The group that illegally obtained the data of thousands of FBI employees: agents were informed by the media, hacker suspected of being linked to…

The cyberattack in which hackers obtained a large amount of personal data belonging to current and former FBI employees is becoming one of the most dangerous incidents involving sensitive government information in the United States. The Federal Bureau of Investigation is working to protect its staff, while the full extent of the damage remains unknown.

Të lidhura

None found

Almost seven days have passed since the ShinyHunters group announced the attack, claiming that it had obtained FBI employees’ data through the agency’s online recruitment portal and threatening to make it public. FBI investigators are still trying to determine how the breach occurred and its true scale.

An analysis of the data reviewed by The New York Times indicates that the hackers are believed to have obtained home addresses, Social Security numbers, sensitive employment details and other personal information. Some have already compared the incident to China’s cyberattack on the US Office of Personnel Management a decade ago, when data belonging to more than 20 million people was stolen.

Many FBI employees learned about the incident from the media, according to current and former officials. The following day, staff received an email reminding them that October marks Cybersecurity Awareness Month, an action some described as inappropriate given the seriousness of the situation.

In an internal memorandum to staff, FBI leaders described the event as a “cybersecurity incident” and confirmed that employees’ personal data had been stolen.

According to the memorandum, “action is being taken on the assumption that the threat actor has also exfiltrated personally identifiable information belonging to all FBI employees.”

The FBI has urged its personnel to exercise caution, report any suspicious communications or threats, avoid unfamiliar phone numbers and activate voicemail services that use artificially generated voices.

Despite the agency’s assurances, many current and former employees still do not know whether their information has fallen into the hackers’ hands and are concerned about their own safety and that of their families.

The FBI announced that it is working “around the clock” to investigate the incident linked to the FBIJobs.gov platform and is contacting people who may have been affected.

As for the threat from ShinyHunters, the group is described as a loose network of young hackers operating internationally. It claimed to have targeted the FBI in retaliation for a public warning the agency issued in the spring, accusing the group of harassing victims and their families.

The hackers demanded that the FBI correct or withdraw the warning, threatening further action if the agency did not comply.

They initially stated that they would publish the data if their demand was not met. However, on Monday they said they had never intended to put it online. According to the group, “We had decided from the beginning that we would never publish this data,” and it described the attack as a “marketing campaign to protect our business.”

Cybersecurity experts nevertheless warn that even if the information is not made public, it could be sold to other criminal groups or foreign governments.

Regarding the nature of the stolen data, the exact amount of information the hackers obtained remains unclear. The group claims to have obtained the data of every person who applied for a job at the FBI, which could bring the number of affected individuals into the tens of thousands.

A sample of files the hackers distributed to the media included names, home addresses, telephone numbers, work email addresses, Social Security numbers, dates of birth and employment data. It also contained information about spouses and emergency contacts, including parents, siblings and children, as well as identification numbers for employees linked to the TSA PreCheck program, which could help track agents’ travel. The distributed material also included data on FBI units, job positions and the names of supervisors.

The classified data includes reports on highly sensitive units, including counterintelligence, narcotics and departments dealing with national security threats from Russia, China and Iran.

ShinyHunters also claimed to have obtained employees’ medical data, including psychiatric records, blood and urine test documents, as well as information about security clearances.

Regarding the risk to agents and foreign intelligence services, security experts warn that this data could help foreign intelligence agencies build detailed profiles of FBI agents, including those working undercover.

With the support of artificial intelligence, hackers or espionage services could combine this data with other information they already possess or may obtain on the dark web.

The investigation into the attack is continuing, and it is still not known with certainty how ShinyHunters managed to gain access to the FBI’s systems. The group claims it exploited an unknown vulnerability in Oracle PeopleSoft software, which is used to manage human resources and financial data.

However, cybersecurity researchers believe the attack may be linked to a previously known vulnerability in the same system, for which a security update had already been released.

In another development, a 24-year-old Dutch man has been arrested in connection with the ShinyHunters hacking group and is expected to appear before a court in Rotterdam, local police announced.

The announcement did not disclose the detainee’s name, but Benjamin Korper, head of Amsterdam-based cybersecurity company Neo Security, said the man was Pepin van der Stapp, the company’s head of offensive security.

According to a Reuters source, Dutch cybercrime investigators visited the company’s offices on September 15, on the evening van der Stapp was arrested during a police operation that also involved the use of flash-bang devices.

The arrest comes at a time when concerns about ShinyHunters’ activities have grown. The group is known for large-scale data attacks and extortion.

The news of Van der Stapp’s arrest, first reported by journalist Brian Krebs, sent shockwaves through the security community.

Internationally, the Dutchman had become known for moving from a past in cybercrime to a career in systems defense.

His 2023 convictions for data theft and extortion received widespread publicity, as did his public denial of his previous actions.

Van der Stapp had acknowledged on his personal website that his path “had not been straight,” while arguing that his experience had taught him that “knowledge is for building and protecting, not destroying.”

The head of Neo Security said he had carefully checked Van der Stapp’s background before hiring him and had monitored his activities while he worked there.

Korper said: “I truly believe that people deserve a second chance, but in this case I was not rewarded for that. Everyone I have spoken to is shocked.”

He added that the company had hired an external team to determine whether Van der Stapp had compromised Neo Security’s systems or those of its clients, but so far there is no evidence that he acted against the company or its partners.

The ShinyHunters group denied that van der Stapp had any connection to it and called the Dutch authorities “incompetent.”

The hackers also said they were no longer giving the FBI a deadline to withdraw its warning about the group’s activities, softening the initial threat that had given the agency one week to respond.

The group stated: “This was not a threat. Nothing will happen.”


Shtuar më 29.09.2026 15:03

Tags:
sultanbeyli escortCasibomjojobetjojobetjojobetcasibomCasibomCasino welcome bonusjojobetcasibomjojobetmarsbahismarsbahis güncel girişcasinoroyaljojobetjojobetjojobet girişjojobet girişHoliganbet girişHoliganbet girişHoliganbetcasibomcasibombahsegelsekabetjojobet