Skip to content

Invest1 publisher2 min readPublished

FBI memo tells every employee to treat their personal data as stolen after the FBIjobs.gov breach

FBI told staff in an internal memo to assume hacking group ShinyHunters stole data on every employee after a claimed 2 to 3 terabyte breach of FBIjobs.gov. Until the bureau confirms the scale, staff and the job applicants the hackers say are also in the files have reason to treat their home addresses as exposed.

The Investor · Invest desk

Photograph accompanying FBI memo tells every employee to treat their personal data as stolen after the FBIjobs.gov breach
Photo: pbs.org

What happened

  • ShinyHunters says it acted over a May 15 FBI advisory about its harassment tactics and gave the bureau one week to retract that warning.
  • The group says it got in through a previously unknown flaw in Oracle's PeopleSoft HR software, and the FBI has not confirmed the method.
  • On Sept. 29, as the week ran out, Cyber Division chief Brett Leatherman posted a video citing a Sept. 15 Dutch arrest of a man the group says has no link to it.
  • ShinyHunters now calls the ultimatum a marketing campaign and says it does not plan to publish the data.
  • The memo tells staff to expect virtual briefings and to watch for suspicious texts or calls from unknown numbers.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • exposure If the PeopleSoft account holds, every employer running the same HR software has the same hole, and no fix existed when the group used it.
  • cost The blanket premise hands the screening work to each employee and their family, who have to treat every unknown caller as a possible approach until the FBI can say who is actually in the files.
  • constraint The only price ShinyHunters named is withdrawal of the May 15 warning, so the FBI has no payment it could make without telling the public its own harassment finding was wrong.

ShinyHunters named a price with no dollar figure in it. The group wanted the FBI to withdraw, within a week, an advisory issued 130 days before FBIjobs.gov showed its seizure banner [6][4][1]. After bribed support agents leaked Coinbase customer data last year, the exchange faced a $20 million extortion demand [12]. A retraction has no resale value. I think its worth to this group is reputational: ShinyHunters denies the threats against victims' relatives and the swatting that the May 15 advisory described [5]. Leatherman's video told the hackers "we know how to find you" [8].

The memo, as Reuters reported it, tells every staffer to assume the data is already out, and I think that premise holds whatever the group now promises [1]. ShinyHunters surfaced in 2020 selling stolen databases on hacker forums, helped run one of the biggest, BreachForums, and last year claimed about 1.5 billion records from Salesforce customers [11]. Its business started with selling. A pledge not to publish does not cover a sale.

The memo covers staff. The claim that everyone who applied for an FBI job is in the files, with names, phone numbers and in some cases spouses' details, comes from the group, and the FBI says it is investigating and has not confirmed the scale [2][3]. The reporting does not describe any notice to applicants. If the files are released, Decrypt wrote, identity theft cases may surge and relatives of doxxed employees could be at risk [16]. In my view anyone who applied through FBIjobs.gov should treat those details as exposed until investigators say otherwise, and so should any organisation that uses them to confirm who someone is. That advice is too broad if the investigation finds applicants were never in the files, or that the haul is well short of 2 to 3 terabytes [3][2].

Crypto holders have already paid for addresses sitting in leaked files. As of April, France had recorded 135 crypto-related wrench attacks since 2023 and had charged 88 suspects [14]. Attackers who beat a couple outside their Nancy apartment reportedly got their details from a January leak at Waltio, a French crypto tax platform that exposed about 50,000 users [15].

What to watch

  • An Oracle advisory or patch for PeopleSoft would confirm or undercut the group's zero-day account and tell other employers whether their HR systems share the flaw.
  • FBIjobs.gov records turning up for sale on a forum would test the group's pledge not to publish.
  • Any FBI notice to people who applied through FBIjobs.gov would show whether the bureau extends its premise past its own staff.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories