The J. Edgar Hoover FBI Building in Washington, July 18, 2025. A criminal hacking group known as ShinyHunters revealed last week that it had stolen a vast trove of sensitive personal data from the FBI, potentially one of the worst breaches of sensitive government information in the internet age. (Tierney L. Cross/The New York Times)
Share
|
Getting your Trinity Audio player ready...
|
WASHINGTON — A criminal hacking group known as ShinyHunters revealed last week that it had stolen a vast trove of sensitive personal data from the FBI, potentially one of the worst breaches of sensitive government information in the internet age.
The breach may have compromised information about tens of thousands of former and current FBI employees, including data such as home addresses, Social Security numbers and even secretive job assignments.
In a series of cryptic statements, ShinyHunters demanded that the FBI retract a public advisory the bureau had issued this spring warning of the group’s cyberattacks. In an email to The New York Times on Friday, ShinyHunters said that the bureau had until the end of Tuesday to fulfill its request. But on Monday, it appeared to walk back that demand, saying it would not publish the data, as it typically does with the information it steals.
In a video posted online Tuesday, the FBI warned the group that it would aggressively pursue its members as it promoted the recent arrest of a suspect it said was affiliated with the group.
Here’s what to know:
What Is ShinyHunters?
ShinyHunters is a loose collective of relatively young hackers who have been responsible for dozens of data breaches since about 2019. The group has typically engaged in what are known as ransom-or-release attacks, demanding millions of dollars in payments in exchange for not publishing the data its members steal.
The name of the group appears to refer to the Pokémon video games, specifically players who devote significant time and energy toward hunting for rarer shiny Pokémon.
Recent arrests offer a glimpse of ShinyHunters’ membership, suggesting that the group operates across the globe.
Sebastien Raoult, a French citizen who was then 22 years old, was convicted in 2024 of participating in some ShinyHunters attacks after being arrested in Morocco. He was extradited to the United States for trial and sentenced to three years in prison.
Others who were suspected of being part of ShinyHunters were arrested last year in France. All were young men — born between 2001 and 2004 — and were described by officials as highly isolated.
On Monday, security journalist Brian Krebs reported that authorities in the Netherlands had arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions tied to ShinyHunters just days before the FBI breach. ShinyHunters denied Monday that the suspect was associated with the group.
What Has the Group Been up To?
ShinyHunters has targeted hundreds of corporations, government agencies and other entities for their ransom attacks.
Cybersecurity authorities say the group often targets software and cloud service providers. Once infiltrated, those providers can allow hackers to gain access to many targets simultaneously. Several high-profile Google and Salesforce customers, for example, were breached through several waves of attacks over the past year. Those targets included luxury-goods company LVMH — the owner of Dior, Louis Vuitton and Tiffany — and Adidas.
In one of its first major attacks, the group stole the sensitive data of millions of AT&T customers from the company in 2021 and sold the trove online. The telecommunications giant initially denied that the data was authentic, but the company confirmed in a legal filing in 2024 that the hackers acquired sensitive customer records, including account numbers, passcodes and Social Security numbers. AT&T was hit with another cyberattack targeting a cloud service provider, Snowflake, in 2024. The breach exposed phone records from “nearly all” of its customers, the company said.
Among the group’s more high-profile targets this year was Rockstar Games, the studio behind the highly anticipated video game Grand Theft Auto VI, in which it stole and shared the company’s financial data. That data revealed the studio’s profit margins, including billions of dollars in revenue from players buying in-game cash.
ShinyHunters has claimed to have breached a variety of targets: Grubhub; the European Commission; airline Qantas; insurance company Allianz Life; Kering, the luxury goods company that owns Balenciaga, Gucci and Alexander McQueen; Harvard University, Princeton University and the University of Pennsylvania; Pornhub; and Telus, a Canadian telecom company.
The group’s attacks have significantly ramped up over the past year, officials and experts say.
In May, it said it had compromised an online learning system called Canvas that is used by thousands of schools and universities around the world, an attack that prompted the FBI’s advisory in the spring. The group also said it was behind attacks against Ticketmaster in 2024, which the hackers said had compromised the information of more than 500 million customers.
What Is Happening With the FBI Breach?
Last week, ShinyHunters said it had stolen records from an online jobs portal for the FBI and demanded that the FBI “correct or simply REMOVE” the spring advisory.
Even as ShinyHunters has now said that it would not release the data, as it has for previous breaches, security researchers warned that even if the group did not publish the data, it could still sell it to other criminals or foreign governments.
It is also unclear just how much sensitive information the hackers stole. The group claimed to have stolen records on everyone who has applied for a job at the FBI, and told the Times that the people with compromised information numbered in the tens of thousands. An internal memo sent to the FBI workforce by bureau leaders said it was investigating the breach under the presumption that all employees had data stolen.
A sample of records shared with the Times by the hackers included particularly sensitive workplace records, including extraordinary job assignments like counterintelligence, narcotics and various desks focused on Russian, Chinese and Iranian national security threats.
In addition to personal records like names, addresses, phone numbers and Social Security numbers, ShinyHunters also said that it had stolen medical data about employees, including psychiatric records and documents related to blood and urine tests. It also said that it had additional background check files on employees.
—
This article originally appeared in The New York Times.
By Chris Cameron/Tierney L. Cross
c. 2026 The New York Times Company
RELATED TOPICS:
Categories
Qatari Mediators Press Peace Deal Between US and Iran
Number of Guard Troops in Washington Drops Below 3,000





