FBI Declares Cyber Security Incident After ShinyHunters Breach Exposes Employee Medical Records and Counterintelligence Work Details
The FBI declared a "cyber security incident" in an internal notice, MS Now reporter Ken Dilanian reported, telling staff that names, addresses, job titles and Social Security numbers were exposed after hackers breached its FBIJobs.gov applicant portal through an
ShinyHunters will likely publish stolen FBI employee data on a leak site or public channel by October 31. The demand for a corrected advisory works as leverage, and the group's claim that it never planned to publish carries little weight given its record of leaking other victims' data. The FBI's shift from silence to confirming stolen Social Security numbers, plus its assumption that all employees are exposed, settles that the data is real. Files reportedly covering China and Russia unit staff raise the counterintelligence stakes. The Dutch arrest of a suspected leader, with more data found on his laptop, may instead have disrupted the group and pushed remaining members to hold the data as a bargaining chip. Confidence is high because CNN, Reuters and TechCrunch independently agree on the breach vector, data types and demands. If publication occurs, the FBI must relocate or protect exposed agents and Congress will likely face a major-incident notification.