A criminal hacking group known as Shiny Hunters revealed last week that it had stolen a vast trove of sensitive personal data from the F.B.I., potentially one of the worst breaches of sensitive government information in the internet age. The breach may have compromised information about tens of thousands of former and current F.B.I. employees, including data like home addresses, Social Security numbers and even secretive job assignments.
In a series of cryptic statements, Shiny Hunters demanded that the F.B.I. retract a public advisory the bureau had issued this spring warning of the group’s cyberattacks. In an email to The New York Times on Friday, Shiny Hunters said that the bureau had until the end of Tuesday to fulfill its request. But on Monday, it appeared to walk back that demand, saying it would not publish the data, as it typically does with the information it steals.
Shiny Hunters is a loose collective of relatively young hackers who have been responsible for dozens of data breaches since about 2019. The group has typically engaged in ransom-or-release attacks, demanding millions of dollars in payments in exchange for not publishing the data its members steal. Recent arrests offer a glimpse of Shiny Hunters’ membership, suggesting that the group operates across the globe. Sebastien Raoult, a French citizen then 22 years old, was convicted in 2024 of participating in some attacks.
Shiny Hunters has targeted hundreds of corporations and government agencies. Among its targets were AT&T, the luxury goods company LVMH, and Rockstar Games. Cybersecurity authorities say the group often targets software and cloud service providers to gain access to many targets simultaneously.