Security1 publisher2 min readPublished
ShinyHunters vows to withhold FBI employee files it has already used against one agent
ShinyHunters told 404 Media it will never publish its FBI haul, which it claims is 2 to 3 terabytes covering all employees and applicants. Keeping the files unpublished limits public exposure, but agents' home addresses, spouses' names and medical records are still with the group.
The Watch · Security desk

What happened
- When 404 Media first reported the breach, ShinyHunters sent out the personal data of an FBI agent and the agent's spouse, saying the agent was investigating the group.
- Last week the group handed 404 Media a sample of 5,000 FBI officials, many with spouse details, and 404 checked it against OSINT Industries and District 4's Darkside.
- Reuters reported that some officials in that sample are assigned to investigate China or Russia.
- A since-deleted leak-site post gave the FBI one week to correct or remove an earlier Bureau report about the group.
- The FBI said it is investigating the FBIJobs.gov incident and sent multiple Bureau-wide communications within 24 hours of public reporting.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Agents on China or Russia cases and Remote Operations Unit members remain identifiable to the group, and to anyone it shares the copy with, whether or not a leak site ever carries it.
- constraint Withholding the files closes one channel. Direct phone contact and tracking, already used by same-ecosystem criminals on investigating agents, needs only the addresses and spouse names already taken.
- contradiction The group says it is not after money, while the FBI report it demanded corrected says it overstates its access to get paid and threatens families, so the pledge rests on credibility the Bureau already disputes.
The promise covers publication and nothing else. 404 Media's assessment is that the damage will be smaller if the files stay offline. It also found that the theft still carries much of the same national security risk, because the data shows in detail how the FBI operates [6].
Targeting an agent does not require a leak site. The agent-and-spouse file went out while the trove was unpublished [4]. As 404 Media describes the breach, it includes physical addresses, job roles and spouses' names [3]. Criminals in the same ecosystem as ShinyHunters have previously used hacked phone data to track and harass the FBI agents investigating them [5].
Whoever holds the files can match staff to their assignments and their medical histories without posting anything. 404 Media found names and personal data for some members of the Remote Operations Unit, the Bureau's secretive hacking team [18]. The BBC reported that the haul included Special Agents' blood and urine test results [19]. Reuters reported that mental health evaluations were also affected [20].
Only the 5,000-name sample has been independently checked [7]. Everything beyond it rests on the group's own statements, including a since-deleted post that said, "We have a lot more than we claim here" [9]. The FBI's statement to 404 Media did not address scope. "The FBI treats the security of its information and the safety of its workforce as top priorities, and our investigation is ongoing," the Bureau said [16].
ShinyHunters usually extorts victims by threatening to publish their data unless they pay [12]. On Monday its representative said the public and media had misread the one-week deadline as a threat to publish everything if the FBI did not comply [21]. The representative insisted "this is NOT extortion, this is NOT ransom, this is NOT financially motivated" [13]. "This was all a marketing campaign to protect our business and actively combat disinformation," the representative told 404 Media [14].
What to watch
- Whether any FBI employee or applicant records surface on a leak site or with other criminals despite the pledge.
- An FBI statement on scope: whether the breach reaches all employees and applicants, as the group claims, or something closer to the verified 5,000-name sample.
- Reports of agents or spouses being contacted, tracked or threatened using details from the breach.