The foreign minister of Estonia said Putin is no longer in a “secure” position as the war he’s been waging in Ukraine enters its fifth year.
thedailybeast.com/vladimir-p…— @thedailybeast Sep 23, 2026
Month: September 2026
|
Michael_Novakhov shared this story . |
Advertisement
The compromise, if confirmed, would be the latest in a string of cybersecurity failures at the F.B.I., which said it was investigating the matter.
A prolific criminal hacking group said it had stolen the data from an online jobs portal for the F.B.I.Credit…Tierney L. Cross/The New York Times
Dustin Volz covers cybersecurity and intelligence and has reported extensively on multiple major hacks of sensitive data at the F.B.I. He reported from Washington.
A prolific criminal hacking group said Tuesday that it had stolen a large tranche of sensitive personnel information belonging to thousands of F.B.I. officials in what would amount to a stunning breach of private data for the nation’s top law enforcement agency.
The hackers, who call themselves ShinyHunters, said the records were stolen from an online jobs portal for the bureau and included names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information and other data. The group does not appear to have yet leaked any of the data publicly.
“We have compromised the FBI,” the group said in a message posted online that was addressed to the F.B.I. director, Kash Patel, and Brett Leatherman, who oversees the bureau’s cybersecurity division. “We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.”
In its message, ShinyHunters said it had targeted the F.B.I. as retribution for a public advisory the bureau issued in the spring warning about the group’s tactics. The group demanded the F.B.I. “correct or simply REMOVE” the advisory, which said ShinyHunters was known to harass victims and family members with threatening or coercive maneuvers, and do so within a week or risk further consequences.
An F.B.I. spokeswoman acknowledged the breach, saying that the bureau was aware of the claims and that it was investigating. In a statement, the bureau said, “While the point of breach is still undetermined — whether a third-party or the F.B.I.’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”
The jobs website remained inaccessible Wednesday morning after its homepage a day earlier featured a banner that read, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”
In an exchange with The New York Times, ShinyHunters described the personnel records it had, stating they concerned the private information of tens of thousands of people. News of the apparent hacking was reported earlier by 404 Media, an online cybersecurity and technology news publication.
Current and former F.B.I. officials and cybersecurity experts who track criminal groups said that the breach appeared authentic and that it amounted to a potentially devastating security lapse and counterintelligence danger for the bureau. Among other concerns, the personnel information of F.B.I. officials, if posted on the dark web, could be acquired by foreign intelligence agencies in China, Russia or elsewhere and weaponized for espionage operations.
Image
Kash Patel, the F.B.I. director, had his personal emails hacked and leaked in March by a pro-Iranian group.Credit…Tierney L. Cross/The New York Times
“If true, this data breach is a reminder that no one is immune from cyberthreats and, unfortunately, it raises serious public safety and counterintelligence risks,” said Sumon Dantiki, a partner at the law firm Baker McKenzie and former senior F.B.I. and Justice Department official who worked on cybersecurity issues.
A more tangible concern is that the data could also be a road map for violent criminals to seek retribution against the F.B.I. agents who put them behind bars, said Cynthia Kaiser, a former senior F.B.I. official who oversaw major cyberinvestigations. F.B.I. agents sign their names to court paperwork submitted against criminal suspects but are generally trained to avoid letting sensitive personal information, such as home addresses or familial ties, easily surface online.
Sign up for the On Politics newsletter. It’s a pivotal moment for American politics. Join us for 2026 and beyond.
“What worries me most is how any criminal with a grudge could use this data to target and physically harm not only the F.B.I. agents who investigated them, but also those agents’ families,” Ms. Kaiser said.
ShinyHunters is a well-known hacking collective that has been active for years and has claimed a string of major headline-grabbing breaches, though security researchers say the group has at times exaggerated or misrepresented its actions. It credibly takes responsibility for several notable hacks, however.
In May, it said it had compromised an online learning system called Canvas that is used by thousands of schools and universities around the world, which led to the spring F.B.I. advisory. The group also said it was behind attacks against Ticketmaster in 2024, which the hackers said had compromised the user information of more than 500 million customers.
The apparent F.B.I. breach called to mind the vast theft more than a decade ago of about 20 million government employee and contractor records from the Office of Personnel Management. That heist, which the Obama administration blamed on the Chinese government, is still considered one of the worst cybersecurity failures on record in the United States. As a result, government agencies strove to better protect and disaggregate sensitive data in an attempt to avoid future thefts of such richly detailed databases.
Given the O.P.M. debacle, former F.B.I. officials said they were stunned to learn that such valuable — and voluminous — private information about bureau personnel appeared to be held in an online database tied to a jobs portal.
The ShinyHunters breach would be just the latest in a recent string of cybersecurity lapses for the F.B.I. Earlier this year, the bureau identified what it believed were Chinese hackers inside a database it maintains on its domestic surveillance orders. That discovery was especially alarming because Beijing appeared to be building on a catastrophic infiltration of the F.B.I.’s internal network used to process and maintain domestic wiretaps on criminal suspects, which was part of a far-reaching espionage campaign that officials first disclosed in 2024 that infiltrated U.S. telecommunications infrastructure.
Mr. Patel, too, had his personal emails hacked and leaked in March by a pro-Iranian hacktivist group associated with the country’s Ministry of Intelligence and Security.
In the most recent episode, ShinyHunters said it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management. The group declined to answer specific questions about the apparent flaw, saying in an email that “we intend to utilise the zero-day for our businesses’ normal operations.” Oracle did not respond to a request for comment.
It was not clear what ShinyHunters, which said it had made off with two to three terabytes of data in total, intended to do should the F.B.I. not retract its advisory about the group. Flashpoint, a cybersecurity company in the United States, said it expected the hackers would likely follow their playbook against corporate victims and soon leak the stolen data online.
“We cannot comment on what we will do if the F.B.I. does not comply with our request,” ShinyHunters said in its email to The Times. “We reiterate we are not extorting the F.B.I. and this is NOT financially motivated.”
The hackers added: “Our intention, goal and motive is solely to set the record straight.”
Tawnell D. Hobbs contributed reporting.
Dustin Volz writes about cybersecurity and intelligence for The Times. He is based in Washington.
Related Content
Advertisement
Add the Sunday Times in print to your subscription. 50% off the first year. Learn more.
Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records – The New York Times nytimes.com/2026/09/23/us/po…
— Michael Novakhov (@mikenov) Sep 23, 2026
💢 Hacking group ShinyHunters claimed on Tuesday to have breached multiple FBI-related services and stolen data “on all FBI employees and applicants,” including names, home addresses, phone numbers and spouse information, according to 404 Media.
➤ The group also defaced the FBI’s jobs website Tuesday with a message reading “this site has been seized by ShinyHunters.”
➤ A group representative provided a sample containing data on 5,000 FBI employees, some of which 404 Media verified through open-source tools, and said the group used a zero-day exploit in an Oracle PeopleSoft product to access AWS GovCloud servers and exfiltrate between two and three terabytes of data.
➤ An FBI spokesperson said the agency is “aware of claims” and investigating the incident.
➤ The group, which typically extorts victims after breaches, said its motivation here is not financial but rather “coercion” tied to a prior FBI report describing ShinyHunters’ tactics, which it demanded be corrected or removed within a week.Dark Web Informer (@DarkWebInformer)‼️ ShinyHunters has shared a message on their pay or leak portal to Director Brett Leatherman of the FBI Cyber Division and Director Kash Patel of the FBI:
“Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI,
During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended.
We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to “disrupt” our operations, an effort that ultimately proved unsuccessful.
For us to properly address and correct these unfounded allegations, we were compelled to adopt a forceful and assertive posture to ensure our response was fully acknowledged. This PSA today does just that.
Our PSA today works to address these allegations and correct them.
We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job. Whether it be a Special Agent or any other role within your agency. The following FBI services were compromised: Criminal Justice (CJ), HR, Medlink, and more.
We are willing to allow you a time of 1 week to correct or simply REMOVE the 2026 Quarter 2 FLASH report on us that includes several FALSE allegations:
– “Threat actors often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. ”
– “To exert pressure on victims[1], SH actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting”
– ” Threat actors may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”We wish to state unequivocally our threats and claims are very real. Not exaggerated and never a bluff. This PSA today is living evidence of that.
We wish to state unequivocally we have NEVER conducted swatting attacks against corporate victims personnel nor have we ever texted victims personnel family members any threats.
We wish to state unequivocally we have NEVER claimed to have sensitive or compromising information, including embarrassing photographs and videos of victims. WE ARE NOT SEXTORTIONISTS.Finally, we wish to STATE UNEQUIVOCALLY we are NOT apart of “The Com”. We have NEVER been apart of “The Com”. “The Com” is a propaganda started by the Information Security Industry which has brainwashed past FBI and DOJ officials into formalising this nonsense.
As a big believer and supporter of the U.S. Constitution – we are exercising the First Amendment and actively combating disinformation. This is not a ransom, coercion, or extortion. Your federal policies do not apply here. This PSA is NOT financially motivated.
We recognise that certain statements within your FLASH report appear to stem from biased public reporting by certain journalists who have previously and intentionally propagated false narratives about our organisation in an attempt to “disrupt” our operations and hinder clients trust in our organisation hoping nobody pays us. Should those certain journalists and you know very well who you are, continue these unwarranted attacks and defamatory statements, we will be forced to respond in a civil manner with a commensurate and forceful defence of our reputation. As any human being would do.
We welcome any and all journalists to inquire us at shinygroup@onionmail.com to hear our side of the story.
Make the right decision, don’t be the next headline.
Thank you for your attention to this matter. -SH”— https://x.com/DarkWebInformer/status/2102449668449882464
— @DropSiteNews Sep 23, 2026
🇺🇦🇺🇸 **“This is a disaster”: Zelenskyy’s U.S. trip may have changed more than it seemed**
Zelenskyy’s latest trip to the United States appears to have produced far fewer concrete results for Kyiv than many had hoped.
According to this assessment, meetings with **Donald Trump, Ursula von der Leyen, Emmanuel Macron** and other Western leaders resulted primarily in an agreement to **continue negotiations**, rather than an immediate breakthrough on Ukraine’s most pressing problems.
More importantly for Kyiv, the framework for any future agreement is reportedly being accompanied by **additional and tougher conditions**.
The result is being compared to a chess **zugzwang**: a position in which every available move risks making the player’s situation worse.
For Zelenskyy, the diplomatic board may be getting smaller by the day. **When every move makes your position weaker, sometimes the biggest problem isn’t choosing the right move—it’s realizing you’re already in zugzwang.** ♟️🇺🇦😏
— @SprinterPress Sep 23, 2026
Breaking news: The FBI said it is investigating a reported breach of its systems by a notorious cybercriminal group that claimed to have stolen a trove of “very sensitive” data on the bureau’s personnel. wapo.st/4y6VQdr
— @washingtonpost Sep 23, 2026
🇺🇦🇷🇺 **Zelenskyy and Lavrov clash over the future of Crimea**
Ukrainian President **Volodymyr Zelenskyy** said that a return to normal life for Ukrainians is impossible without the **liberation of Crimea**, keeping the peninsula at the center of Kyiv’s vision for a post-war settlement.
Russian Foreign Minister **Sergey Lavrov**, meanwhile, reiterated Moscow’s position at the UN Security Council that the **“issue of Crimea is closed forever.”**
The two statements underline one of the fundamental obstacles to any comprehensive peace agreement: **Kyiv insists Crimea must return to Ukraine, while Moscow says its status is non-negotiable.**
And judging by the statements coming out of New York, **the only thing moving faster than diplomacy is the distance between the two positions.** 🇺🇦🇷🇺😏
— @SprinterPress Sep 23, 2026
