{"id":359419,"date":"2026-09-29T02:12:13","date_gmt":"2026-09-29T02:12:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-ny\/359419\/"},"modified":"2026-09-29T02:12:13","modified_gmt":"2026-09-29T02:12:13","slug":"embarrassing-breach-at-f-b-i-fuels-fears-of-harm-to-its-employees-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-ny\/359419\/","title":{"rendered":"Embarrassing Breach at F.B.I. Fuels Fears of Harm to Its Employees"},"content":{"rendered":"<p class=\"css-12m5bll evys1bk0\">The theft by a criminal hacking group of reams of sensitive personal data involving potentially tens of thousands of former and current F.B.I. employees is emerging as one of the worst breaches of sensitive government information, leaving the bureau rushing to protect its personnel as an uncertain deadline loomed.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Nearly a week after the group, known as ShinyHunters, <a class=\"css-povzk\" href=\"https:\/\/www.nytimes.com\/2026\/09\/23\/us\/politics\/fbi-hack-shinyhunters-data.html\" title=\"\" rel=\"nofollow noopener\" target=\"_blank\">revealed it had pilfered<\/a> intimate details about bureau personnel from the agency\u2019s jobs portal and threatened to leak them online, F.B.I. investigators are still piecing together how the breach took place and the total damage.<\/p>\n<p class=\"css-12m5bll evys1bk0\">The hack appears to have swept up home addresses, Social Security numbers, secretive job assignments and much more, according to a New York Times analysis of some of the records. Some are already comparing it to China\u2019s breach of more than 20 million records from the Office of Personnel Management over a decade ago, considered so catastrophic that officials and lawmakers vowed to never let something like it happen again.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Many F.B.I. employees <a class=\"css-povzk\" href=\"https:\/\/www.404media.co\/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">first learned about the hack<\/a> when news reports about it surfaced on Tuesday, according to current and former officials. The next day, F.B.I. staff received an email reminding them that October is cybersecurity awareness month, which struck some as tone deaf in light of the breach, one of those people said.<\/p>\n<p class=\"css-12m5bll evys1bk0\">On Friday, bureau leaders, in an internal memo to its rank and file, declared the hack a cybersecurity incident and acknowledged its employees had personal information stolen.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cWe are operating under the premise that the threat actor is also exfiltrating PII of all F.B.I. employees,\u201d according to the memo, which was described by someone who had seen it, using the abbreviation for personally identifiable information.<\/p>\n<p class=\"css-12m5bll evys1bk0\">The memo said the agency would offer virtual briefings in the weeks ahead and instructed employees to remain vigilant at home and at work, report any unsolicited contacts or threats, avoid answering calls from unknown numbers and set up voice mail accounts with A.I.-generated voices. \u201cBureau leadership remains committed to supporting the safety of you and your family,\u201d it said.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Still, many past and present personnel remain in the dark about whether their data has been purloined. In recent days, some have anxiously asked Times reporters whether their names are contained in the hacked data, wondering whether they needed to take steps to protect themselves or their families.<\/p>\n<p class=\"css-12m5bll evys1bk0\">In a statement on Monday, the agency said it was \u201cworking around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted \u2014 including multiple bureau-wide communications within 24 hours of public reporting.\u201d<\/p>\n<p class=\"css-12m5bll evys1bk0\">It added, \u201cThe F.B.I. treats the security of its information and the safety of its work force as top priorities, and our investigation is ongoing.\u201d<\/p>\n<p class=\"css-12m5bll evys1bk0\">In announcing its hack, ShinyHunters, believed to be a loose collective of young hackers operating across the globe, said it had targeted the F.B.I. as retribution for a <a class=\"css-povzk\" href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260515\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">public advisory<\/a> the bureau had issued in the spring, warning that the group was known to harass victims and family members with threatening or coercive maneuvers. In their note, the hackers demanded that the F.B.I. \u201ccorrect or simply REMOVE\u201d the advisory or risk further consequences.<\/p>\n<p class=\"css-12m5bll evys1bk0\">In an email to The Times on Friday, ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request, even as the hackers themselves appeared to acknowledge that the bureau was unlikely to acquiesce.<\/p>\n<p class=\"css-12m5bll evys1bk0\">That note left open the possibility that the hackers would not dump the data online, even as the group reiterated its deadline. But on Monday, in a new statement, the group claimed it never intended to do so.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cSince the very beginning we had made our decision that we would never publish this data,\u201d the group said. \u201cWe have never intended to nor have we ever planned to.\u201d It added that the hack and threat to the F.B.I. was a \u201cmarketing campaign to protect our business\u201d and said that \u201cwe are not taking any further actions\u201d with the data, including revealing more about what is contained in the files.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cWe seek no escalation as our goals have widely been accomplished,\u201d it said.<\/p>\n<p class=\"css-12m5bll evys1bk0\">It remains to be seen what ShinyHunters will do, and security researchers warned that even if they did not publish it online they could still sell it to other criminals or foreign governments.<\/p>\n<p class=\"css-12m5bll evys1bk0\">It is also unclear just how much sensitive information the hackers stole. The group claimed publicly to have stolen records on everyone who has applied for a job at the F.B.I., and told The Times that the people with compromised information numbered in the tens of thousands.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Ciaran Martin, the former head of Britain\u2019s cyberdefense agency, said the F.B.I. hack likely had \u201chuge impact on the operational capability\u201d of the bureau and could rank as one of the most consequential data breaches in history \u2014 graver even than the Office of Personnel Management burglary.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cLosing the data on 20 million federal employees to the Chinese was bad,\u201d Mr. Martin said. \u201cBut you knew the Chinese weren\u2019t going to sell or publish it.\u201d<\/p>\n<p>From Sensitive Job Assignments to T.S.A. PreCheck<\/p>\n<p class=\"css-12m5bll evys1bk0\">A sample of records that the hackers have shared with The Times and other news organizations includes newer hires as well as retired ones, with birth dates ranging from the early 1940s to the mid 2000s. The most recent date references in the spreadsheet were from late April, suggesting the stolen files are at most only months old.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Current and former U.S. officials said that at least portions of the sample, and potentially all of it, appeared to be authentic.<\/p>\n<p class=\"css-12m5bll evys1bk0\">A Times review of the sample found that it contained a range of private personal data, including:<\/p>\n<p class=\"css-1bhfxxi evys1bk0\">The names, home addresses, phone numbers, work emails, Social Security numbers and birth dates and hire dates of current and former F.B.I. personnel.<\/p>\n<p class=\"css-1bhfxxi evys1bk0\">Names and numbers for spouses and other emergency contacts, including in some cases parents, siblings and even children.<\/p>\n<p class=\"css-1bhfxxi evys1bk0\">Employee identification numbers that are used for the Transportation Security Administration\u2019s PreCheck program, which could aid spies in tracking travel itineraries of agents, including those that work undercover.<\/p>\n<p class=\"css-1bhfxxi evys1bk0\">Names of the units in which F.B.I. personnel are employed and their job titles, as well as the names of supervisors. While some list mundane departments, others reveal extraordinarily sensitive assignments including counterintelligence, narcotics and various desks focused on Russian, Chinese and Iranian national security threats. F.B.I. agents in those roles are generally expected to zealously protect their work in such fields to avoid putting a target on their back.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Additionally, ShinyHunters said that it had stolen medical data about employees, including psychiatric records and documents related to blood and urine tests. It also said that it had additional background check files on employees.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Former bureau officials and security experts said the hacked data prompted no end of worries. The data could also make it far easier for violent criminals to seek revenge against F.B.I. agents who sent them to prison. When they submit paperwork against criminal suspects, F.B.I. agents sign their names to the records but are typically trained to not let delicate personal information easily emerge online.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cIt doesn\u2019t take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released,\u201d said Andrew Brandt, a threat intelligence researcher at the cybersecurity company Huntress. \u201cThe bigger worry is ShinyHunters selling the data to other criminal or nation-state groups who could put it to more damaging use, rather than dumping it themselves.\u201d<\/p>\n<p class=\"css-12m5bll evys1bk0\">Security experts said that given the breadth of the records, they would be of enormous value if they were acquired by foreign spies, who could then use the material to build elaborate dossiers on F.B.I. agents \u2014 including those who may be undercover or later assigned to such a post \u2014 and track them for years, if not decades. Aided by artificial intelligence, spies or hackers could also combine the information with other exposed data that is already in their hands or that is easily acquired on the dark web.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cBreaches do not exist in a vacuum,\u201d Justin Sherman, a senior associate at the Center for Strategic &amp; International Studies, wrote in a recent essay arguing that different exposed data sets can be combined and analyzed by hostile spy services.<\/p>\n<p>A History of Security Lapses<\/p>\n<p class=\"css-12m5bll evys1bk0\">The hack is just the latest in a string of embarrassing security failures for the F.B.I.<\/p>\n<p class=\"css-12m5bll evys1bk0\">Two years ago, government investigators learned that Chinese spies had compromised vast segments of the nation\u2019s telecommunications infrastructure in a hacking campaign known as Salt Typhoon. Among the most startling revelations was that the breach included sensitive wiretap networks at Verizon and AT&amp;T that process court-authorized surveillance orders for the F.B.I. to monitor domestic criminal suspects.<\/p>\n<p class=\"css-12m5bll evys1bk0\">China has denied involvement, but U.S. intelligence officials considered the compromise a counterintelligence failure of the highest magnitude, with national security implications that could last for years. It prompted such alarm within the F.B.I. that field offices were told to check if informants had been potentially compromised and, if necessary, take steps to ensure their safety.<\/p>\n<p class=\"css-12m5bll evys1bk0\">The bureau still does not understand the full scale or scope of Salt Typhoon and its exposure from it, according to current and former U.S. officials. But the F.B.I. received another blow this spring when suspected Chinese hackers were found again inside a network it maintains for domestic surveillance orders.<\/p>\n<p class=\"css-12m5bll evys1bk0\">In the case of ShinyHunters, it was not Chinese spies but a notorious gang of cybercriminals who hit the F.B.I. Already, bureau leadership had warned staff that hackers linked to ShinyHunters who infiltrated AT&amp;T in 2024 may have stolen months of call and text logs belonging to some of its agents, which also fanned concerns about whether its informants had been exposed, <a class=\"css-povzk\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2025-01-16\/fbi-has-warned-agents-it-believes-hackers-stole-their-call-logs\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">as Bloomberg reported last year<\/a>.<\/p>\n<p class=\"css-12m5bll evys1bk0\">The members of ShinyHunters are seen as highly skilled \u2014 and audacious \u2014 English-speaking hackers who extort their victims for millions of dollars and brag about their exploits. In their recent correspondence with The Times, the hackers have favored British spellings of certain words.<\/p>\n<p class=\"css-12m5bll evys1bk0\">A French citizen charged with participating in some ShinyHunters attacks was arrested in Morocco in 2022, extradited to the United States and sentenced to three years in prison. Other suspected members were arrested last year in France.<\/p>\n<p class=\"css-12m5bll evys1bk0\">On Monday, a security journalist, Brian Krebs, <a class=\"css-povzk\" href=\"https:\/\/krebsonsecurity.com\/2026\/09\/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation\/\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">reported<\/a> that authorities in the Netherlands had arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions tied to ShinyHunters just days before the F.B.I. breach. ShinyHunters said in response on Monday that the Dutch suspect \u201chas no association with us.\u201d<\/p>\n<p class=\"css-12m5bll evys1bk0\">The F.B.I.\u2019s Dallas field office has been leading an investigation into ShinyHunters and working with international partners to hunt down other members, according to people familiar with the matter who were not authorized to speak publicly.<\/p>\n<p class=\"css-12m5bll evys1bk0\">It is not clear exactly how ShinyHunters pulled off the F.B.I. hack. The group said it had used a zero-day, or previously undiscovered, coding flaw within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.<\/p>\n<p class=\"css-12m5bll evys1bk0\">But some security researchers said the story may be more complicated. On Friday, Google revealed in a <a class=\"css-povzk\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft\" title=\"\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">blog post<\/a> that its threat intelligence teams have recently seen ShinyHunters renewing a campaign of \u201cmass exploitation\u201d against victims using a bug with Oracle PeopleSoft that was publicly disclosed with a patch in June. The post does not mention the F.B.I. breach, but a person familiar with the matter said investigators believe the known bug was involved in the ShinyHunters theft of personnel files.<\/p>\n<p class=\"css-12m5bll evys1bk0\">The flaw was considered important enough that the Cybersecurity and Infrastructure Security Agency promptly added it to a catalog of high-risk known vulnerabilities that federal agencies are instructed to quickly address.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cThis type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,\u201d CISA said at the time.<\/p>\n<p>An Uncertain Deadline<\/p>\n<p class=\"css-12m5bll evys1bk0\">In response to questions from The Times, ShinyHunters said in an email on Friday that the F.B.I. had not contacted the group and that it would hold firm to its Tuesday deadline.<\/p>\n<p class=\"css-12m5bll evys1bk0\">The hackers said that the severity of the breach was \u201cSIGNIFICANTLY\u201d worse than publicly known but did not explain in what way. Cybersecurity researchers who have followed the collective have said it has a track record of sometimes embellishing its activities but so far, in this breach, its claims have been largely corroborated.<\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cWe have no intention to reveal the true impact, we will leave that to the F.B.I.,\u201d ShinyHunters said. \u201cIf they lie, we will not correct them.\u201d<\/p>\n<p class=\"css-12m5bll evys1bk0\">The group also said that it was aggrieved by the F.B.I.\u2019s advisory and that the hack was \u201call about protecting our business.\u201d <\/p>\n<p class=\"css-12m5bll evys1bk0\">\u201cThis is happening so we are heard and acknowledged,\u201d ShinyHunters said. \u201cWe may sound like children whose feelings are hurt, sure, but in our game, reputation is all that matters.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"The theft by a criminal hacking group of reams of sensitive personal data involving potentially tens of thousands&hellip;\n","protected":false},"author":2,"featured_media":359420,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[38],"tags":[128,86628,99703,129478,86627,90403,133712,11597,4669,9,24,63,18545,129,131,130,76290],"class_list":["post-359419","post","type-post","status-publish","format-standard","has-post-thumbnail","category-the-bronx","tag-bronx","tag-computer-security","tag-cyberattacks-and-hackers","tag-cybersecurity-and-infrastructure-security-agency","tag-cyberwarfare-and-defense","tag-espionage-and-intelligence-services","tag-extortion-and-blackmail","tag-federal-bureau-of-investigation","tag-government-employees","tag-new-york","tag-new-york-city","tag-nyc","tag-office-of-personnel-management","tag-the-bronx","tag-the-bronx-headlines","tag-the-bronx-news","tag-threats-and-threatening-messages"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/posts\/359419","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/comments?post=359419"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/posts\/359419\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/media\/359420"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/media?parent=359419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/categories?post=359419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ny\/wp-json\/wp\/v2\/tags?post=359419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}