Full Breakdown
FBI Warns ShinyHunters After Massive Personnel Data Breach and Dutch Arrest
By Drooid · · How we work
The breach and FBI’s public warning
A hacking collective calling itself ShinyHunters announced it had stolen data from the FBI’s jobs portal, including names, addresses, phone numbers, Social Security numbers, emergency contacts, medical and psychiatric records, and intelligence-related information for FBI staffers. The message was framed as both a threat and an invitation to communicate with law-enforcement investigators.
Timeline of key events
- September 15 – Dutch police arrested a 24-year-old suspect in Amsterdam, identified as Pepijn van der Stap, Neo Security’s offensive-security lead.
- September 21 (scheduled) – ShinyHunters claimed to have breached the FBI’s servers and began sharing samples with journalists.
- September 29 – Brett Leatherman released a video urging the hackers to surrender; FBI Director Kash Patel thanked Dutch partners for the arrest in an X post.
Data exposed
- The BBC reported roughly 38,000 FBI employees and applicants were affected.
- The New York Times suggested the breach could include all current and former FBI personnel.
Official statements & responses
- Brett Leatherman (FBI Cyber Division) said the bureau knows how to locate the hackers.
- Dutch police confirmed the September 15 arrest and said seized devices contained “a large amount of information,” adding the suspect is also linked to a separate alleged murder-for-hire plot.
- ShinyHunters denied any intention to publish the data, calling the episode a “marketing campaign” and rejecting the FBI’s May advisory that labeled the group a threat-actor.
Conflicting reports & gaps
- Scope of exposure: Estimates range from ? 38,000 records to a claim that every FBI employee and applicant may be affected.
- Motivation: The FBI frames the breach as a serious security failure, while ShinyHunters says it was not financially motivated and aimed to force a retraction of a public advisory.
- Technical details: ShinyHunters alleges the intrusion exploited an unknown vulnerability in Oracle’s PeopleSoft system, a claim not independently verified.
Verbatim quotes
- “Other groups believed anonymity or their friends would protect them, and they were wrong.” — Brett Leatherman
- “We know how to find you.” — Brett Leatherman
Why it matters
The exposure of personally identifiable information for thousands of federal law-enforcement personnel raises the risk of targeted phishing, identity theft, and intimidation of agents and their families, highlighting challenges in securing third-party cloud platforms that host sensitive government data.
What’s next
The FBI says it will continue “aggressively pursuing” remaining ShinyHunters members and is analyzing seized devices for leads. Dutch authorities indicated further arrests are possible, and the separate murder-for-hire investigation remains open. Updated security guidance for federal employees is expected in the coming weeks.
