The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the stolen data.
The theft captured personal details for every FBI employee and applicant. The list includes physical addresses, job roles, names of spouses, and medical records. Criminals operating in the same ecosystem as the hacking group, ShinyHunters, have previously used hacked phone data to track and harass the agents investigating them. When 404 Media first broke the story, the group released the personal data of an agent and their spouse who were said to be investigating the group.
While the risk of public damage is lower if ShinyHunters does not release the data, the theft itself still poses significant national security risks. The information provides granular insight into how the FBI operates.
“Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to,” a representative of ShinyHunters told 404 Media on Monday.
Last week, ShinyHunters provided 404 Media with a sample list of 5,000 FBI officials. This sample often included details on their spouses too. 404 Media verified this data by cross-referencing it with open source records available in the research tool OSINT Industries, and previously compromised data in Darkside, a tool made by cybersecurity company District 4.
At the time of the breach, the ShinyHunters representative said the exfiltrated data totalled between two and three terabytes. In a since-deleted announcement posted to their leak site, ShinyHunters wrote, “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”
ShinyHunters said on its site that it was “allowing you [the FBI] a time of 1 week to correct” or remove a previously published FBI report. In that report, the FBI said that ShinyHunters exaggerates its claims of access to sensitive data to elicit payment, and that the group sends threatening text messages and phone calls to victims and their families. Typically, ShinyHunters extorts victims by threatening to publish their data online if the target organisation does not pay up.
In the new statement on Monday, ShinyHunters told 404 Media “Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated. However, the public and media has misinterpreted this for an extortion and have assumed that if the victim entity does not comply within 1 week which we all know including ourselves that they would never comply, we would publish all the data.”
“This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts,” the statement added.
The FBI told 404 Media in a statement “The FBI is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple Bureau wide communications within 24 hours of public reporting. The FBI treats the security of its information and the safety of its workforce as top priorities, and our investigation is ongoing.”
The scope of the theft
Last week, Reuters reported some of the personnel in the 5,000 officials sample include those assigned to investigate China or Russia, presenting a serious national security threat. 404 Media found the hack also exposed the names and personal data of some members of the FBI’s secretive hacking team, called the Remote Operations Unit. The BBC reported the breach included Special Agents’ blood and urine test results. Reuters reported the hack also impacted mental health evaluations.
“We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our business’s operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations,” ShinyHunters told 404 Media on Monday.
The data of 5,000 FBI employees has spread, though. On its site ShinyHunters said it only provided the data to “a select group of prominent U.S. media organizations solely to verify our claims.” Soon after, the cybersecurity researcher and YouTuber John Hammond said they obtained a copy too. Hammond declined to tell 404 Media how he obtained the data when asked last week.
This information, as well as the alleged two to three terabytes of overall stolen data, is likely of high interest to foreign intelligence agencies, potentially making anyone who has obtained it a target. In a separate case that shows the potential danger of stolen data, a man linked to the hack of all AT&T customer metadata records communicated with an email address he believed belonged to a foreign country’s military intelligence service, and attempted to sell the data to that country, 404 Media previously reported. Asked last week if ShinyHunters planned on selling the hacked FBI data to a foreign intelligence agency, the representative said, “No definitely not.”
On Monday, the New York Times reported the FBI sent a memo to staff saying it would offer virtual briefings and instructed employees to remain vigilant while at home and their place of work. “Bureau leadership remains committed to supporting the safety of you and your family,” the memo reportedly said.
On Monday, Krebs on Security reported authorities in the Netherlands had arrested a 23-year-old on suspicion of aiding ShinyHunters. The representative told 404 Media “the Dutch police are incompetent. That individual has no association with us. Frankly, we are laughing.”




