The FBI is investigating claims from hacking group ShinyHunters that it breached the FBI and stole personal information belonging to employees and applicants.
In a statement ShinyHunters said the group obtained data on “all FBI employees and applicants,” including names, home addresses, phone numbers and information about spouses.
According to a sample provided to 404 Media, the data contains information on about 5,000 alleged FBI employees. 404 Media said some of the phone numbers matched people with the same names listed in the sample, while others were associated with U.S. Department of Justice personnel.
ShinyHunters also claimed it breached and defaced the FBI jobs website, replacing it with a message saying the site had been “seized by ShinyHunters.” The group said it used a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers and steal 2 to 3 terabytes of data.
ShinyHunters claimed it compromised several FBI services, including Criminal Justice, HR and Medlink.
The group denied carrying out swatting attacks or sending threats to victims and their families, saying the operation was not financially motivated. It also gave the FBI one week to correct or remove a Quarter 2 FLASH report that ShinyHunters said contained false allegations about the group.
An FBI spokesperson told Reuters that the bureau is aware of “claims regarding unauthorized activity affecting FBIjobs.gov” and is investigating. The FBI has not confirmed that ShinyHunters accessed or stole the data it claims to possess.

