Subscribe Sign in

Politics

FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

Ars Technica
3 min read Rewritten in plain language

PolicySecurityFbiHackersShinyhunters

Show what we removed Rules applied: A3 C2 C5 D3×3 D4 F2 all 30 rules
  • The FBI is now investigating claims from a hacker group that thousands of current and former employees’ personal data was stolen after the group exploited a previously unknown bug found on an agency jobs website.
  • About two to three terabytes of data were taken, ShinyHunters told The New York Times.
  • In a message posted on the dark web that was reviewed by Ars, ShinyHunters said it was “severely offended” that the FBI alleged that they sometimes use “exaggerated claims” to extract payments from victims.
  • To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or risk a breach of sensitive employee data.
  • The FBI has not confirmed that the hack occurred, but it has begun probing the claims.

5 sentences from our version of the report, chosen to cover it. Nothing here is written; every line is in the article below. How

The FBI has not confirmed the hack occurred, but it has begun probing the claims.

Headline check

The one thing this headline claims is in the report.

Figures, names and quoted words in the headline, looked for in the report itself — not in the summary above. One claim in this headline could be checked, so this is a narrow pass and not a thorough one. How this is checked

Read the full reportHide the full report3 min

The FBI is now investigating claims from a hacker group that thousands of current and former employees’ personal data was stolen after the group exploited a previously unknown bug found on an agency jobs website.

On Tuesday, 404 Media reported that ShinyHunters took down the agency site, FBIJobs.gov, then posted a banner on the homepage that said “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”

About two to three terabytes of data were taken, ShinyHunters told The New York Times. None of the data has been leaked yet, but it included “names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information, and other data.” According to Bloomberg, the data could be used to potentially retaliate against agents, with one sample appearing to include “potentially sensitive professional information on the FBI employees’ work focus such as counter-intelligence work on China, Russia and Iran, as well as work against street gangs.”

The group’s motive was not to extort the FBI or seek a ransom, it said. Instead, the strike was meant to force the FBI to either remove or edit a May advisory warning about ShinyHunters that the group said circulated “disinformation in an attempt to ‘disrupt’ our operations.”

In a message posted on the dark web that was reviewed by Ars, ShinyHunters said it was “severely offended” that the FBI alleged that they sometimes use “exaggerated claims” to extract payments from victims. “We wish to state unequivocally our threats and claims are very real,” the group said. “Not exaggerated and never a bluff.”

ShinyHunters was also upset that the FBI claimed the group conducts swatting attacks against corporate workers and makes sextortion threats. That “never” happens, ShinyHunters said.

To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with demands or risk a breach of sensitive employee data.

Not many details have been released on how ShinyHunters got access to the data. ShinyHunters would only tell NYT that “it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management.” So far, Oracle is silent on that bug, reports said, while ShinyHunters said it plans to continue using the zero-day for its “businesses’ normal operations.”

The FBI has not confirmed that the hack occurred, but it has begun probing the claims. On Wednesday, the FBI said in a X post that “the point of breach is still undetermined—whether a third-party or the FBI’s enterprise.” Until more information is known, the FBI said, “we are actively and aggressively investigating this matter and working closely” with third-party providers that support the jobs site “to mitigate any and all risk.”

As of Wednesday, the jobs site remained inaccessible, as sources inside the FBI told Bloomberg that all personnel received an email warning them to “take steps to protect themselves while the investigation continues.”

ShinyHunters has not said what will happen if the FBI misses the deadline, but cybersecurity experts told the NYT that most likely the data will be leaked online.

“We cannot comment on what we will do if the FBI does not comply with our request,” ShinyHunters said in an email to the NYT. “We reiterate we are not extorting the FBI and this is NOT financially motivated.”

“Our intention, goal, and motive is solely to set the record straight,” the group said.

You are reading our version, not theirs. This is Ars Technica's report with its verdicts and loaded words taken out. Plain description stays, and so do adjectives that carry a fact, such as "former" or "federal". The reporting, the facts and the quotations are theirs — quotations are never edited — and the indicators beside it measure this version. Hover or tap Adjectives to see every one left in the text.

How this outlet filed it, and how we rewrote it

No other newsroom we read has filed on this event, so there is nothing to compare it with yet.

Outlet Niral ScoreAdjectivesSourcingSentimentHappiness
Ars Technicaas they published this story 4.2 4 91 -0.2 48.6
Mundane Readneutralized from Ars Technica 3.2 4 91 -0.2 48.6

Sign in to react.

Comments

Nothing here yet.

Sign in to comment.

Questions

Readers can ask a question about this story here. Questions and answers are for subscribers. Sign in to read them.

Comments are read before they appear where anything in them needs a person to look. Nothing posted here is ever deleted; a comment taken down keeps its text and the reason, so the decision can be looked at again. How this works