite justifiably was, oh, kind of total misunderstanding. Look, far be it for me to try to get inside the minds of a diffuse network of international hackers. But here's what strikes me. The FBI says they are aggressively investigating this, working with third parties to go after the hackers, essentially. They are treating this as a five alarm fire internally. Meanwhile, the news of the hack is getting more and more attention. The hackers are doling out exclusives to various media outlets about exactly what they've taken. That drumbeat continues. And you see the reaction building too from former FBI officials, security experts saying this is historically bad when we think about the theft of data from the government. And so all of this is building into a crescendo as this deadline approaches. And that's when the hackers decide to issue this updated statement. Now, like I said, it's hard to know exactly what their motivations are. This is a loose collective of hackers. It's believed to be a bunch of different people working together from across the globe. And so it is very possible that you have different factions that have different views about how hard they want to push this, right? Some might be saying, hey, let's milk this for all its worth. Let's keep going. Others might think, maybe we have gotten what we wanted. We got the attention and let's sit back. Right. I mean, it seems quite reasonable to speculate that perhaps one of the factions within this collective of diffuse hackers may have made the claim to the rest of them that what they did here was ultimately maybe just a little too ambitious, that this is not AT&T. This is not ticket master. And that kicking this hornet's nest, the FBI, that that might be a huge mistake and that it would backfire and that it might even destroy this group. It's hard to know, but it's very possible. And I mean, think of the Mafia or other criminal organizations over the years, like this is not an unusual situation where you do have competing factions that might have disagreements about what they should do, how they should carry out their business. However, if they thought they were going to get the FBI off their back by vowing to not publish the data, they were wrong. Wrong how? On Tuesday, I'm Brett Leatherman, Assistant Director of the FBI's Cyber Division. Brett Leatherman, who has a great name for an FBI official, came out in a public video. Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of shiny hunters. Any doubts in this video, the recent arrests in the Netherlands of a 24-year-old hacker believed to be a key figure in the shiny hunters group? Now, to the remaining members of shiny hunters. And he says, essentially, to the rest of the gang, other groups believed anonymity or their friends would protect them and they were wrong. You know how to find us and we know how to find you. We are coming after you. I suggest you reach out first while the choice is still yours. Well, while the FBI issues these threats and no doubt is vigorously attempting to find all these hackers and arrest them, the reality is that all of this data is still floating around within the hacker's computer systems and I suppose even in the email of some reporters. That's right. So just because the hackers said they're not going to publish it, first of all, they could change their mind and decide to do that later. But also, there's nothing to stop them from selling the hacked data to the highest bidder or multiple bidders, including Russian and Chinese intelligence agencies that might have deep interest in learning everything they can about the FBI's workforce. So the idea that this is the end of the story is definitely not the case because this is data that is now out there. They've shared it with several different news outlets. There are security researchers who have come forward and publicized that they have also obtained the sample dataset as well. It's unclear how. But once you start sharing data with other people, it tends to take on a life of its own and it really can't be put back in the box. I have to ask Dustin, because I'm genuinely curious, and listen to maybe two, you said you got a sample of this hacked material. What do you, what do we? The times do with this, if I can ask. You know, this was a difficult issue for us to deal with internally. Should we even look at it? And if we look at it, what should we do with it? Should we analyze it? Should we report on it? How much should we report on it? These were a lot of questions we had internally with our lawyers and our standards team about sort of how do we want to handle this material that is out there. We are not sharing it with anyone, and we are securing it to the best of our ability. So what seems clear is that the FBI, when it comes to this data, is not at all out of the woods. And that makes me want to go back to Dustin, what you had described as the government's response to that infamous OPM hack all those years ago, when it said we're never going to let this happen again, and it does happen again. Because ultimately, this feels like a very meaningful, not just security breakdown, but a betrayal of people at the FBI who signed up for really sensitive law enforcement work with an understanding that their personal information would be protected implicitly. That's a reasonable bargain to reach with your employer if your employer is the FBI. And instead, the FBI left its personnel system so vulnerable that this hack happened, and these workers are now in real unnecessary peril. That's right. I think there's a lot of current and former officials that we've been hearing from at the FBI who are very frustrated about the situation and made clear to us that they didn't even know that a data set like this existed, and that question's about why it existed, and why would there be a plan?
place where there's a repository of so much intimate information that seemingly is kept for years without being deleted, without being purged, that a hacker could access and take. And a lot of these officials said, you know, working for the FBI can be a dangerous job. I sign up for this, but my family doesn't. And the fact that this data set includes emergency contacts, spouses, siblings, in some cases children, that is, I think, what is especially alarming to a lot of the people who work at the FBI, that it's not just them that have to worry about it, but their entire families in some cases. And to me, this demonstrates that even though the government has come a long way since that last big hack, that hack of OPM, it still has a very long way to go to protect its systems and more importantly to protect its people. Well, Dustin, thank you very much, I appreciate it. Thank you for having me. You can read more from Dustin Volts and all of our reporters on the New York Times app. If you don't already have the app, we want to let you know that if you download it right now, you'll get access to all of our journalism free for one month. So give it a try. We'll be right back. Here's what else you need to know today. The Times reports that in the months before OpenAI's artificial intelligence went rogue and attacked the startup company Hugging Face, two OpenAI employees raised and alarmed with their superiors, but were ignored. In emails, the employees worried that OpenAI's newest artificial intelligence models were not being appropriately monitored during testing. In response, their superiors said that that testing needed to move ahead to meet deadlines, and workers said that no new safety protocols were created. And in a temporary victory for the Trump administration, the Supreme Court allowed the government to keep deporting people to countries they aren't from and may have no connection to. These so-called third-country deportations, including to authoritarian countries with human rights abuses, were the focus of Monday's episode of the show. And while the justices cleared the way for those deportations to continue for now, they fast-tracked a final ruling in the case for next year. Today's episode was produced by Alex Stern, Olivia Nat, and Eric Krupke, with help from Jack Desidoro. It was edited by Annie Minoff, contains music by Pat McCusker, Rohanemisto, and Diane Waugh, and was engineered by Alyssa Moxley. Our theme music is by Wonderly. That's it for the Daily. I'm Michael Bavaria. See you tomorrow.
Podcast Summary
Key Points:
Hackers known as Shiny Hunters breached the FBI’s jobs portal, stealing highly sensitive personal and employment data including names, addresses, spouses’ and children’s details, and covert job titles related to foreign intelligence work.
Unlike traditional ransomware groups, Shiny Hunters target organizations to extort payments by threatening to leak stolen data, and this attack on the FBI was unusually audacious given the agency’s high security status.
The hackers claimed their actions were a form of revenge against the FBI for a public advisory that labeled them as "harassment-focused" rather than honorable thieves, and they specifically cited a zero-day vulnerability in Oracle PeopleSoft as their method of entry.
A key development was the hackers’ sudden reversal of their threat—claiming they would not publish the data—just before the deadline, likely due to internal factional disagreements or fear of backfiring and exposure.
Despite the withdrawal of publication threats, the data remains in hacker hands and has been shared with media and security researchers, posing ongoing risks of resale to foreign intelligence agencies.
The breach exposes systemic failures in government cybersecurity, echoing the 2015 OPM hack and highlighting inadequate data encryption and outdated personnel data retention practices.
Former FBI officials express deep concern over the personal and familial risks faced by agents, especially given that sensitive data like emergency contacts and family details were exposed.
The FBI is actively investigating the hackers, with one leader arrested in the Netherlands, but the incident underscores a lasting vulnerability in how government personnel data is stored and protected.
Summary:
A group of international hackers known as Shiny Hunters has breached the FBI’s internal jobs portal, exposing tens of thousands of current and former employees’ deeply personal information—including spouses’ and children’s names, addresses, and secret job titles tied to foreign intelligence operations. Unlike traditional ransomware attacks, these hackers targeted the FBI as a form of revenge, claiming the agency misrepresented them as criminals in a public advisory. They exploited a previously unknown zero-day vulnerability in Oracle PeopleSoft to gain access and threatened to leak the data unless the FBI retracted its statement.
Though the hackers abruptly reversed their threat just before a deadline, the data remains in their possession and has been shared with media and security researchers. This breach highlights systemic failures in government cybersecurity, echoing the 2015 OPM data breach and revealing inadequate encryption and outdated data retention practices. Former FBI officials express alarm, noting that agents—often working behind the scenes—now face real threats to their privacy and family safety.
Despite an arrest of a key suspect in the Netherlands, the incident reveals that the FBI’s systems remain dangerously vulnerable, and the stolen data could be sold to foreign intelligence agencies. The attack marks a profound breach of trust between government employees and their institutions, raising urgent questions about the protection of personal data in high-security agencies.
FAQs
The hack affected tens of thousands of current and former FBI employees, exposing highly sensitive personal information including names, addresses, family details, and secret job titles.
The stolen data included sensitive job titles such as those working on counterintelligence, China desk, or Russia desk, revealing which FBI agents are assigned to specific foreign adversary investigations.
The hackers, known as Shiny Hunters, are a global collective of young criminal hackers who operate under the name 'Shiny Hunters,' referencing a Pokémon game, and claim to have exploited a zero-day vulnerability in Oracle PeopleSoft.
They claimed to be seeking revenge against the FBI for a public advisory that labeled their hacking activities as harassment and intimidation, which they see as a mischaracterization of their actions.
They threatened to publish the stolen personal data of FBI employees online unless the FBI retracted its public statement, setting a deadline of September 29th for a response.
No, they retracted their threat and stated they would not publish the data, but the information remains accessible and could be sold or shared with foreign intelligence agencies.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.