Hacker News Viewer

'We hacked the FBI:' Hackers say they have data on all FBI employees

by spenvo on 9/22/2026, 5:46:02 PM

<a href="https:&#x2F;&#x2F;archive.ph&#x2F;96YBP" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;96YBP</a>

https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/

Comments

by: jacobgold

At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.<p>China hacked 22.1 million records of US government employees:<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Management_data_breach" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;2015_Office_of_Personnel_Manag...</a>

9/22/2026, 8:53:15 PM


by: reactordev

There’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…

9/22/2026, 8:36:52 PM


by: corvad

Looks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.

9/22/2026, 8:40:59 PM


by: 1970-01-01

If this was 1992, we&#x27;d be retelling and celebrating the hack for decades.<p>1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.

9/22/2026, 9:31:18 PM


by: tencentshill

Well that&#x27;s a big one.<p>Perhaps firing expertise and hiring incompetents wasn&#x27;t a good idea.

9/22/2026, 7:09:22 PM


by: TutleCpt

404 Media is doing a much better job at breaking major stories than mainstream media. Nice.

9/22/2026, 9:25:12 PM


by: smalltorch

Thats a major attack on the US.<p>If your systems are compromised and need to coordinate, what do you even do if you can&#x27;t trust anything, assuming the attacker is still inside the network?

9/22/2026, 6:08:03 PM


by: whynotmaybe

&gt; data totalled between two and three terabytes.<p>That&#x27;s lot of data for a list of employees.

9/22/2026, 9:02:06 PM


by: steveBK123

Claiming they got all employee &amp; spouse data.<p>Wondering about pets..

9/22/2026, 8:53:37 PM


by: corvad

Hmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.

9/22/2026, 8:38:32 PM


by: S-E-P

Hasn&#x27;t that db been pwned previously?

9/22/2026, 9:11:01 PM


by: KronisLV

That feels like publicly announcing that you want to be in a lot of trouble.

9/22/2026, 8:45:33 PM


by: iAMkenough

In the same week the head of the FBI went on national TV to claim credit for increasing the bureau&#x27;s use of AI by 605%, whatever that&#x27;s supposed to mean.<p><a href="https:&#x2F;&#x2F;www.tomshardware.com&#x2F;tech-industry&#x2F;artificial-intelligence&#x2F;kash-patel-says-that-ai-use-at-the-fbi-has-increased-by-605-percent-since-he-became-director-claims-that-every-major-tech-player-is-embedded-in-the-agency" rel="nofollow">https:&#x2F;&#x2F;www.tomshardware.com&#x2F;tech-industry&#x2F;artificial-intell...</a>

9/22/2026, 7:57:32 PM


by: kelseyfrog

So they&#x27;re getting access to a year&#x27;s worth of free credit reporting for the inconvenience?

9/22/2026, 7:03:57 PM


by: dgellow

Im sorry given how bad of a situation that is, but it would be so ironic if they used Claude or codex for this

9/22/2026, 6:06:47 PM


by: Apocryphon

Remember how the original <i>Mission Impossible</i> movie (1996) was about the bad guys getting the NOC list? This feels somehow even worse than that.

9/22/2026, 9:04:27 PM


by: levocardia

So, what are the odds this was done with an open-weight LLM?

9/22/2026, 8:44:58 PM


by: Jamesbeam

I will tell you where this gets really embarrassing for the FBI.<p>Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.<p>In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.<p>Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.<p>All you need to know about Clop is that they got fucked by SH as well just a few days ago.<p>ShinyHunters defaced Clop&#x27;s Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.<p>Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.<p>In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?<p>If you guessed Oracle PeopleSoft, you were right.<p>Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.<p>But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.<p><a href="https:&#x2F;&#x2F;mesoclever.com&#x2F;2026&#x2F;06&#x2F;11&#x2F;oracle-wins-396m-hr-contract&#x2F;" rel="nofollow">https:&#x2F;&#x2F;mesoclever.com&#x2F;2026&#x2F;06&#x2F;11&#x2F;oracle-wins-396m-hr-contra...</a><p>They even mentioned in the above June article:<p>&gt; Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.<p>So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.<p>Fookin Big Idiots.

9/22/2026, 9:21:48 PM


by: TZubiri

Is their name a reference to pokemon? Or to the meme that the FBI&#x2F;CIA glows through the screen?

9/22/2026, 8:09:26 PM


by: Ancapistani

Meh - I&#x27;ll believe it when I see the actual data.<p>Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.

9/22/2026, 8:57:35 PM


by: jgalt212

If I use Claude or OpenAI swarm to commit crimes, and the vendor knows I&#x27;m up to no good, what&#x27;s their liability? Do they plan to invoke the phone company defense?

9/22/2026, 8:47:52 PM


by: bearjaws

America is at war and losing comically.<p>Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.<p>The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming &quot;AI&quot;.<p>Almost like its run by a bunch of 80 year olds...

9/22/2026, 8:57:42 PM


by:

9/22/2026, 8:27:42 PM


by: Simulacra

Again?

9/22/2026, 8:23:24 PM


by: applfanboysbgon

Wow, that is bold. I wonder if they&#x27;ll get away with it because incompetent leadership has decimated the US&#x27;s capabilities? This certainly doesn&#x27;t bode well for the US&#x27;s odds against its nation-state rivals.

9/22/2026, 8:03:13 PM


by: giancarlostoro

...and this is how the FBI makes you a higher priority target, and you wind up caught.

9/22/2026, 8:21:15 PM


by: phendrenad2

Imagine the FBI&#x27;s relief when the hackers only got a list of their employees, not the UFO files.

9/22/2026, 8:51:24 PM


by: htrp

TLDR. A Peoplesoft (Oracle HR) instance was compromised which allowed movement into GovCloud (AWS)

9/22/2026, 7:34:26 PM