An internal memo warned FBI staff that ShinyHunters, the group claiming it hacked the bureau's jobs site, may hold their private details.
The group denies that. It gave the bureau one week to retract the warning.
ShinyHunters is not new. It surfaced in 2020 selling stolen databases on hacker forums, and helped run one of the biggest, BreachForums. Last year it claimed about 1.5 billion records from customers of Salesforce, a popular customer-data platform.
Then the FBI hit back. Cyber Division Chief Brett Leatherman posted a video on X on Sept. 29, pointing to a Dutch arrest from Sept. 15 and telling the hackers "we know how to find you." He urged them to reach out first, and the group says the arrested man has no association with it.
FBI pitches ShinyHunters on cooperating: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours. pic.twitter.com/LP90fjlsnO
— Ken Klippenstein (@kenklippenstein) September 29, 2026
ShinyHunters later said the ultimatum was a marketing campaign and that it doesn't plan to publish the data. The memo also tells staff to expect virtual briefings and to watch for suspicious texts or calls from unknown numbers.
Why would a home address matter that much? Because stolen data rarely stays on a screen. If that data is released and employees get doxxed, employees could be threatened or harmed, identity theft cases may surge and relatives of doxxed FBI employees could be at risk.
Crypto has already shown the pattern. Coinbase said bribed support agents leaked customer data last year, then faced a $20 million extortion demand. As of April, France had recorded 135 crypto-related “wrench attacks” since 2023, and had charged 88 suspects .
In one case, attackers who beat a couple outside their Nancy apartment reportedly got their details from a January leak at Waltio, a French crypto tax platform that exposed about 50,000 users.
The one-week window the hackers set has passed, and ShinyHunters says it will not publish the data. The memo, as reported, tells staff to assume their data is already out.