
FBI Tracks Hackers Who Stole Employees’ Sensitive Data: NPR
The J. Edgar Hoover FBI Building is seen on September 26, 2025 in Washington, DC
Samuel Corum/Getty Images
hide caption
toggle caption
Samuel Corum/Getty Images
In a video posted to social media, FBI Cyber Division Deputy Director Brett Leatherman vowed Tuesday to track down members of a cybercriminal group called ShinyHunters, the same group that last week claimed to have stolen tons of sensitive data from the FBI itself.
“You know how to find us, and we know how to find you,” Leatherman said in the video, encouraging the prolific group of loosely connected data extortionists to come forward and share information or face consequences. “I suggest you contact us first while the choice is still yours.”
The FBI says it is “aggressively” investigating the breach and how the hackers obtained sensitive FBI employment information, including whether the hackers broke into third-party software or the FBI’s own internal systems. In an emailed statement to NPR, an FBI spokesperson said the bureau was working “around the clock to investigate the cyber incident involving FBIJobs.gov and was in regular communication with anyone who may be affected.”

It is still unclear exactly how much information was stolen, although media and threat intelligence researchers have already verified the authenticity of some of the stolen documents. Meanwhile, a defacement message was posted on the FBI employment website late last week in which ShinyHunters took credit for the attack, and the site was temporarily shut down.
Current and former FBI employees familiar with the matter, who spoke to NPR on condition of anonymity because they feared retaliation for speaking out about an ongoing investigation, said many employees first learned about the breach through the media. They suggested that there could be up to several terabytes of text files in the data slice, including FBI applications, promotion details, sensitive job posting information, family details, medical data and much more. These same employees, particularly those who have retired, say there is growing frustration from FBI leadership, including FBI Director Kash Patel, over the lack of communication about the breach, exactly who was affected and how the FBI plans to protect its current and former employees. Some retired employees who worked undercover may need protective services like relocation assistance or even a name change if their data is publicly exposed.
The FBI told NPR that it sent several “bureau-wide communications within 24 hours of the breach being publicly reported” and that “the FBI considers the security of its own information and that of its personnel to be top priorities.”
A former senior FBI official told NPR that the breach could be comparable to the 2015 compromise of tens of millions of sensitive government employee records from the Office of Personnel Management. The U.S. government attributed the breach to the Chinese government and described it as a large-scale espionage operation aimed at identifying potential targets for intelligence collection.
However, unlike the OPM violation, there is greater concern in this case that the stolen documents will fall into the wrong hands or be used as weapons, either by ShinyHunters or by any number of criminal, terrorist, or domestic organizations seeking to steal the stolen files. ShinyHunters said it never intended to release the files, although it gave the FBI a September 30 deadline to amend previously issued press releases about the group that it said were inaccurate, but that does not necessarily prevent further theft or exploitation of the data.
The bureau and its former employees are “bracing for impact” and assuming the stolen documents could be irreparably compromised, according to the former top FBI official.

But experts say members of the ShinyHunters, which many threat intelligence researchers have previously identified as a collective of young hackers around the world, should also prepare for the FBI’s response.
Cynthia Kaiser, a former deputy director of the FBI’s cyber division who now leads ransomware research at cybersecurity firm Halcyon, described the hackers as “reckless” for targeting the FBI, especially since the FBI has a clear policy of not paying ransoms or negotiating with criminal actors. “When a bad actor directly targets the FBI, they should expect the FBI to mobilize additional resources to quickly bring them to justice,” she wrote in a social media post.
Although the FBI has promised to seek information to make arrests against the ShinyHunters hackers following this breach, it is unclear how imminent those actions might be.
The FBI video posted to social media also featured the recently announced arrest of a suspected ShinyHunters member in Amsterdam by the Dutch National Police, an operation the FBI thanked its Dutch partners for leading. However, that arrest preceded ShinyHunters’ theft of FBI personnel data, according to the former senior FBI official familiar with the matter. It is unclear whether this arrest prompted the FBI data breach and whether there were concerns about possible retaliation following this arrest.
Although the FBI has not shared any technical details about how the hackers broke into its systems, Google’s Mandiant has released new research revealing that ShinyHunters is currently targeting a vulnerability in a human resources software tool called PeopleSoft, which is owned by tech giant Oracle. PeopleSoft is a tool used by the FBI, among other major customers in IT, business, government, academia and beyond.
Google initially disclosed information about the vulnerability and its exploitation in June and revealed that while the company had released a patch, some customers had instead implemented protections like a firewall to try to prevent bad actors from exploiting it. Ultimately, ShinyHunters was able to easily bypass these controls.
Gn headline