Foreign agents, terrorists, criminal gangs all have a foothold on our government. The ones who bought politicians and bureaucrats are the idiots for wasting their money. The smart ones got everything for free.
⚠️ 🇺🇲 The FBI's own internal memo now assumes the worst case as its working premise: ShinyHunters likely stole personal data on every current and former bureau employee, not a subset. That includes Social Security numbers, home addresses, TSA PreCheck IDs that could track undercover agents' travel, psychiatric and medical records, and, most dangerously, unit assignments naming who works counterintelligence, narcotics, and Russian, Chinese and Iranian threat desks specifically, exactly the personnel foreign intelligence services would most want catalogued.
Ciaran Martin, who used to run the UK's own cyberdefense agency, said this could rank worse than the 2015 OPM breach, and his reasoning is precise: "you knew the Chinese weren't going to sell or publish it."
OPM was state espionage, quiet by design. ShinyHunters is a criminal extortion group that explicitly threatened to dump the data unless the FBI retracted a public advisory calling them out for harassment tactics, then reversed itself Monday, claiming it never intended to publish anything and calling the whole episode "a marketing campaign to protect our business."
That walkback doesn't reduce the exposure. Security researchers are explicit that unpublished data can still be sold quietly to criminal networks or foreign governments, arguably the more dangerous outcome, since a public dump at least tells victims what's exposed.
The technical root cause connects this directly to a vulnerability CISA had already flagged as high-risk months earlier. Google's own threat intelligence team reported ShinyHunters running a "mass exploitation" campaign against a PeopleSoft bug publicly disclosed and patched back in June, the same flaw investigators now believe breached the FBI.
A federal agency running human-resources software with a known, patched vulnerability, three months after the patch existed, is the kind of institutional lag that turns a fixable bug into a historic breach.
🇳🇱 The Dutch arrest adds an odd coda rather than a resolution. Pepijn van der Stap, a convicted hacker who had rebuilt his public reputation as a reformed security professional working at a legitimate cybersecurity firm, was arrested in a raid involving flash-bang grenades, and his own former employer says an outside investigation has so far found no evidence he compromised the company or its clients.
ShinyHunters itself denies any association with him. Whether his arrest connects meaningfully to the FBI breach at all is still unclear, a loose thread in an investigation whose central finding, that a government law enforcement agency doesn't know the true scope of its own employee data exposure, is already established regardless of how that thread resolves.