Why hacker group’s claim that it has stolen over 2 terabytes of data has left FBI ‘worried’ | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A notorious cybercrime group known as ShinyHunters has claimed responsibility for stealing more than 2 terabytes of data from FBI systems, including detailed personal information about thousands of employees and job applicants, according to a report by Axios. The group posted on its dark‑web site that it had obtained “very sensitive data on almost ALL FBI agents and individuals who filed an application with the FBI for a job.” According to ShinyHunters, the stolen data includes names, agent statuses, emails, phone numbers, home addresses, Social Security numbers, and even spouse information. While cybercriminals and state-sponsored hackers have been infiltrating US IT systems for years, cyber experts told Axios that stealing sensitive personal data specifically about FBI employees marks a notably bold escalation. The concern isn’t just the breach itself — it’s what happens next. Stolen data of this kind is routinely traded on the dark web, effectively putting it up for sale to whichever buyer is willing to pay the most.

The group behind the claim FBI hack

The hacking group ShinyHunters, which has a track record of breaking into numerous institutions, posted on its dark-web site Tuesday claiming to have stolen highly sensitive data covering nearly all FBI agents and everyone who has ever applied for a job with the bureau. An FBI spokesperson confirmed the bureau is aware of claims involving unauthorized activity on FBIjobs.gov and said it’s currently investigating.Cynthia Kaiser, a former senior official in the FBI’s cyber division, told Axios that when hackers target the FBI directly, the bureau typically responds by dedicating extra resources to bringing those responsible to justice more quickly than in a typical case.

What was allegedly stolen

According to ShinyHunters, the stolen dataset includes names, agents’ employment status, email addresses, phone numbers, home addresses, and in some cases even spouse information — including Social Security numbers. The group also claims it accessed the FBI’s criminal justice and HR systems, among other internal services, and says it defaced the bureau’s jobs webpage by exploiting a zero-day vulnerability in Oracle’s PeopleSoft platform. That site remained offline as of Tuesday afternoon.Axios said it could not independently verify whether the stolen data is legitimate or recent, though cybersecurity researchers confirmed the underlying attack itself appears genuine. Separately, 404 Media obtained a sample of the data that reportedly includes information tied to roughly 5,000 alleged agents.

The bigger risk isn’t the hack — it’s what comes after

Allan Liska, a threat intelligence analyst at Recorded Future, told Axios that while the breach will likely draw more law enforcement attention to ShinyHunters in the near term, the more lasting damage falls on the FBI employees and families whose information was exposed. He noted that once data like this is out, it tends to get downloaded and passed around repeatedly among other threat actors, making it nearly impossible to fully contain.Andrew Brandt, principal threat intelligence incident commander at Huntress, echoed that concern, saying the real danger hinges on whether ShinyHunters ultimately decides to sell the data to other criminal groups or nation-state hackers. He warned it isn’t hard to imagine scenarios where FBI employees or their family members could face direct threats or harm if this kind of information is released more widely.

FBI’s Response

An FBI spokesperson confirmed the bureau is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” Former FBI cyber division official Cynthia Kaiser told Axios that when hackers target the FBI, the bureau typically “marshals additional resources to bring them more quickly to justice.”



Click Here For The Original Source.

——————————————————–

..........

.

.