Reuters has verified parts of data allegedly stolen from the FBI, including records linking personnel to sensitive intelligence, cyber and counterespionage assignments.

Allegedly Stolen FBI Data Reveals Sensitive Intelligence Assignments, Reuters Finds

The420 Web Correspondent
7 Min Read

Data allegedly stolen from the FBI by the ShinyHunters cybercrime group contains detailed information about employees working in sensitive intelligence and counterintelligence roles, according to a Reuters review of part of the dataset.

The development significantly raises the stakes of the suspected breach. The FBI had previously confirmed only that it was investigating claims of unauthorised activity affecting FBIJobs.gov. Reuters has now independently verified details relating to more than 22 people named in a 5,000-line spreadsheet supplied by the hackers.

The bureau has not confirmed that the full dataset is authentic, nor has it verified ShinyHunters’ claim that between 2TB and 3TB of information was stolen.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Spreadsheet includes roles linked to China, Russia and cyber operations

The spreadsheet reviewed by Reuters contains names, home addresses, telephone numbers, dates of birth, Social Security numbers and emergency-contact information that the hackers claim belongs to thousands of FBI personnel.

More seriously, the material includes information about some employees’ assignments to specific field offices and specialised units. Reuters found references to personnel involved in work connected with Chinese espionage, Russian intelligence, cyber operations, surveillance, drug cartels and human intelligence.

Reuters said it could not authenticate the entire spreadsheet.

However, it independently verified information relating to more than 22 individuals by comparing the records with credit data and information previously collected by dark-web intelligence company District 4 Labs.

That partial verification does not prove that every record is genuine, but it gives the alleged leak substantially more credibility than the group’s initial claims alone.

Why intelligence assignments make this breach more serious

A normal employee-data breach can expose people to identity theft and phishing.

This case carries an additional risk because the leaked information allegedly connects individual FBI personnel with specialised national-security and intelligence work.

If accurate, such information could potentially help criminal organisations or foreign intelligence services identify personnel associated with investigations or sensitive operational areas.

Home addresses and family-related information may also create personal-security risks.

404 Media, which first examined a sample of around 5,000 alleged FBI records, reported that the material included names, addresses, phone numbers and information relating to employees’ spouses. The publication warned that such information could be useful for intimidation or surveillance if it reached hostile actors.

Neither Reuters nor 404 Media has published the sensitive personal details.

FBI says cause remains undetermined

The FBI has now expanded its public response to the incident.

It said it was aware of a cybercriminal group claiming a compromise of the FBIJobs.gov portal and an alleged impact on FBI employee personally identifiable information.

The bureau said the cause remained undetermined and that it was actively investigating the incident.

That statement is still narrower than ShinyHunters’ claims.

The FBI has not publicly confirmed that internal systems beyond the recruitment portal were compromised, that 2TB to 3TB of data was stolen, or that the hackers gained access to intelligence-related infrastructure.

The FBIJobs.gov website remained unavailable for at least part of Wednesday as the investigation continued.

PeopleSoft zero-day claim remains unverified

ShinyHunters has separately claimed that it entered FBI systems by exploiting a previously unknown vulnerability in Oracle PeopleSoft.

The group told BleepingComputer that the alleged flaw allowed remote code execution and that it later moved into FBI-managed AWS GovCloud systems. It also claimed access to Human Resources, Criminal Justice, Medlink and other services.

None of those technical claims has been independently confirmed.

BleepingComputer said it could not verify the existence of the alleged zero-day, the claimed lateral movement or the amount of data reportedly stolen.

That distinction is important because ShinyHunters has a history of making aggressive breach claims, and law-enforcement agencies typically require forensic evidence before confirming how attackers entered a system.

Hackers say they are withholding wider release of data

ShinyHunters has claimed that it is currently trying to prevent the FBI personnel data from circulating more widely.

The group says the breach was retaliation for an FBI advisory issued in May that described ShinyHunters as a cybercriminal group involved in large-scale breaches and extortion. It has demanded that the bureau withdraw or amend that advisory.

The hackers’ statements are their own claims and have not been independently substantiated.

The FBI has given no indication that it intends to comply with the demand.

Breach could become a counterintelligence problem

The latest Reuters findings shift the incident from a recruitment-portal security issue toward a possible counterintelligence concern.

If the data is genuine and includes accurate descriptions of employees’ operational assignments, investigators will need to determine not only whose personal data was exposed but whether any active investigations or intelligence functions have been placed at risk.

The broader scale also remains unresolved.

ShinyHunters says the 5,000-record spreadsheet is only a fraction of its claimed 2TB to 3TB collection. Reuters has verified only a small portion of that material, and the FBI has not confirmed the attackers’ claimed haul.

For now, the most firmly established facts are that the FBI is investigating unauthorised activity affecting FBIJobs.gov and that Reuters has independently matched parts of the alleged stolen dataset to real people.

What this means for you: A breach involving employee names and addresses is serious on its own, but exposure of specific intelligence assignments can create wider security risks. The full scale of the incident remains unconfirmed, so claims about the 2–3TB haul and the alleged PeopleSoft zero-day should still be treated as unverified.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected