New details have emerged about ShinyHunters’ hack of the Federal Bureau of Investigation (FBI), including more info on the types of officials caught up in the breach. Some of the stolen records appear to identify members of the bureau’s secretive hacking unit.
404 Media reported Wednesday that it found three entries that referenced the FBI’s Remote Operations Unit.
The outlet says that the records involving the unit exposed “each person’s address, a list of phone numbers for them, and in some cases the name of their spouses and their phone numbers.”
404 Media said that when it searched one official’s phone number using the breached-data intelligence platform Darkside, it found previously leaked information linking that person to the Secret Service. Another person in the data tied to the unit was listed as a “student workforce trainee.”
404 Media first reported the breach on Tuesday. The outlet said the hacking group ShinyHunters shared a spreadsheet with the outlet listing the personal information of roughly 5,000 alleged FBI officials. The spreadsheet includes information about employees’ job assignments, along with addresses, phone numbers, and emergency contacts.
404 Media and other media outlets that received the stolen data were able to verify details belonging to some of the people on the list by cross-referencing the information with public records and previously leaked data.
Reuters reported that 14 people on the list were allegedly connected to the FBI’s work on China-related matters, while another nine were listed in Russia-related roles.
Meanwhile, the FBI acknowledged Wednesday that it is investigating a compromise involving its jobs website.
“The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the bureau said in a statement posted online.
As of Thursday morning, the FBI Jobs site is down.
The bureau said the point of breach is still unknown and that it is “actively and aggressively investigating this matter.”
ShinyHunters also posted a statement online addressed to FBI Director Kash Patel and Brett Leatherman, who oversees the bureau’s cyber division, taking responsibility for the breach and claiming it was carried out in retaliation for an FBI advisory about the group, according to The New York Times.
The group claims to have obtained sensitive information on nearly all FBI agents and job applicants.
ShinyHunters is now demanding that the FBI “correct or simply REMOVE” the advisory.
The FBI issued the advisory in May and said groups like ShinyHunters have used real or exaggerated claims of access to sensitive information to extort victims. It also warned that the hackers have used harassment tactics including threatening text messages and phone calls.
The breach comes amid a crazy year for cybersecurity. OpenAI agents have gone rogue during testing, U.S. intelligence agencies have warned that Iran-linked hackers are targeting American water systems, and officials have raised alarms about AI making attacks on critical infrastructure easier.
And just this month, Meta helped push AI agents further into the mainstream with Muse, which is wildly popular and has already been shown to have some security vulnerabilities. Amazon even blocked the agent from shopping on its site, citing privacy and security concerns.
Now, apparently, even the FBI’s own hacking team isn’t safe.
The FBI did not immediately respond to a request for comment.