Cyber‑crime group ShinyHunters claims breach of FBI, steals employee data

NNewsdesk1 min read
Colorful cutout letters spelling 'Cyber Security' on a striped background.
Photo: Ann H / Pexels
Share

Cyber‑criminal group ShinyHunters said it breached the US Federal Bureau of Investigation (FBI) on 22 September, stealing personal details of current and former FBI staff.

The group posted a screenshot that it claimed contained information on 5,000 FBI agents, including names, addresses, phone numbers and spouse details. Reuters could verify some of the data, matching details to at least ten employees, one of whom was FBI director Kash Patel, but could not confirm the source of the leak or whether it came from FBI systems.

According to 404 Media, citing an FBI spokesperson, the breach was achieved via a zero‑day exploit in Oracle’s PeopleSoft product, allowing the attackers to access AWS GovCloud servers and download between 2 TB and 3 TB of data.

ShinyHunters said the attack was retaliation for an FBI report earlier this year that described the group’s methods and warned against paying ransoms. The group demanded the FBI correct or remove the report within a week, but gave no comment on what would happen to the data if the deadline passes.

Security expert William Wright warned that Oracle must act quickly to patch the alleged vulnerability, noting that any delay could leave other organisations exposed to further attacks.

Source: Silicon Republic. Photo: Ann H / Pexels.

Share