The Daily - Inside the Devastating Hack of the F.B.I.
Episode Date: September 30, 2026A little over a decade ago, after hackers broke into the U.S. government and stole the personnel records of millions of federal workers, officials vowed that it would never happen again. Something sim...ilar recently did — to the F.B.I.Dustin Volz, who covers cybersecurity for The New York Times, tells the story of the attack, the group behind it and what could happen to the stolen data.Guest: Dustin Volz, a cybersecurity and intelligence reporter for The New York Times.Background reading: The hackers said they had stolen thousands of sensitive F.B.I. personnel records.The embarrassing breach at the F.B.I. has fueled fears of harm to its employees.Photo: Julia Demaree Nikhinson/Associated Press For more information on today’s episode, visit nytimes.com/thedaily. Transcripts of each episode will be made available by the next workday. Subscribe today at nytimes.com/podcasts or on Apple Podcasts, Spotify and Amazon Music. You can also subscribe via your favorite podcast app here https://www.nytimes.com/activate-access/audio?source=podcatcher. For more podcasts and narrated articles, download The New York Times app at nytimes.com/app. Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
Transcript
Discussion (0)
From New York Times, I'm Michael Barrow.
This is the Daily.
A little over a decade ago, after hackers broke into the U.S. government
and stole the personnel records of millions of federal workers,
U.S. officials found that it would never happen again.
It just did, this time, to the FBI.
Today, my colleague, cybersecurity reporter Dustin Volz,
tells the story of this devastating attack, the group behind it,
and what now happens to the hypersensitive data that those hackers have stolen.
It's Wednesday, September 30th.
Dustin, welcome back to the Daily.
Thank you. Good to be here.
Good to have you.
You cover the world of hacking cyber attacks,
and this hack is a doozy.
So can you just describe the scale of what just happened at the FBI?
It is a doozy.
And I think more important than the scale, which could be tens of thousands of current and former FBI employees affected here,
I think the scope of it is what's really important because the hackers were able to break into a government jobs bore world the FBI uses and not just steal names and phone numbers and emails, but far more sensitive to.
about these officials, including their spouse's names,
in some cases, their children's names,
their addresses, their secretive job titles,
and even details that could be used to help a hacker
follow them during their travels.
Let me just zero in on one of these staggering things you just said,
job titles at the FBI.
What kind of job titles were revealed in this hack?
So the FBI is a pretty secret
organization. A lot of the work they do is public, but a lot of it is behind the scenes. And so
the job titles might not be classified, but they are very, very sensitive. And they might
reveal things such as an agent working in counterintelligence against foreign spies or working
on a China desk or a Russia desk. And these are FBI officials that you sort of never really
hear about. You never meet. And they spend oftentimes decades of their lives working behind the
scenes to try to pursue various alleged criminals.
So this hack accessed information so detailed that the hackers who now have it can see
which people within the FBI are assigned to which of our foreign adversaries.
That's very intrusive.
It is, and it's not just their job titles.
It's also, in many cases, they're supervisors.
And in many ways, you almost can build a map of the FBI's.
workforce and see what people are doing, learn more about their investigations, and potentially
respond in other ways, depending on what your pursuit or interests are. Right. And your pursuit could be
to end such an FBI investigation. Your pursuit could be to seek revenge on an FBI agent,
to extort them. Who knows? This information would seem to arm you to do any number of those things.
Absolutely. One of the top concerns that I've been hearing for the past week from a number of
former FBI officials that I've spoken to, including senior officials who worked on cybersecurity issues,
is that these are going to be FBI agents who maybe put violent criminals behind bars, you know,
maybe prosecuted the mafia and are now, you know, if the data surface is publicly exposed to forms of retaliation.
You know, I think it's important for people to understand that these types of FBI agents zealously guard their privacy.
They do everything they can to make sure their addresses are not listed.
These people are not on social media.
and now you have this database that is out there that reveals all sorts of intimate details.
So given the scale of what you're laying out here, where does this, how does this stack up against previous hacks into the United States government?
So about 12 years ago, U.S. officials this morning are blaming Chinese hackers for another serious data breach.
The Chinese government hacked the Office of Personnel Management, also known at a personal management, also known
OPM, and stole more than 20 million records of U.S. government employees and contractors,
as well as something like 5 million fingerprints.
As one official told us, Charlie, this is bad.
There is no way to put lipstick on this pig.
And that was kind of considered a historic hack of epic magnitude
that the Chinese intelligence services would be dining out for years, if not decades.
I remember it.
Why wasn't this information encrypted?
The encryption is one of the many tools that systems can use.
I'll look to my colleagues at DHS for their response.
No, I want to know from you why the information wasn't encrypted.
It was a huge deal, and it prompted all sorts of congressional hearings.
The status was unacceptable when leadership has to resign.
Resignation from the director.
This was during the Obama administration.
And a lot of vows to better protect data, put it behind lock and key.
to make sure this never happened again.
Obviously, they failed.
They failed.
And a lot of officials are telling me
that this current hack could be as bad
or in some ways worse than what happened
with the OPM breach
because of the granularity of the data at issue
and because of who took it.
Hmm, well, talk about that.
Who took it?
What do we know about the hackers who did this?
Why they did it?
precisely how they did it.
So the hackers in this case are not a foreign intelligence agency.
Instead, they are a loose collective of young criminal hackers believed to be operating in
countries around the world.
And these hackers go by the name, shiny hunters.
Hackers often have very interesting names.
Analysts say that this one seems to be a reference to the popular video game Pokemon
in which gamers go after it.
is extremely rare and exotic, shiny Pokemon.
Got it.
So the shiny hunters are out there not to just get everyday paydays,
but to score big hits, to bring home big game.
And they are breaking into hundreds of organizations
to extort them, in some cases, for payments of millions of dollars.
So they're basically in the business of ransomware.
Yes, but it's not a traditional ransomware group.
Instead of breaking into an organization and locking
up their files and demanding payment, what they do instead is they break into an organization,
steal all of that data, and then threaten to do things with it, like publish it online,
unless they're given a payment via Bitcoin in oftentimes as little as 72 hours.
And they go after all sorts of companies, no matter how big, AT&T, Ticketmaster, educational software
used by students around the country and the world. I mean, these are just a few names that stick out.
So this would seem to be a real departure from this group's normal MO of going after companies, threatening to release things, getting paid.
The FBI is not Ticketmaster, and it's not an education software company.
So why target the premier law enforcement agency of the United States?
That's a great question.
It is certainly audacious to go after the FBI.
And it really surprised a lot of people.
It surprised me.
It surprised a lot of security researchers.
and it certainly surprised, I think, the FBI
and a lot of former officials who worked there.
The hackers said when they disclosed this hack
that essentially they were doing this as a form of revenge.
For what?
They said they were seeking retribution from the FBI
for a public service advisory
that the Bureau issued back in May of this year
where they warned that the shiny hunters, hackers
are very, very serious and doing a lot of damage
and in that they detailed their tactics.
The FBI said that they engage in harassment and intimidation of victims to try to secure payment.
Such as.
Such as revealing private photos that they've stolen from victims,
launching swatting attacks where local law enforcement is called into the address of a victim to scare them maybe with guns drawn,
all sorts of harassment type activities that the shodding.
Johnny Hunter's group says, hey, look, we extort victims, but we don't do those kinds of things.
And the FBI needs to correct the record.
So basically, they're mad that they're not being seen by the FBI for the honorable thieves they see themselves to be.
They feel like the FBI has incorrectly maligned them as something even worse than they are.
Yes, they view themselves as honorable thieves.
At least some of them do.
They talk about their work as if it's almost a business that they are running.
and they are very good at what they do.
And in this case, what they did or what they've claimed to have done is to find a zero-day computer flaw.
This is a type of flaw that is unknown to the world that has not been previously disclosed
to attack a Oracle PeopleSoft product that is used for helping with HR and financial records and data management for companies.
and what they have said is that they use this zero day to compromise the FBI to get this historic and current data from the jobs portal and walk away with it.
And so the world learns about this hack last Tuesday when the group posts on its dark web forum that they have hacked the FBI.
And in their statement, which calls out Director Cash Patel, as well as the cyber leader of the FBI, they say,
we need you to fix this public service alert or else, essentially.
And in that statement, they also include conveniently a email to contact them.
So being a reporter, as I am what to do, I reached out to them.
I sent them a note and said, hi, I hear that you have hacked the FBI.
What a funny position to be in.
It was. I honestly did not expect them to respond at all, but they were eager to do so and got back to me, I think, within about 10 minutes.
Wow.
And that's when they sent me a sample of data that they said was from the hack of the individuals who had their data compromised.
They sent you essentially a sample of the hacked material to prove that they've done what they say they have done.
Yes, it was sort of like, you know, we've stolen a lot of stuff and here's a receipt.
And they shared that information and said, you know, we have a deadline for the FBI to retract or remove this public statement.
Tuesday, September 29th.
And the officials and security experts that I spoke with were very much under the impression that they were going to leak some or,
or all of the data that they had obtained online.
They would publish all this very sensitive FBI personnel data
if the FBI didn't meet their demand.
Yes.
So the clock is ticking.
I am emailing with the hackers.
I ask them point blank,
what are you going to do if the deadline passes
and the FBI does not comply?
They say no comment.
But meanwhile, the fear and anxiety is growing
in the security community within the FBI
that come the deadline,
they could do something very dramatic
and just publish FBI names and titles
and family member names,
all of the data online for the whole world to see.
And then on Monday, a day before the deadline comes to pass,
the hackers reach out with a new message
that twists the story on its head.
We'll be right back.
So, Dustin, what did these hackers say
right before this deadline
that ultimately ends a really different,
changing the whole direction of this story.
So the hackers reach out in a lengthy email and tell me,
we have a clarification.
We are not going to publish this FBI data online.
Hmm.
We are not going to do it.
And anybody who thought otherwise was mistaken.
So essentially, nothing to see here.
Let's all move on.
I mean, how do you understand such a complete backing down from their normal tactics?
And a sudden claim that the thing,
everyone feared seemingly quite justifiably was, oh, kind of total misunderstanding.
Look, far be it from me to try to get inside the minds of a diffuse network of international hackers.
But here's what strikes me. The FBI says they are aggressively investigating this,
working with third parties to go after the hackers, essentially. They are treating this as a five-alarm fire
internally. Meanwhile, the news of the hack is getting more and more attention. The hackers are
doling out exclusives to various media outlets about exactly what they've taken. That drumbeat
continues. And you see the reaction building, too, from former FBI officials, security experts,
saying this is historically bad when we think about the theft of data from the government.
And so all of this is building into a crescendo as this deadline approaches. And that's when
the hackers decide to issue this updated statement.
Now, like I said, it's hard to know exactly what their motivations are.
This is a loose collective of hackers.
It's believed to be a bunch of different people working together from across the globe.
And so it is very possible that you have different factions that have different views about how hard they want to push this, right?
Some might be saying, hey, let's milk this for all it's worth.
Let's keep going.
Others might think, you know, maybe we have gotten what we wanted.
We got the attention and let's sit back.
Right. I mean, it seems quite reasonable to speculate that perhaps one of the factions within this collective of diffuse hackers may have made the claim to the rest of them that what they did here was ultimately maybe just a little too ambitious, that this is not AT&T, this is not Ticketmaster, and that kicking this Hornets Nest, the FBI, that that might be a huge mistake and that it would backfire and that it might even destroy this group.
It's hard to know, but it's very possible.
And I mean, think of, you know, the mafia or other criminal organizations over the years.
Like, this is not an unusual situation where you do have competing factions that might have disagreements about what they should do, how they should carry out their business.
However, if they thought they were going to get the FBI off their back by vowing to not publish the data, they were wrong.
Hmm.
Wrong how.
On Tuesday.
I'm Brett Leatherman, assistant director of the FBI's cyber division.
Brett Leatherman, who has a great name for an FBI official, came out in a public video.
Today, our partners at the Dutch National Police announced the arrest of one of the alleged leaders of Shiny Hunters.
And he touts in this video, the recent arrests in the Netherlands of a 24-year-old hacker believed to be a key figure in the Shiny Hunter's group.
Now, to the remaining members of Shiny Hunters.
And he says, essentially, to the rest of the gang.
Other groups believed anonymity or their friends would protect them, and they were wrong.
You know how to find us, and we know how to find you.
We are coming after you.
I suggest you reach out first while the choice is still yours.
Well, while the FBI issues these threats and no doubt is vigorously attempting to find all these hackers and arrest them,
the reality is that all of this data is still floating around.
within the hackers' computer systems,
and I suppose even in the email of some reporters.
That's right.
So just because the hackers said they're not going to publish it,
first of all, they could change their mind and decide to do that later.
But also, there's nothing to stop them from selling the hacked data
to the highest bidder or multiple bidders,
including Russian and Chinese intelligence agencies
that might have deep interest in learning everything they can
about the FBI's workforce.
So the idea that this is the end of the story is definitely not the case because this is
data that is now out there.
They've shared it with several different news outlets.
There are security researchers who have come forward and publicized that they have also obtained
the sample data set as well.
It's unclear how.
But once you start sharing data with other people, it tends to take on a life of its own.
And it really can't be put back in the box.
I have to ask, Dustin, because I'm genuinely curious and listeners maybe, too, you said you got a sample of this hacked material.
What do you, what do we, the Times, do with this if I can ask?
You know, this was a difficult issue for us to deal with internally.
Should we even look at it?
And if we look at it, what should we do with it?
Should we analyze it?
Should we report on it?
How much should we report on it?
These were a lot of questions we had internally with our lawyers and our standards.
team about sort of how do we want to handle this material that is out there.
Mm-hmm. We are not sharing it with anyone, and we are securing it to the best of our ability.
So what seems clear is that the FBI, when it comes to this data, is not at all out of the woods.
And that makes me want to go back to, Dustin, what you had described as the government's response to that infamous OPM hack all those years ago, when it said,
we're never going to let this happen again, and it does happen again.
Because ultimately, this feels like a very meaningful, not just security breakdown,
but a betrayal of people at the FBI who signed up for really sensitive law enforcement work
within understanding that their personal information would be protected implicitly.
That's a reasonable bargain to reach with your employer if your employer is the FBI.
and instead the FBI left its personnel system so vulnerable that this hack happened.
And these workers are now in real unnecessary peril.
That's right.
You know, I think there's a lot of current and former officials that we've been hearing from at the FBI
who are very frustrated about the situation and made clear to us that they didn't even know that a data set like this existed.
And had questions about why it existed and why would there be a place where there's a repository of so much,
intimate information that seemingly is kept for years without being deleted, without being purged,
that a hacker could access and take. And a lot of these officials said, you know,
working for the FBI can be a dangerous job. I sign up for this, but my family doesn't. And the fact
that this data set includes emergency contacts, spouses, siblings, in some cases, children,
That is, I think, what is especially alarming to a lot of the people who work at the FBI,
that it's not just them that have to worry about it, but their entire families in some cases.
And to me, this demonstrates that even though the government has come a long way since that last big hack,
that hack of OPM, it still has a very long way to go to protect its systems,
and more importantly, to protect its people.
Well, Dustin, thank you very much. I appreciate it.
Thank you for having me.
You can read more from Dustin Volz and all of our reporters on the New York Times app.
If you don't already have the app, we want to let you know that if you download it right now,
you'll get access to all of our journalism free for one month.
So give it a try.
We'll be right back.
Here's what else you need to another day.
The Times reports that in the months before OpenAI's artificial intelligence went rogue
and attacked the startup company Hugging Face,
two OpenAI employees raised an alarm with their superiors but were ignored.
In emails, the employees worried that OpenAI's newest artificial intelligence models
were not being appropriately monitored during testing.
In response, their superiors said that that testing needed to be,
move ahead to meet deadlines. And workers said that no new safety protocols were created.
And in a temporary victory for the Trump administration, the Supreme Court allowed the government
to keep deporting people to countries they aren't from and may have no connection to.
These so-called third-country deportations, including to authoritarian countries with human rights abuses,
were the focus of Monday's episode of the show.
And while the justices cleared the way
for those deportations to continue for now,
they fast-tracked a final ruling in the case for next year.
Today's episode was produced by Alex Stern,
Olivia Nat, and Eric Kruppke,
with help from Jack DeSidoro.
It was edited by Annie Minoff.
Contains music by Pat McCusker,
Rowan Misto, and Diane Wong.
and was engineered by Alyssa Moxley.
Our theme music is by Wonderly.
That's it for the daily.
I'm Michael Bobara.
See you tomorrow.
