The FBI is investigating unauthorized activity involving its recruitment website after hackers claimed they obtained a potentially sweeping database of current and former bureau personnel, turning what initially appeared to be a compromised public-facing portal into a possible personnel-security breach.
The bureau said Tuesday it was “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
The FBI has not confirmed that personnel records were stolen.
ShinyHunters, a cyber-extortion group with a history of large-scale data theft, claims otherwise. The group told Reuters it obtained data on “almost ALL FBI Agents” and people who had applied for FBI jobs. It provided what it described as a sample containing information on roughly 5,000 agents.
Axios separately reported that the hackers claim to possess more than 2 terabytes of data covering thousands of employees and applicants.
The available evidence suggests at least part of the dataset may contain genuine information, although its origin remains unresolved.
Reuters said the sample appeared to include names, home addresses, Social Security numbers, FBI assignments, and, in some cases, family members. The news organization checked portions against credit bureau information and previously breached data held by cybersecurity firm District 4 Labs. At least 10 records appeared to match, Reuters reported.
Reuters stressed that those checks did not establish that the information was taken from FBI systems.
404 Media, which first disclosed the hackers’ claim, said a sample of 5,000 purported personnel records it reviewed included names, addresses, phone numbers, and information concerning employees’ spouses.
ShinyHunters told the outlet, “We hacked the FBI. We hold data on all FBI employees and applicants.”
The attackers told Reuters the operation was retaliation for an FBI warning issued in May that described ShinyHunters’ methods and urged victims not to pay extortion demands.
The unresolved question is now whether the attackers merely assembled previously exposed personal information or gained access to FBI-controlled systems capable of linking identities, addresses, family information, Social Security numbers, and assignments.
Former FBI official Cynthia Kaiser told Reuters that stolen personnel data can retain value to criminals long after the original breach because it can be used to expose or pressure investigators.