ShinyHunters says it won’t publish FBI data
ShinyHunters says it won’t publish FBI data
The group’s new statement — which called the incident a “marketing campaign" — follows reports that the stolen material includes medical records and details about employees working in sensitive intelligence roles.
The ShinyHunters cybercriminal group said Monday it does not intend to publish troves of sensitive FBI employee data it claims to have stolen, describing its confrontation with the bureau as a “marketing campaign” after demanding last week that the agency retract a public warning about its tactics.
“Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to,” the group said in an email to Nextgov/FCW.
The assertion leaves unresolved questions about the full scope of the intrusion and the risks to employees whose personal information may be already outside the bureau’s control. ShinyHunters previously circulated samples to news organizations, and its latest statement does not say it has deleted the records.
“This was all a marketing campaign to protect our business and actively combat disinformation,” the group said. It accused news outlets and the public of misinterpreting its earlier demand that the FBI correct or remove an advisory within a week. It said it had deliberately left unspecified what would happen if the bureau did not comply, and claimed it had never expected compliance.
“This was not a threat. It may have been worded like a threat but ultimately the public has drove [sic] this story out of context and made their own wild assumptions and speculations,” the statement said.
The group disputes a May 15 FBI advisory warning that ShinyHunters uses harassment, threats and sometimes exaggerated claims about stolen information to pressure victims into paying. It addressed its initial demand that the agency remove the advisory to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman.
Nextgov/FCW has asked the FBI for comment. The bureau said last week it was investigating claims involving its FBIJobs.gov recruiting portal and employee personal information. The agency also emailed personnel about the matter and urged them to take protective steps while investigators assessed the incident.
Reuters reported Friday that records circulated by the hackers included psychiatric and medical evaluations. The BBC also reported seeing blood and urine test results. ShinyHunters declined to comment on whether it possesses medical information in the stolen data.
Nextgov/FCW previously reported that the exposed information identifies employees working on intelligence matters involving Russia, China, Hezbollah and cartels, as well as personnel involved in human intelligence and electronic surveillance. The records also included employees in the bureau’s Remote Operations Unit, which develops specialized tools to target computers and networks.
The group had also provided Nextgov/FCW with an apparent sample containing some 5,000 entries, including names, home addresses, phone numbers and information about relatives. Multiple named individuals in the data were verified via online searches, though the entire dataset was not analyzed.
“ShinyHunters has made a name for itself by turning stolen data into leverage, and that’s what makes this incident so concerning,” said Adam Marrè, a former FBI special agent and chief information security officer at Arctic Wolf.
That stolen information could support phishing, fraud, social engineering and further attacks on employees, as well as counterintelligence efforts that could damage sensitive operations, he warned.
Separately, Dutch authorities arrested a suspected ShinyHunters associate earlier this month, cybersecurity journalist Brian Krebs reported Monday, citing sources familiar with the matter. The arrest preceded ShinyHunters’ claim of responsibility for the FBI intrusion.
The incident has drawn attention to flaws in Oracle’s PeopleSoft software.
ShinyHunters told 404 Media it used a previously unknown PeopleSoft flaw to gain access before reaching servers in Amazon Web Services’ GovCloud environment. That account has not been independently verified, though Google cybersecurity analysts said Friday that ShinyHunters had resumed widespread exploitation of a PeopleSoft vulnerability by modifying its attacks to evade web application firewall rules.
“The FBI’s focus now should be on understanding the full scope of the compromise, containing any downstream risk, and closing the gaps that allowed the intrusion to happen,” Marrè said.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.