ShinyHunters Claim: FBI Personnel Data Compromised
The ShinyHunters group claimed to have stolen terabytes of FBI personnel data by breaching PeopleSoft and AWS GovCloud.
The hacker group known as ShinyHunters claimed to have breached FBI systems and stolen 2 to 3 terabytes of personnel data, and some of the shared samples have been verified.
Cyberattack Claim and Method
The hacker group ShinyHunters alleged that they infiltrated the systems of the Federal Bureau of Investigation (FBI) and stole the agency's personnel data. The cybercriminals stated that the attack initially started via PeopleSoft.
The hackers asserted that following this phase, they transitioned to the AWS GovCloud environment and downloaded a total of 2 to 3 terabytes of data. The agency has not yet confirmed the details of the incident.
Shared Sample Data
The cybercriminals shared a sample dataset of 5,000 individuals from the archive they allegedly acquired. This list includes names, home addresses, phone numbers, dates of birth, and spouse information for some individuals.
Journalists cross-referenced a portion of the records with independent sources. The Reuters agency also confirmed that the name and address information of 9 individuals on the list is correct.
Currency and Scope of the Information
Although the attack is claimed to be recent, it is not yet known how up-to-date the information in the files is. The archive contains critical details that raise questions.
According to the statement by the ShinyHunters group, the archive includes not only current employees but also former FBI personnel and individuals who applied to the agency in the past.
Security Risks and Potential Dangers
If the hackers' claims turn out to be true, the incident could go far beyond an ordinary data breach and lead to serious security vulnerabilities.
Sensitive information such as home addresses, phone numbers, and family connections that has emerged could be used for targeted phishing attacks, harassment, or counterintelligence activities.