Fbi data breach. Tech room with agents seated at computer monitors
FBI photo with RH filter.

FBI Data Breach: What Hackers Took From Agents

The FBI data breach exposed agents' home addresses, Social Security numbers, and medical records. Here's what hackers took and why it puts the country at risk.

Serena Zehlius
By
Serena
Serena Zehlius
Senior Writer
Serena Zehlius is a passionate writer and Certified Human Rights Consultant. Her love for animals is matched only by her commitment to human rights and progressive...
- Senior Writer
9 Min Read
Disclosure: This website may contain ads or links for affiliate products, which means we might earn a commission (doesn't affect price you pay) if you click on one and make a purchase. Resist Hate only recommends products we like and feel will add value to your life. Your support is appreciated! LEARN MORE
Summarize with AI
Total Reads:0

The FBI got hacked. Yes, the same FBI that tells the rest of us how to stay safe online.

A criminal hacking group called ShinyHunters says it broke into the bureau's job website. It walked away with personal files on thousands of FBI employees and job applicants.

For days, the FBI said the damage was still unknown. Then, on September 26, word got out that it had quietly told its own workers the truth: their names, addresses, job titles, and Social Security numbers had been exposed.

This FBI data breach is bad news for the agents. It's also bad news for the country.

What Happened

On September 22, 404 Media first reported that ShinyHunters claimed to have hacked the FBI. The group bragged to Reuters that it had data on "almost ALL" FBI agents, plus people who had applied for jobs there.

The target was FBIJobs.gov, the site where people have applied for FBI jobs since 2017. Soon after the claim, the jobs site and the special agent application portal both went offline.

The hackers say they used a brand-new flaw in Oracle PeopleSoft, a common human resources program, to reach servers in Amazon's government cloud, Nextgov reports.

No one has confirmed that yet. But Google's security team says ShinyHunters has been attacking PeopleSoft systems on a large scale.

On September 23, the FBI said it was "actively and aggressively investigating." It admitted it didn't know yet whether the break-in happened at the FBI itself or at an outside company that helps run the site.

What the Hackers Took

ShinyHunters says it stole two to three terabytes of data. That's a mountain of files. To prove it, the group gave reporters a sample with about 5,000 entries.

Reuters found that the sample included names, home addresses, phone numbers, birth dates, Social Security numbers, and emergency contacts.

Some entries listed spouses and relatives. Reuters checked more than 22 people against credit records and older leaks, and their details matched.

Affilate
Dog food adDog food ad

One apparent match was FBI Director Kash Patel himself.

The sample also showed what people do at the FBI. Some entries tied employees to work against Chinese spies, Russian intelligence, and drug cartels. Eighteen people were listed in surveillance and interception jobs.

Nextgov reported that the files also named people in the FBI's Remote Operations Unit, a team that builds tools to break into computers.

Then it got more personal. Reuters reviewed a half-dozen files that included psychiatric and medical evaluations of FBI staff, and was able to partly confirm some of them.

The BBC saw blood and urine test results from fitness-for-work exams. The hackers say they got into MedLink, the system that holds employee medical records.

Think about who is in this data. It's not just veteran agents. It's also people who simply applied for a job. Someone who applied years ago and never got hired may now have their personal details on a hacking group’s server.

Why They Did It

ShinyHunters says this wasn't about money. In May, the FBI published a public warning about the group. It said ShinyHunters harasses victims and their families with threatening calls and texts.

In some cases, the FBI said, the group uses swatting, which means making a fake 911 call so armed police show up at someone's door.

The hackers demanded that the FBI take down that warning within a week. They addressed their letter to Patel and Brett Leatherman, who leads the FBI's Cyber Division.

So to prove they don't threaten people, they stole thousands of home addresses and held them over the FBI's head.

That's one way to show you're not a bully.

On September 28, the group changed its tune. It told Nextgov it never planned to publish the data and called the whole thing a "marketing campaign."

It didn’t say it had deleted anything.

Why This Is So Dangerous

National security expert Justin Sherman called the breach a "counterintelligence disaster" in Lawfare. If this data leaks or gets stolen again, countries like China, Russia, and Iran could use it to find FBI workers to spy on, trick, or blackmail.

Affiliate
Ad imageAd image

A young applicant today could be a top spy-catcher in ten years. Foreign spies would already have their file.

Former FBI counterintelligence operative Eric O'Neill called the stolen data a "foreign intelligence service goldmine."

The danger isn't only overseas. Sherman warned that leaked home addresses could lead to doxxing, swatting, or revenge attacks on agents who worked cases against organized crime, terrorists, and human traffickers.

Their families live at those addresses too.

And the damage doesn't fade. "Once that information is stolen, it is used forever," Cynthia Kaiser, a former FBI cyber official now at the security firm Halcyon, told Reuters.

She noted that a leak of FBI data from 2016 is still sometimes used to harass agents today.

The Government Left the Door Open

No computer system is hack-proof. But this administration has made the hackers' job easier.

It slashed staff at the Cybersecurity and Infrastructure Security Agency (CISA), the agency built to defend government networks. The cuts were so bad that lawmakers called for an investigation.

It also pulled Homeland Security cyber staff off their jobs to work on Trump's mass deportation project. Cybercrime is exactly what hackers do.

Some of the people trained to fight hacking were sent to chase immigrants instead.

This isn't even the FBI's first breach this year.

Hackers believed to be Chinese broke into an FBI surveillance system that exposed the targets of FBI investigations.

In March, a pro-Iran hacking group also claimed it hacked an account belonging to Patel.

Caricature of kash patel. One victim of the fbi data breach by shinyhunters hacking group.
Photo credit: DonkeyHotey on Flickr (CC BY 2.0)

Then there's Congress. Federal rules require agencies to tell lawmakers about a "major incident," which includes stolen personal data likely to harm national security.

As of Monday, it wasn't clear whether the FBI had done that. Its own workers heard first. The public heard from hackers and reporters.

What’s Next

The FBI still hasn't said how many people are affected or exactly how the hackers got in. Adam Marrè, a former FBI special agent, told Nextgov the bureau must now learn how bad the damage is, contain it, and fix the holes that let the hackers neak in.

If you ever applied for a job with the FBI, don't wait for a letter. Freeze your credit with all three credit bureaus. Be extra careful with emails and texts that seem to know a little too much about you. If you spot identity theft, report it at IdentityTheft.gov.

The people who protect us from hackers deserve better protection themselves. So does everyone who ever stood up, wanting to serve.

What Can I Do?


If you ever applied for a job with the FBI, don't wait for a letter. Freeze your credit with all three credit bureaus. Be extra careful with emails and texts that seem to know a little too much about you. If you spot identity theft, report it at IdentityTheft.gov.

See more of our content in Google search results!

Share This Article
Serena Zehlius
Senior Writer
Follow:
Serena Zehlius is a passionate writer and Certified Human Rights Consultant. Her love for animals is matched only by her commitment to human rights and progressive values. When she’s not writing about politics, you’ll find her outside enjoying nature.
Leave a Comment