logoalt Hacker News

'We hacked the FBI:' Hackers say they have data on all FBI employees

202 pointsby spenvotoday at 5:46 PM146 commentsview on HN

https://archive.ph/96YBP


Comments

jacobgoldtoday at 8:53 PM

At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

China hacked 22.1 million records of US government employees:

https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

show 8 replies
reactordevtoday at 8:36 PM

There’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…

show 5 replies
corvadtoday at 8:40 PM

Looks like it was an Oracle PeopleSoft 0-day so I imagine there are a lot more systems vulnerable.

show 1 reply
TutleCpttoday at 9:25 PM

404 Media is doing a much better job at breaking major stories than mainstream media. Nice.

show 2 replies
1970-01-01today at 9:31 PM

If this was 1992, we'd be retelling and celebrating the hack for decades.

1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.

tencentshilltoday at 7:09 PM

Well that's a big one.

Perhaps firing expertise and hiring incompetents wasn't a good idea.

show 7 replies
Buttons840today at 9:49 PM

White-hat and grey-hat hackers need to be able to perform penetration testing without permission. Nobody is able to build secure systems. The best we can hope for is that the good guys find the vulnerabilities first and report them responsibly.

This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?

Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.

show 1 reply
whynotmaybetoday at 9:02 PM

> data totalled between two and three terabytes.

That's lot of data for a list of employees.

show 1 reply
smalltorchtoday at 6:08 PM

Thats a major attack on the US.

If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?

show 3 replies
corvadtoday at 8:38 PM

Hmm ShinyHunters seems to be in the news quite a bit recently. Most high profile was the Canvas LMS hack last spring right during college finals. Wonder if there will be a ransom for this data as well.

show 2 replies
steveBK123today at 8:53 PM

Claiming they got all employee & spouse data.

Wondering about pets..

KronisLVtoday at 8:45 PM

That feels like publicly announcing that you want to be in a lot of trouble.

S-E-Ptoday at 9:11 PM

Hasn't that db been pwned previously?

show 1 reply
dgellowtoday at 6:06 PM

Im sorry given how bad of a situation that is, but it would be so ironic if they used Claude or codex for this

show 1 reply
iAMkenoughtoday at 7:57 PM

In the same week the head of the FBI went on national TV to claim credit for increasing the bureau's use of AI by 605%, whatever that's supposed to mean.

https://www.tomshardware.com/tech-industry/artificial-intell...

show 1 reply
Apocryphontoday at 9:04 PM

Remember how the original Mission Impossible movie (1996) was about the bad guys getting the NOC list? This feels somehow even worse than that.

bearjawstoday at 8:57 PM

America is at war and losing comically.

Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.

The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".

Almost like its run by a bunch of 80 year olds...

kelseyfrogtoday at 7:03 PM

So they're getting access to a year's worth of free credit reporting for the inconvenience?

TZubiritoday at 8:09 PM

Is their name a reference to pokemon? Or to the meme that the FBI/CIA glows through the screen?

show 3 replies
levocardiatoday at 8:44 PM

So, what are the odds this was done with an open-weight LLM?

show 1 reply
jgalt212today at 8:47 PM

If I use Claude or OpenAI swarm to commit crimes, and the vendor knows I'm up to no good, what's their liability? Do they plan to invoke the phone company defense?

Ancapistanitoday at 8:57 PM

Meh - I'll believe it when I see the actual data.

Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.

Jamesbeamtoday at 9:21 PM

I will tell you where this gets really embarrassing for the FBI.

Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.

In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.

Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.

All you need to know about Clop is that they got fucked by SH as well just a few days ago.

ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.

Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.

In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?

If you guessed Oracle PeopleSoft, you were right.

Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.

But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.

https://mesoclever.com/2026/06/11/oracle-wins-396m-hr-contra...

They even mentioned in the above June article:

> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.

So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.

Fookin Big Idiots.

Simulacratoday at 8:23 PM

Again?

applfanboysbgontoday at 8:03 PM

Wow, that is bold. I wonder if they'll get away with it because incompetent leadership has decimated the US's capabilities? This certainly doesn't bode well for the US's odds against its nation-state rivals.

giancarlostorotoday at 8:21 PM

...and this is how the FBI makes you a higher priority target, and you wind up caught.

show 1 reply
phendrenad2today at 8:51 PM

Imagine the FBI's relief when the hackers only got a list of their employees, not the UFO files.

show 1 reply
htrptoday at 7:34 PM

TLDR. A Peoplesoft (Oracle HR) instance was compromised which allowed movement into GovCloud (AWS)

show 2 replies