© 2026 KRWG
Play Live Radio
Next Up:
0:00
0:00
0:00 0:00
Available On Air Stations

FBI investigating massive data breach of the bureau's job portal

A MARTÍNEZ, HOST:

The FBI says it's hunting for hackers who stole sensitive data about the agency's employees. Here's the FBI's assistant director for the cyber division, Brett Leatherman, in a video posted online Tuesday.

(SOUNDBITE OF ARCHIVED RECORDING)

BRETT LEATHERMAN: You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours.

MARTÍNEZ: NPR's cybersecurity correspondent Jenna McLaughlin is covering the breach. Jenna, the focus of this investigation - what is it?

JENNA MCLAUGHLIN, BYLINE: Yeah. So the FBI is zeroing in on a hacker group that goes by the name ShinyHunters. That group told the media they hacked the FBI last week. Now the FBI says they're investigating. What they appear to acknowledge was a cyber incident impacting the bureau's job portal. So in that clip, you heard Brett Leatherman make a pitch to these hackers. He says, come forward with information or risk the consequences. And he references a recent arrest of a member of this group in Amsterdam by Dutch authorities.

So I'm told by current and former FBI officials familiar with this matter who weren't authorized to speak on the record about an ongoing investigation that the bureau's already mobilized a lot of resources into this. But FBI employees, those retired and still inside, are reeling because the database accessed by these hackers had not only information on job applications, but promotions, too. That's got detailed lists of their sensitive job postings, medical and family data.

Most people don't actually know if their data was taken yet. And there's some frustration about the lack of clear communication or response plans from senior leadership, including FBI Director Kash Patel, though the FBI does tell me they sent multiple internal messages within 24 hours of this incident and they're working round the clock to protect their data and their employees. For what it's worth, I know about a couple of groups of former employees who are banding together as we speak to support each other as - if this information leaks online.

MARTÍNEZ: And has this group threatened to leak the information? And actually, more the bigger point, I guess, Jenna, is how did they manage to do this?

MCLAUGHLIN: So the group now says that they never had any intention of leaking the stolen data - that they simply wanted to pressure the FBI to say nice things about them, essentially, and get a marketing boost. The FBI has been tracking their activities for a while - since at least 2019. As for their capabilities, this group has been absolutely prolific in stealing sensitive data and extorting their victims for a payday. They've targeted big names like Jaguar Land Rover, Ticketmaster. The ShinyHunters name actually appears to be a reference to the game "Pokemon," for other '90s kids out there.

MARTÍNEZ: (Laughter).

MCLAUGHLIN: Now, typically, this group likes to use tactics like social engineering or taking advantage of misconfigured cloud data systems. But in this case, it appears they may have exploited a vulnerability in third-party software to get access to the FBI jobs portal.

MARTÍNEZ: If they targeted third-party software, does that mean that there could be other people maybe connected to that software who are vulnerable to maybe a similar kind of attack?

MCLAUGHLIN: Yeah. Exactly. Cybersecurity researchers from Google put out a new report revealing that ShinyHunters are taking advantage of a flaw in a human resource management software called PeopleSoft, which was acquired by tech giant Oracle back in 2005. So there was a previously undiscovered bug in that software back in June. The company put some protections in place, but not all organizations fully fixed it. And that gave hackers the opportunity to jump around those protections and exploit it.

Big-name organizations across business, academia, IT services and beyond - they've all been targeted in recent weeks. Now, A, we don't know if hackers are using AI to launch these attacks. But AI's growing ability to help hackers find and weaponize these vulnerabilities at scale and at near-lightning speed - it's a really big concern recently.

MARTÍNEZ: Yeah. That's NPR's Jenna McLaughlin. Thanks.

MCLAUGHLIN: Thank you. Transcript provided by NPR, Copyright NPR.

NPR transcripts are created on a rush deadline by an NPR contractor. This text may not be in its final form and may be updated or revised in the future. Accuracy and availability may vary. The authoritative record of NPR’s programming is the audio record.

Jenna McLaughlin is NPR's cybersecurity correspondent, focusing on the intersection of national security and technology.
A Martínez is one of the hosts of Morning Edition and Up First.