Read as article
ShinyHunters Hauled Off Terabytes From FBI Jobs Portal
By @sharedot · · 8 pages
ShinyHunters stole several terabytes of FBI personnel files from the jobs portal, and Google researchers say dozens of PeopleSoft systems worldwide are being hit.
What happened
NPR reports that the cybercriminal group ShinyHunters stole several terabytes of text files from the FBI jobs portal — not the bureau's case systems, but reams of personnel data. According to NPR, the haul covers job applications and promotions files with sensitive details including previous postings, medical information, and family names.
Why it is surprising
The irony is hard to miss: the agency tasked with investigating cybercrime just lost terabytes of its own people's records to criminals who specialize in extortion and leaks. NPR notes the last comparable event was the 2015 Office of Personnel Management breach, which the US attributed to the Chinese government — but this time the perpetrators are career criminals with a reputation for leaking stolen files. In a twist, ShinyHunters told NPR they now say they have no plan to publish the information, claiming their goal was to get the FBI to correct public statements about them — yet they have already given parts of the data to reporters.
The PeopleSoft connection
NPR reports new research from Google pointing to a widespread compromise of third-party software called PeopleSoft, the Oracle-acquired HR platform whose clients include big retailers and government agencies. According to NPR, the platform was first targeted over the summer; protections were put in place but the problem was not fully fixed, and attackers are now hitting dozens of systems around the world. The vulnerability was potentially used to access the FBI system, and other criminal groups besides ShinyHunters are actively looking to exploit it — meaning the FBI breach may be one visible edge of a much larger campaign.
The mood inside the bureau
NPR's reporting describes a grim mood among current and former FBI staff: more anger and frustration than panic, with some dark humor and memes circulating. Frustration is directed mostly at FBI leadership, with employees feeling there has been little communication about how the bureau will protect current and former employees; only a few people have been notified so far. A community of former employees is banding together to figure out how to help each other if the data surfaces. Many are assuming the data is effectively out in the world, ready for hostile actors to buy or steal from ShinyHunters.
Takedowns and taunts
The Dutch police arrested a member of the group in Amsterdam earlier in September, though they only publicly announced the arrest recently, NPR reports. The FBI then posted an unusual video on social media in which Cyber Division assistant director Brett Leatherman taunted ShinyHunters directly: 'You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.' The FBI says publicly it is aggressively investigating the point of the breach, mitigating the damage, and is in regular communication with anyone who may be impacted.
What comes next
The FBI jobs-portal incident lands alongside the Pentagon DMDC breach, which TIME reports affected some 2.76 million living individuals and 294,000 deceased individuals, with year-long credit monitoring offered through IDX. The broader stakes are simple: identity data like Social Security numbers and birth dates cannot be replaced, and NPR notes bad actors worldwide will be committed to stealing the FBI files from ShinyHunters. Expect more PeopleSoft-targeted intrusions until Oracle's fix actually holds, and expect the FBI breach's real damage to be measured in phishing and impersonation campaigns against bureau staff for years.