Inside the Devastating Hack of the F.B.I.
Episode
23 min
Read time
2 min
Topics
Relationships, Crypto & Web3, Psychology & Behavior
AI-Generated Summary
Key Takeaways
- ✓Scope over scale: The FBI hack's danger lies not in volume but in data granularity. Hackers accessed agents' supervisors, covert job titles (including China and Russia desk assignments), family members' names, addresses, and travel patterns — enough to construct a detailed organizational map of the FBI's clandestine workforce and identify targets for retaliation or extortion.
- ✓Shiny Hunters' extortion model: Unlike traditional ransomware groups that lock files, Shiny Hunters steals data and threatens public release within 72-hour windows, demanding Bitcoin payment. They have previously breached AT&T, Ticketmaster, and educational platforms — demonstrating that no organization size provides immunity from this data-theft-and-threaten methodology.
- ✓Motivation was reputational, not financial: Shiny Hunters targeted the FBI specifically in retaliation for a May FBI advisory that accused the group of swatting and harassment tactics. The hackers disputed those characterizations and demanded the advisory be retracted — revealing that criminal hacker groups actively monitor and respond to law enforcement's public communications about them.
- ✓Data containment is effectively impossible: Once stolen data is shared with multiple news outlets and security researchers — as occurred here — it cannot be recalled. The FBI hack sample circulated across several organizations within days. Stolen datasets can subsequently be sold to foreign intelligence services, including Russian and Chinese agencies, regardless of hackers' stated intentions not to publish.
- ✓Government data hygiene remains a systemic failure: FBI personnel did not know a centralized repository containing years of accumulated sensitive employee and family data existed within the Oracle PeopleSoft HR portal. The 2014 OPM breach, which exposed 20 million records and 5 million fingerprints, prompted reform vows that clearly did not extend to auditing and purging legacy sensitive datasets.
What It Covers
Cybersecurity reporter Dustin Volz details how the criminal hacker collective Shiny Hunters breached an FBI HR portal, exposing tens of thousands of current and former agents' personal data — including family members, home addresses, and covert job titles — in what officials compare to the 2014 OPM breach.
Key Questions Answered
- •Scope over scale: The FBI hack's danger lies not in volume but in data granularity. Hackers accessed agents' supervisors, covert job titles (including China and Russia desk assignments), family members' names, addresses, and travel patterns — enough to construct a detailed organizational map of the FBI's clandestine workforce and identify targets for retaliation or extortion.
- •Shiny Hunters' extortion model: Unlike traditional ransomware groups that lock files, Shiny Hunters steals data and threatens public release within 72-hour windows, demanding Bitcoin payment. They have previously breached AT&T, Ticketmaster, and educational platforms — demonstrating that no organization size provides immunity from this data-theft-and-threaten methodology.
- •Motivation was reputational, not financial: Shiny Hunters targeted the FBI specifically in retaliation for a May FBI advisory that accused the group of swatting and harassment tactics. The hackers disputed those characterizations and demanded the advisory be retracted — revealing that criminal hacker groups actively monitor and respond to law enforcement's public communications about them.
- •Data containment is effectively impossible: Once stolen data is shared with multiple news outlets and security researchers — as occurred here — it cannot be recalled. The FBI hack sample circulated across several organizations within days. Stolen datasets can subsequently be sold to foreign intelligence services, including Russian and Chinese agencies, regardless of hackers' stated intentions not to publish.
- •Government data hygiene remains a systemic failure: FBI personnel did not know a centralized repository containing years of accumulated sensitive employee and family data existed within the Oracle PeopleSoft HR portal. The 2014 OPM breach, which exposed 20 million records and 5 million fingerprints, prompted reform vows that clearly did not extend to auditing and purging legacy sensitive datasets.
Notable Moment
One day before their own deadline, Shiny Hunters reversed course and told Dustin Volz they never intended to publish the FBI data publicly — a complete contradiction of their stated threat. The FBI responded the same day by announcing the arrest of an alleged 24-year-old Shiny Hunters leader in the Netherlands.
Episode Transcript
Hey what's up guys, it's Haley Bailey. Okay, I need to tell you about something. I just got YouTube Premium. It's got tons of awesome features like offline downloads so I can download my favorite videos before I travel and watch them whenever I don't have WiFi because we all know airplane WiFi is the worst. I get ad free, I get backroom play, and there's like a ton more in there. You should try it. If you like YouTube, you'll love YouTube Premium. Try it now for two months free at youtube.com/premium. Trial eligibility varies. Terms apply. Cancel anytime. That's a mouthful. From New York Times, I'm Michael Bilbaro. This is The Daily. A little over a decade ago, after hackers broke into the US government and stole the personnel records of millions of federal workers, US officials vowed that it would never happen again. It just did, this time to the FBI. Today, my colleague, cybersecurity reporter Dustin Voltz, tells the story of this devastating attack, the group behind it, and what now happens to the hypersensitive data that those hackers have stolen. It's Wednesday, September 30. Dustin, welcome back to The Daily. Thank you. Good to be here. Good to have you. You cover the world of hacking cyberattacks, and this hack is a doozy. So can you just describe the scale of what just happened at the FBI? It is a doozy. And I think more important than the scale, which could be tens of thousands of current and former FBI employees affected here, I think the scope of it is what's really important. Because hackers were able to break into a government jobs portal the FBI uses, and not just steal names and phone numbers and emails, but far more sensitive details about these officials, including their spouses' names, in some cases, their children's names, their addresses, their secretive job titles, and even details that could be used to help a hacker follow them during their travels. Let me just zero in on on one of these staggering things you just said, job titles at the FBI. What what kind of job titles were revealed in this hack? So the FBI is a pretty secretive organization. A lot of the work they do is public, but a lot of it is behind the scenes. And so the job titles might not be classified, but they are very, very sensitive, and they might reveal things such as an agent working in counterintelligence against foreign spies, or working on a China desk, or a Russia desk. And these are FBI officials that you sort of never really hear about, you never meet, and they spend oftentimes decades of their lives working behind the scenes to try to pursue various alleged criminals. So this hack accessed information so detailed that the hackers who now have it can see which people within the FBI are assigned to which of our foreign adversaries. That's very intrusive. It is. And it's …
Get the full transcript (4,103 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 20-minute episode.
Get The Daily (NYT) summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from The Daily (NYT)
Are Prediction Markets Gambling? A Lot Rides on the Answer.
Sep 29 · 26 min
Cognitive Revolution
Zero to One in AI Safety: Halcyon's Mike McCormick on Launching 30 New Orgs & the Founder Bottleneck
Sep 25
More from The Daily (NYT)
He Was Deported to a Country He’d Never Heard Of
Sep 28 · 27 min
Modern Wisdom
Ex-Military Hacker: The Secret World Of Government Surveillance - Bill Thompson - #1131
Aug 1
More from The Daily (NYT)
We summarize every new episode. Want them in your inbox?
Are Prediction Markets Gambling? A Lot Rides on the Answer.
He Was Deported to a Country He’d Never Heard Of
The Best TV Shows of the 21st Century
Sylvester Stallone Hid His Struggles for Decades. Now He’s Coming Clean.
The Life and, for Now, the Death of the Kennedy Center
Similar Episodes
Related episodes from other podcasts
Cognitive Revolution
Sep 25
Zero to One in AI Safety: Halcyon's Mike McCormick on Launching 30 New Orgs & the Founder Bottleneck
Modern Wisdom
Aug 1
Ex-Military Hacker: The Secret World Of Government Surveillance - Bill Thompson - #1131
Cognitive Revolution
May 24
All Compute Is Food: Palisade's Jeffrey Ladish on AI Shutdown Resistance, Self-Replication & Ecology
The Joe Rogan Experience
Apr 15
#2483 - Spencer Pratt
The Jordan Harbinger Show
Mar 31
1305: Johnathan Walton | How to Spot Scammers, Grifters, and Thieves
Explore Related Topics
This podcast is featured in Best News Podcasts (2026) — ranked and reviewed with AI summaries.
You're clearly into The Daily (NYT).
Every Monday, we deliver AI summaries of the latest episodes from The Daily (NYT) and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime