Wireva

FBI Probes Breach of Jobs Portal as Hackers Claim Sensitive Personnel Data

The FBI is investigating a claimed compromise of its FBIJobs.gov portal by the cybercriminal group ShinyHunters, which says it stole 2 to 3 terabytes of data on current and former personnel and job applicants. The bureau has not confirmed where the breach occurred, and a suspect was arrested in the Netherlands.

The FBI is investigating a claimed cyberattack on its FBIJobs.gov portal after the cybercriminal group ShinyHunters said it stole highly sensitive information belonging to current and former bureau personnel and people who applied for jobs there. The bureau acknowledged the group's claims and said it was «actively and aggressively investigating» the incident, while warning that investigators had not yet determined whether the breach involved an FBI system or a third-party provider that supports the jobs portal.

That unresolved question matters. The FBI said the point of breach remained undetermined and that it was working closely with third-party providers to reduce potential risk. The bureau did not verify ShinyHunters' full account of what the group says it took. The FBIJobs.gov site and the Special Agent Applicant Portal were both unavailable as the incident unfolded, according to a notice posted Sept. 22. The applicant portal supports people who have moved through portions of the special-agent hiring process, which makes the type of information potentially involved especially sensitive.

ShinyHunters says it stole between 2 and 3 terabytes of information connected to FBI personnel and job applicants, and has also claimed that Justice Department worker data was obtained. The group provided journalists with a spreadsheet containing about 5,000 alleged FBI personnel records. Reuters reported that the spreadsheet included names, home addresses, phone numbers, dates of birth, Social Security numbers and emergency contact information, along with field office assignments and, in some cases, details tied to sensitive intelligence or counterespionage work.

Reuters said it could not authenticate the entire spreadsheet, but reporters independently verified details belonging to more than 22 people by comparing the information with credit records and earlier leaked data. The outlet also matched career information or job titles for eight people against court filings, news reports, public profiles and online posts. Those matches do not establish where every record came from, since real information can appear in several databases or previous breaches, but they add credibility to at least portions of the sample.

404 Media separately reported that the 5,000-person sample contained names, home addresses, phone numbers and information involving FBI employees' spouses. The outlet also reported that the data appeared to expose members of the FBI's Remote Operations Unit, described as a secretive team involved in developing and using hacking tools to gain access to target devices.

The reported job information raises risks beyond ordinary privacy concerns. Reuters found records identifying people connected to China-related investigations, Russian intelligence work, human intelligence operations and electronic surveillance. Other entries referenced covert access, clandestine technical operations and telecommunications interception. Reuters said it could not verify that every assignment was authentic or up to date.

The combination of personal and professional details could be dangerous in the wrong hands. A name may lead to a home address, an emergency contact could identify a spouse or child, and job information might reveal the kind of investigations someone works on. For an FBI employee in a sensitive position, that creates risks far beyond financial fraud.

The FBI has struck back since acknowledging the claims. The bureau announced the arrest of an alleged ShinyHunters leader in the Netherlands after a joint operation with Dutch authorities. Dutch police said a 24-year-old Amsterdam man was arrested Sept. 15. The FBI has not said whether employee or applicant data was accessed, and it has not confirmed whether affected individuals are being notified or offered identity protection.

Same event, other desks

Story file →