A series of high-profile cyberattacks have exposed severe vulnerabilities in U.S. government systems, including the FBI, Department of Homeland Security, and critical water infrastructure in Minnesota and Michigan. The most recent FBI breach by the "shiny hunters" group compromised personal data of thousands of employees, including job details, addresses, and family information, and revealed the FBI’s own hacking unit. The attack exploited a zero-day vulnerability in Oracle PeopleSoft and leveraged third-party infrastructure to infiltrate systems. This follows a pattern of breaches dating back to February and March, including hacks of Cash Patel’s emails and DHS data. Cybersecurity experts believe the attacks, particularly on water systems, are likely tied to foreign actors such as Iran, though U.S. officials—including Donald Trump—have blamed incompetent state governments instead of external threats. The Trump administration’s dismantling of cybersecurity leadership and lack of transparency have likely enabled foreign intelligence agencies to penetrate and exploit sensitive data. With critical infrastructure increasingly at risk and internal systems exposed, the full scale of the cyber threat remains obscured, raising serious concerns about national security and public safety.
We are now learning that the massive hack into the FBI database is much worse than even initially reported, and I do want to remind you that not only has the FBI database been hacked this past week, they were also hacked back in February of this year. Cash Patel's personal emails were hacked in March of this year. The Department of Homeland Security had its database hacked in June of this year, and in August, there were 30 water facilities in Minnesota, and close to seven to 10 water facilities or so in Michigan that were hacked as well. There is a pervasive hacking issue and the vulnerabilities that currently exist in our government systems with the incompetence of the Trump regime. It's being covered up, but I think we're learning more and more about it, especially right now with the latest hack by shiny hunters. I mean, they plastered their imagery on the FBI jobs page. When you went to FBI jobs, it would say shiny hunters has basically taken over this website, and what we now know is some of the data that was taken. I mean, it just goes beyond the information of a lot of FBI personnel and their spouses and where they live and other confidential personnel information about these FBI employees. But according to this Reuters report from earlier this morning, the FBI data allegedly stolen by the hacking group shiny hunters carries granular detail about scores of Bureau officials' job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels, and more. And this is particularly interesting as well as it comes on the same time or comes on the heels right around the same time as Xi Jinping, of course, arriving in the United States, Donald Trump bowing to Xi Jinping at that bizarre tarmac joint Andrews base meeting that we covered here where Donald Trump made our Air Force personnel and Army personnel literally get on their knees with the red carpet for Xi Jinping. Here's what 404 is reporting. They've been doing extraordinary reporting on these hacks. This is the latest from them. FBI hack exposed FBI's own hacking unit as well. So the FBI has a remote operations unit called ROU and it's a highly secretive team of the FBI hackers and the ability to gain information into them. That's now been exposed. What they do, how the FBI hacks databases. That's being exposed by this most recent hack. So 404 goes on to say the catastrophic hack of at least thousands of FBI officials personal data, including their address phone numbers and even their spouses personal data includes members of the FBI's secretive hacking team potentially revealing who exactly is in that unit. 404 media has found the findings further highlight how sensitive the stolen data is and how valuable it may be to criminals or to foreign intelligence agencies. There is very little public information about the FBI's hacking unit including the operation it conducts the tools it used or which agents are part of it. Now I should also note as I'm reading this I reflect on the fact that we now know for sure China has analyzed and working to reverse engineer those F 35 parts that were supposed to be sent from Australia back to the United States but they found their way into Hong Kong and then they found their way further into the broader Beijing intelligence apparatus. The sloppiness of which the Trump regime does everything. The fact that they gutted so many people responsible for cybersecurity. If this is what we're seeing shiny hunters do just think about what foreign intelligence agencies have been able to penetrate and we know this Trump regime covers up everything. What does China know about our systems? What does Russian know about our systems? What does any intelligence agents North Korea? What does any intelligence agency know about our systems? I can be pretty damn confident that they've got all this data and they're just eaten it up right now. So the FBI's recent statement was we're aware of a cyber criminal enterprise group claiming a compromise of the FBI jobs.gov portal and alleged impact to FBI employee personally identifying information while the point of the breach is still undetermined whether a third party or the FBI is enterprise. We're actively and aggressively investigating this matter and working closely with those third party providers that support FBI jobs.gov to mitigate this risk. It's probably at least 5000 FBI officials whose information now is in the hands of shiny hunters and others as well. But you go back January, February, March. I think March the story was revealed that back on, I think it was February 17th. The FBI first detected suspicious activity then and then it was revealed on March that there appeared to be a sophisticated hack that took place then they later had to alert lawmakers about what happened. Every wake up sweaty, freezing or just uncomfortable. The temperature in your bedroom can make or break your sleep. That's why I switched to miracle-made sheets. They're inspired by NASA technology and use silver infused temperature regulating fabric to help you sleep perfectly all night long. Here's the thing. Thanks to their antibacterial silver technology, miracle-made sheets stay cleaner and fresher up to three times longer than regular sheets. That means fewer odors, fewer wash cycles and way less laundry. All that hidden bacteria in regular sheets, it can clog your pores and cause breakouts. Miracle-made antibacterial design helps you sleep cleaner and clearer night after night. And they feel just as good if not better than sheets you'd find at a five star hotel, but without that steep price tag, smooth, breathable and ridiculously comfortable. Miracle-made sheets are crafted with NASA-inspired silver infused fabric that helps regulate your body temperature. Hot sleeper, cold sleeper, it doesn't matter. These sheets help keep you in the comfort zone all night long. Upgrade your sleep or give the gift a better rest. Go to trymiracle.com/mitus to try miracle-made sheets today. You'll save over 40% and when you use promo code Midas, you'll get an extra 20% off plus a free three-piece towel set. They make an amazing gift and with a 30-day money-back guarantee, there's no risk. That's trymiracle.com/mitus code Midas at checkout. Thanks to Miracle-made for sponsoring this episode. And they said this is the FBI statement back then. The details the FBI shared with Congress and the White House's outreach to the NSA suggest the incident could be significant. The affected system is unclassified and contains law enforcement sensitive information, including returns from legal process such as pen register and trap and trace surveillance returns and personally identifiable information pertaining to subjects of FBI investigations. That's one of the pieces of information that was taken. Pen register and trap and trace devices are used by law enforcement to monitor call metadata to and from a target's home. The FBI said in its notice to Congress that one side of the group's advanced skills was how it broke through the FBI security controls by leveraging a commercial internet service provider vendor's infrastructure to slip into the FBI's network. I mean, look, shiny hunters knows what they're doing. They've got a team of hackers over there. But I mean, here's how they say they did it. They're saying, here's how we did the most recent one. We exploited a zero-day vulnerability in Oracle PeopleSoft, the HR and Recruiting Platform that FBI uses to manage job applications and employee records. They then pivoted to an Amazon hosted government cloud storing agent and applicant data. They defaced the FBI's job portal and then they took all this information. I mean, it was sophisticated, but they kind of told you how they did it most recently, and I mean, when you then say, hmm, I wonder is Cash Patel taking this hacking stuff seriously? March 27, 2026, or Ron Linkt hacker's breached FBI director Cash Patel's personal emails. Remember when that happened over there? Or how about June 30th, 2026? Hacker's breached Department of Homeland.
security information, sharing network, people familiar say a key department of homeland security information database was accessed by an unknown threat actor in recent weeks, potentially exposing sensitive data exchange between federal, state, local and industry partners according to two people familiar with this matter. What about when we go to was an early August when Donald Trump was like the hacks that are happening in Minnesota and Michigan are being caused because they're blue states or that they're run by Democrats. And that's what's going on here. Well, here's what we learn. US officials are investigating a wave of cyber attacks targeting water systems in at least seven states, not just Minnesota and Michigan, but those were two of the main states with evidence potentially pointing to Iran through though officials say the investigation is still preliminary. The attack disrupted some operations, but did not contaminate drinking water or pose known public health risks. Trump disputed Iran's involvement and said these would mean you're disputing Iran's involvement in terms like it's just the states that are incompetent. It's their fault. Cyber security experts describe the campaigns as an unprecedented targeting of US water infrastructure likely aimed at exploiting vulnerable systems rather than specific communities. But lots of people said one of the reasons that Iran probably targeted Minnesota and Michigan and states like that is knowing and testing whether Donald Trump would just blame the states or whether Donald Trump would actually blame hackers for doing it. Do you remember back on, I think it was late July, when Donald Trump had one of those camp dead, he was like, camp David. Yeah. He held the press conference and now we're so close. The war is about to end. It's amazing. Iran wants to do a deal. The Strait of Hormuz is operating the same crap. He was doing it then. And then he said, you know, people are saying that Iran may have been Iran hackers like Hondala, the Iranian and Hondala hackers. They're like one of the premier hacking groups out there. I mean, they've done some powerful, some of the biggest hacks, you know, that have been out there. But remember what Trump said at the time here. Listen to it for yourself. Let's play this clip. I think today I just want to mention that we heard in Minnesota, there was a cyber attack and they blame it on Iran. I don't think so. I think I blame it on Minnesota because it grossly incompetent. There was a cyber attack of 30 water plants and I would blame it on Minnesota and the government, the corrupt government of Minnesota. They like to say, "Oh, it's Iran. Iran should be so lucky. Iran's got bigger problems than worrying about Minnesota." Crazy, right? Trump's like, it's the state that did it. It's the state that did it. And so the broader question here is, as you see what's happening is, where are, where's this data? I mean, I'll show you how this was reported on state regime media. This is what they said on Fox. Hackers are targeting critical infrastructure here at home. Jennifer Griffin has much more for us. Hi, Jennifer, good morning. Hi, good morning, Dana. Minnesota has reported a tax on roughly 30 water systems while Michigan has confirmed nine incidents. Seven states in total. The FBI has warned that Iranian-affiliated cyber actors are targeting internet-connected industrial control systems used by US critical infrastructure, including water and wastewater facilities. But until this point, the White House has tried to avoid blaming Iran. We heard in Minnesota, there was a cyber attack that they blame it on Iran. I don't think so. I think I blame it on Minnesota because they're grossly incompetent. Iran certainly has been doing this well before this conflict, and this is something we certainly need to be aware of. We're at four now. We need to be diligent. Since the cyber security and infrastructure security agency warned Thursday, it is seeing, quote, a significant increase in cyber threat actors targeting programmable logic controllers, PLCs in the water and wastewater system sector, adding that the activity has resulted in boil water notices and sustained manual operations. All indications are pointing to Iran. Who has access to all our government system? How much has been penetrated and how much is being covered up right now? Because I think one of the biggest stories is going to be that all of our systems have basically been hacked. We got rid of all our top people. The Trump regime got rid of all of our top people. So I think what we're going to see is a natural consequence of that. That will learn that most of our systems have been susceptible to all these different intelligence agency operations and hacking group operations. And they're just sitting on this information right now. Hit subscribe. Let's get to seven million subscribers. And thanks for watching everybody. Hey, if you want the full story, how democracy got here and how we take it back, pre-order our new book WTF America today. Just scan the QR code or click the link in the description. Let's do this. Hey, Tiffany Strang here from the WWE Smackdown. Tiffy Time can be crazy at y'all. And when I get a break, that means it's Chumba Time. Chumba Casina has hundreds of online social games and new titles landing every week. There's always something fresh to try. And the daily boosts make Chumba even more fun. They're little epiphanies that make my day sparkle. Ready for a fun way to switch off and take some time for yourself? Let's Chumba. No purchase necessary in VGW group. Void were prohibited by long. CKs insane. 21 plus sponsored by Chumba Casino.
Podcast Summary
Key Points:
The FBI database has been repeatedly hacked, with the most recent breach by the "shiny hunters" group exposing sensitive personal data of thousands of FBI employees, including job assignments, addresses, and spouses' information.
The attack exploited a zero-day vulnerability in Oracle PeopleSoft and used a commercial internet service provider’s infrastructure to infiltrate the FBI’s network, then pivoted to Amazon-hosted government cloud systems.
The FBI’s own remote operations unit (ROU), which conducts cyber-hacking operations against foreign intelligence, has been exposed, revealing significant internal vulnerabilities and potentially compromising identities of agents.
A broader pattern of government system breaches includes hacks of Cash Patel’s emails in March, the Department of Homeland Security in June, and over 30 water facilities in Minnesota and Michigan in August, with evidence pointing to Iranian-affiliated cyber actors.
Despite official claims of limited impact, cybersecurity experts warn of a coordinated and escalating threat targeting critical infrastructure, with U.S. leaders like Donald Trump deflecting blame onto states rather than acknowledging foreign intelligence involvement.
The Trump administration’s cybersecurity weaknesses—such as removing top officials and downplaying attacks—have likely enabled foreign intelligence agencies to exploit and access vast amounts of sensitive data.
The compromised data, including pen register and trap-and-trace records, could be used by foreign powers to target U.S. investigations, especially against Chinese, Russian, or North Korean intelligence operations.
Investigations into the attacks remain underdeveloped, with the White House and government agencies accused of covering up the scale and sophistication of cyber intrusions across federal systems.
Summary:
S. government systems, including the FBI, Department of Homeland Security, and critical water infrastructure in Minnesota and Michigan. The most recent FBI breach by the "shiny hunters" group compromised personal data of thousands of employees, including job details, addresses, and family information, and revealed the FBI’s own hacking unit.
The attack exploited a zero-day vulnerability in Oracle PeopleSoft and leveraged third-party infrastructure to infiltrate systems. This follows a pattern of breaches dating back to February and March, including hacks of Cash Patel’s emails and DHS data. S.
officials—including Donald Trump—have blamed incompetent state governments instead of external threats. The Trump administration’s dismantling of cybersecurity leadership and lack of transparency have likely enabled foreign intelligence agencies to penetrate and exploit sensitive data. With critical infrastructure increasingly at risk and internal systems exposed, the full scale of the cyber threat remains obscured, raising serious concerns about national security and public safety.
FAQs
The hacking group 'Shiny Hunters' defaced the FBI jobs.gov portal and exploited a zero-day vulnerability in Oracle PeopleSoft to gain access to personal data of FBI employees, including addresses, phone numbers, and details about their spouses.
The stolen data includes sensitive personal information of FBI officials such as job assignments, addresses, phone numbers, and details about their spouses, potentially revealing information about the FBI's secretive hacking unit.
They exploited a zero-day vulnerability in Oracle PeopleSoft, a platform used by the FBI for job applications and employee records, and then pivoted to an Amazon-hosted government cloud to access and extract data.
Yes, prior breaches included the hacking of Cash Patel's personal emails in March, the Department of Homeland Security database in June, and water facility systems in Minnesota and Michigan in August.
Yes, the FBI has warned that Iranian-affiliated cyber actors are targeting water and wastewater systems, and investigations have found activity linked to such threats, though the White House initially avoided direct attribution.
It suggests that the FBI’s own remote operations unit (ROU), which conducts cyber operations against foreign intelligence, may have been compromised, revealing sensitive details about its operations and personnel.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.