The FBI’s cyber chief, Brett Leatherman, publicly urged members of the hacking group ShinyHunters to contact the bureau after the group claimed responsibility for a cyberattack that compromised sensitive FBI employment data.
In a video posted to social media on Tuesday, Leatherman, Assistant Director of the FBI’s Cyber Division, warned the group that law enforcement agencies have the capability to locate and apprehend its members. ‘You know how to find us, and we know how to find you,’ Leatherman stated, adding, ‘I suggest you reach out first while the choice is still yours.’
The FBI confirmed it is ‘aggressively’ investigating the breach, which targeted FBIJobs.gov, a portal containing employment-related information. A spokesperson stated the bureau is working ‘around the clock’ to assess the scope of the incident and is in contact with potentially affected individuals. The FBI did not specify how the hackers gained access, nor the total volume of data stolen.
ShinyHunters Responds
The hacking group, known for data extortion operations, denied plans to release the stolen data in a statement to media outlets on Monday. The group described the breach as a ‘marketing campaign’, though it did not elaborate on its motivations or objectives.
Arrest of Alleged Member Highlights Risks
Leatherman referenced the recent arrest of a suspected ShinyHunters leader in the Netherlands, stating that such actions can force suspects to cooperate and provide intelligence to law enforcement. ‘Other groups believed anonymity or their friends would protect them, and they were wrong,’ he said. The FBI did not confirm whether the arrested individual was directly linked to the FBI breach.
Scope of Stolen Data Remains Unclear
Current and former FBI employees, speaking on condition of anonymity due to the ongoing investigation, told NPR that the stolen data may include several terabytes of text files, encompassing FBI job applications, promotion details, sensitive postings, family information, and medical data. The authenticity of some leaked materials has been verified by threat intelligence researchers.
The FBI’s jobs website was temporarily defaced with a message claiming responsibility for the attack, and the site was taken offline following the incident. The bureau has not disclosed whether third-party software or internal systems were compromised in the breach.