While the FBI has not yet commented, the hackers defaced the agency’s recruitment website, and researchers verified that a sample of the stolen data matches records for Department of Justice personnel.
The breach carries severe national security and counterintelligence risks, as sensitive personal details could be used by foreign intelligence agencies or criminals to track and intimidate federal agents.
ShinyHunters stated they carried out the attack by using a zero-day exploit—a previously unknown software vulnerability—in Oracle PeopleSoft to gain access to AWS GovCloud servers.
The group claims to have exfiltrated between two and three terabytes of data, including both personally identifiable information and protected health information.
Unlike typical ransomware attacks aimed at financial gain, the representative characterized the group’s goal as "coercion" rather than extortion.
The incident has already disrupted government infrastructure, leaving the FBI jobs website and the Special Agent Applicant Portal unavailable.
This breach affects a broad range of individuals, from current and former employees to anyone who has applied for a position at the agency, potentially exposing them to long-term safety and privacy threats.