FBI investigates apparent theft of its personnel data by hackers
Anadolu via Getty ImagesThe FBI says it is investigating a reported breach of its system after a cybercrime group claimed to have stolen sensitive information on thousands of bureau personnel.
The hackers, Shiny Hunters, say they now hold private data on all the bureau staff - around 38,000 people - including anyone who applied to join the investigative agency.
The group says it has every agent's name, role, badge number and personal details including home address, phone numbers and spouse information.
In a statement posted on X, the FBI said it was aware of the claim and the agency was "actively and aggressively investigating the matter".
The criminals claim to have breached the FBI's servers on Monday night and began contacting reporters on Tuesday sharing samples and screenshots of the stolen data.
The BBC has seen a small portion of the data which appears to be genuine.
According to Reuters, some of the data contains details about officials' job assignments, including sensitive work against Chinese spies, Russian intelligence and drug cartels.
ShinyHunters is an international collective of hackers, believed to have originally started in France. It has been behind a number of high-profile breaches including on Rockstar Games in April and a highly disruptive hack on education platform Canvas in May.
The group claims to have found a vulnerability in the Oracle cloud storage system used by the FBI to breach multiple systems including FBIJOBS, FBI BEAST, which does background checks on employees and applicants, FBI MedLink, which holds agent's medical records and FBI BICS, which holds investigation information.
In its message on darkness web, the group said it did not hack the FBI system for money.
Instead, the cybercriminals are asking the agency to retract an advisory that it issued about the gang, saying it was "offended" by its characterisation.
That FBI's public service announcement described ShinyHunters as "threat actors" who often "use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims".
"They target major companies across tech, finance, and retail, often stealing millions of customer records at once," the advisory said.
ShinyHunters said it would give the bureau one week to correct or remove what it says are false allegations or they would publish the full databases.
The FBI did not respond to multiple requests for comment from the BBC.
In its statement on X, the agency said it was trying to determine whether or not the hackers had breached its systems or a third party.
"We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk," the post said.
In a statement to the BBC, a cybersecurity expert said it was a "retaliation attack", which demonstrated that "no organisation is safe from the group".
"The group clearly wants to control the narrative around their activities, ensuring nothing is said that could dent their reputation," said William Wright of Closed Door Security.
