'We hacked the FBI:' Hackers say they have data on all FBI employees
- jacobgold - 6973 sekunder sedanAt this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.
China hacked 22.1 million records of US government employees:
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
- reactordev - 7956 sekunder sedanThere’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…
- tencentshill - 13206 sekunder sedanWell that's a big one.
Perhaps firing expertise and hiring incompetents wasn't a good idea.
- TutleCpt - 5056 sekunder sedan404 Media is doing a much better job at breaking major stories than mainstream media. Nice.
- corvad - 7709 sekunder sedanLooks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.
- 1970-01-01 - 4690 sekunder sedanIf this was 1992, we'd be retelling and celebrating the hack for decades.
1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.
- wowczarek - 1491 sekunder sedanRandom member of the public: THEY HACKED THE FBI111!11!!
Anyone with minimal understanding of technology: Oh, PeopleSoft.
- whynotmaybe - 6442 sekunder sedan> data totalled between two and three terabytes.
That's lot of data for a list of employees.
- smalltorch - 16885 sekunder sedanThats a major attack on the US.
If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
- mamcx - 2013 sekunder sedanRemember when in movies getting access to this was THE THREAT?
Fun times.
- Buttons840 - 3579 sekunder sedanWhite-hat and grey-hat hackers need to be able to perform penetration testing without permission. Nobody is able to build secure systems. The best we can hope for is that the good guys find the vulnerabilities first and report them responsibly.
This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?
Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.
- corvad - 7856 sekunder sedanHmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.
- steveBK123 - 6951 sekunder sedanClaiming they got all employee & spouse data.
Wondering about pets..
- dgellow - 16961 sekunder sedanIm sorry given how bad of a situation that is, but it would be so ironic if they used Claude or codex for this
- KronisLV - 7435 sekunder sedanThat feels like publicly announcing that you want to be in a lot of trouble.
- S-E-P - 5907 sekunder sedanHasn't that db been pwned previously?
- Apocryphon - 6301 sekunder sedanRemember how the original Mission Impossible movie (1996) was about the bad guys getting the NOC list? This feels somehow even worse than that.
- bearjaws - 6706 sekunder sedanAmerica is at war and losing comically.
Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.
The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".
Almost like its run by a bunch of 80 year olds...
- malloci - 1850 sekunder sedan"they hacked the Gibson man"
- levocardia - 7470 sekunder sedanSo, what are the odds this was done with an open-weight LLM?
- jgalt212 - 7296 sekunder sedanIf I use Claude or OpenAI swarm to commit crimes, and the vendor knows I'm up to no good, what's their liability? Do they plan to invoke the phone company defense?
- Ancapistani - 6713 sekunder sedanMeh - I'll believe it when I see the actual data.
Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.
- - 8506 sekunder sedan
- Simulacra - 8764 sekunder sedanAgain?
- Jamesbeam - 5260 sekunder sedanI will tell you where this gets really embarrassing for the FBI.
Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.
In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.
Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.
All you need to know about Clop is that they got fucked by SH as well just a few days ago.
ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.
Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.
In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?
If you guessed Oracle PeopleSoft, you were right.
Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.
But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.
https://mesoclever.com/2026/06/11/oracle-wins-396m-hr-contra...
They even mentioned in the above June article:
> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.
So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.
Fookin Big Idiots.
- applfanboysbgon - 9975 sekunder sedanWow, that is bold. I wonder if they'll get away with it because incompetent leadership has decimated the US's capabilities? This certainly doesn't bode well for the US's odds against its nation-state rivals.
- iAMkenough - 10316 sekunder sedanIn the same week the head of the FBI went on national TV to claim credit for increasing the bureau's use of AI by 605%, whatever that's supposed to mean.
https://www.tomshardware.com/tech-industry/artificial-intell...
- kelseyfrog - 13531 sekunder sedanSo they're getting access to a year's worth of free credit reporting for the inconvenience?
- giancarlostoro - 8893 sekunder sedan...and this is how the FBI makes you a higher priority target, and you wind up caught.
- TZubiri - 9602 sekunder sedanIs their name a reference to pokemon? Or to the meme that the FBI/CIA glows through the screen?
- phendrenad2 - 7084 sekunder sedanImagine the FBI's relief when the hackers only got a list of their employees, not the UFO files.
- usumgallu - 919 sekunder sedan[dead]
- htrp - 11702 sekunder sedanTLDR. A Peoplesoft (Oracle HR) instance was compromised which allowed movement into GovCloud (AWS)
Nördnytt! 🤓