FBI Investigates Alleged Cyberattack on Recruitment Portal After ShinyHunters Claims Data Theft

RksNews
RksNews 3 Min Read
3 Min Read

The Federal Bureau of Investigation (FBI) has launched an investigation into a suspected breach of its online recruitment portal after the cybercrime group ShinyHunters claimed it had stolen personal information belonging to FBI agents and job applicants.

“The FBI is aware of claims regarding unauthorized activity affecting FBIJobs.gov and is currently investigating,” the Bureau’s National Press Office said.

ShinyHunters claimed it had obtained what it described as “highly sensitive” information belonging to a large number of FBI personnel, as well as people who had applied for positions at the agency.

The group provided 404 Media with a sample of the alleged stolen data that reportedly contained information on around 5,000 people identified as suspected FBI agents. The sample allegedly included names, residential addresses, telephone numbers and information concerning agents’ spouses.

Two people familiar with the situation told 404 Media that investigators believe the claims are credible. They warned that the disclosure of personal information belonging to FBI employees could create security risks for agents and their families, while potentially providing valuable information to foreign intelligence services and criminal organizations.

FBIJobs.gov, which is used for FBI employment and recruitment services, appeared to have been affected by the incident. The FBI’s own documentation confirms that the system supports public-facing recruitment, hiring and job-application processes and handles personally identifiable information.

The FBI has not publicly confirmed the extent of the alleged breach, the systems or databases that may have been compromised, the amount of information allegedly stolen, or the period covered by the data.

According to a person briefed on the investigation, the intrusion may have exploited a vulnerability in Oracle PeopleSoft, a platform widely used for human-resources management. A representative of ShinyHunters claimed the group had exploited a previously unknown “zero-day” vulnerability, although investigators have not confirmed that allegation.

The incident comes as ShinyHunters remains a known cybercrime threat. The FBI has previously linked the group to major thefts of personal information and described it as a notorious international hacking operation.

The FBI is continuing to investigate the incident, while the full scope and origin of the alleged breach remain unclear.