ShinyHunters, a cybercriminal group, claimed it breached the FBI and stole sensitive data on thousands of agents and job applicants, including names, addresses, and phone numbers. The hackers accessed an Oracle PeopleSoft server and Amazon-hosted government cloud, demanding the FBI remove a report about the group rather than seeking financial gain. The breach poses a significant counterintelligence risk and marks the second known FBI system compromise this year.
Hacking group ShinyHunters claims to have breached the FBI and stolen personal data on all FBI employees and applicants, including names, addresses, phone numbers, and spouse information. The group defaced the FBI jobs website and says it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating 2-3 terabytes of data. The breach poses significant national security and counterintelligence risks, as the stolen data could be used by criminals or foreign intelligence agencies to track and target FBI agents.