--° Loading... Locating...
FBI headquarters in Washington

Hackers Say They Have the Home Addresses of Almost Every FBI Agent. The Bureau Is Investigating.

ShinyHunters says it pulled records on almost all FBI agents and applicants from FBIjobs.gov, and handed reporters a 5,000-record sample. The FBI confirms it is investigating unauthorized activity on the site.

Center

Key Points

  • The hacking group ShinyHunters claimed Tuesday, September 22, that it breached the FBI's online jobs portal, FBIjobs.gov.
  • The group says it stole data on 'almost all' FBI agents as well as applicants for bureau jobs.
  • It gave 404 Media a sample of roughly 5,000 records reportedly containing names, agent status, emails, phone numbers and home addresses.
  • Some records reportedly include spouse information, including Social Security numbers.
  • The FBI confirmed it is investigating unauthorized activity affecting FBIjobs.gov.
  • Investigators are examining whether a vulnerability in Oracle PeopleSoft, a widely used HR application, was exploited.
  • ShinyHunters says its motive was to force the FBI to correct or remove a public service announcement about the group, denying involvement in sextortion schemes.
  • The FBI has not confirmed the size of the breach, the authenticity of the sample, or whether anyone has been notified.
Listen to our news podcast

A hacking crew says it walked out of an FBI website with the home addresses of federal agents. The bureau is not denying that something happened. It confirmed Tuesday that it is investigating unauthorized activity on FBIjobs.gov, its online hiring portal.

What the hackers say they took

The group calls itself ShinyHunters. It is not new and it is not small. The name is attached to a long run of corporate data thefts going back years.

The claim this time is that they hit the jobs portal and pulled records on, in their words, almost all FBI agents, plus people who applied to work there.

Advertisement article banner article banner

They handed 404 Media a sample of about 5,000 records to prove it. The fields reportedly include:

  • Names
  • Whether the person is an FBI agent
  • Work emails and phone numbers
  • Home addresses
  • In some records, a spouse’s information, including Social Security numbers

That last line is the one that matters. A leaked work email is a nuisance. A federal agent’s home address sitting next to a spouse’s Social Security number is a different kind of problem.

How they say they got in

Investigators are looking at Oracle PeopleSoft, according to reporting on the breach. PeopleSoft is boring back-office software that runs payroll and hiring at a huge number of large employers, government ones included.

If that is the door, this was not a movie hack of a classified network. It was an HR system with a known class of weakness, sitting on the public internet, attached to a .gov address.

The bureau has not confirmed the method. It has confirmed it is looking into unauthorized activity on the site.

The reason they gave

Here is the strange part. ShinyHunters says the point was not money.

The FBI had put out a public notice about the group. ShinyHunters wants that notice corrected or pulled down, and objects in particular to being tied to sextortion schemes.

So the stated motive is reputation management. They robbed the bureau to argue about how the bureau described them.

Why agents are the wrong people to expose

Most breach stories end with a year of free credit monitoring. This one does not work that way.

Undercover and counterterrorism work depends on the government controlling who knows an agent’s name and where they sleep. A list that ties a real name to a badge status to a street address is useful to exactly the people the FBI investigates. Cartels. Foreign intelligence services. Organized fraud rings.

It also lands while federal law enforcement is already a target of public anger. An ICE agent shot a DoorDash driver in Austin on Sunday, and enforcement agencies have drawn threats from more than one direction all year.

The wider pattern

Government systems keep getting hit through the least glamorous door available. A cyberattack on UK airports exposed 8.7 million customers in August through a third-party vendor. Google has now patched seven actively exploited Chrome zero-days this year.

The through line is not brilliant attackers. It is old software with too much data sitting behind it.

The BeezLoop Take

The FBI spent this year telling the country it is the sharp end of American security. Kash Patel handed out honorary badges, including one to Shaquille O’Neal, and treated criticism of the bureau as a personal insult. A group of criminals then walked into its hiring website and, by the bureau’s own admission, did something there that required an investigation.

None of that is a partisan point. It is a competence point. A jobs portal is not a vault. It is a public web form, and public web forms get probed around the clock by people with nothing but time. If the data behind it really included agents’ home addresses and spouses’ Social Security numbers, the question is not how the attackers got so clever. The question is why any of that was reachable from a recruiting page.

The hackers’ stated motive is worth reading plainly too. They say they did this to force the government to edit a press release about them. That is not a manifesto, it is a tantrum, and calling it anything more sophisticated does them a favor they have not earned.

What nobody has said yet is the number. The FBI has confirmed unauthorized activity. It has not said how many people are affected, whether the sample is real, or whether anyone has been told. Until it does, the only account of what was taken is the one given by the thieves.

The question

If a federal agent’s home address ends up on a criminal forum because a hiring website was not locked down, who answers for it? And does the public ever learn the number, or does this end the way most federal breaches end, with a short statement and no count?

Sources: TechCrunch · CNN · Axios · Nextgov/FCW · CBC News

How We Sourced This

Written by Kevin Nordi

Kevin Nordi is a freelance writer with five years of experience covering politics, sports, and the everyday moments that shape people's lives. He holds a Bachelor of Science in Multimedia…

More from this author →

BeezLoop News is an independent online news, discussion, opinion, and blog publication. Our articles combine reporting with editorial commentary and analysis. See our editorial standards for how we handle sourcing and corrections.

Leave a Reply

Your email address will not be published. Required fields are marked *

Start typing to search

🔔

Stay Updated!

Get instant notifications for breaking news and important stories. We'll keep you informed!

Don't miss a story

Get the day's clearest news explainers in your inbox.