ShinyHunters claims it has taken the personnel records of the FBI: names, home addresses and telephone numbers of, in its own words, almost every agent. The Bureau has confirmed an investigation into unauthorised activity and has said nothing publicly about the size of the alleged theft. FBIJobs.gov, meanwhile, spent days showing a maintenance notice, which in security work is the polite way of saying somebody pulled the plug in a hurry.
Start with what is a claim and what is not, because the distinction is the whole story. The theft is claimed, not established. A sample of the data reached journalists, and part of it could be matched against public records. That is the end of what anyone outside the investigation knows. The figures floating around, terabytes of information, records on thousands of people, come from the group itself, and a criminal crew describing its own haul is not a neutral witness.
The door they say they used
What deserves attention is not the scale but the route. There is no cinematic exploit here. According to the group’s own account, the first foothold was an Oracle PeopleSoft server, the sort of platform organisations run to handle human resources and job applications, and from there they say they reached a government cloud environment.
That is the part worth sitting with. An agency that argues, year after year, for lawful access to other people’s communications, for retention, for exceptions to encryption, would have been opened through the software that processes CVs. Not the operational core. The back office. The place every large organisation treats as plumbing and staffs accordingly.
The motive claimed is stranger still. The group says the operation has no financial purpose and has asked the Bureau to withdraw a published report that, in its telling, contains false accusations against it. That is not a ransom demand. That is a bad review being negotiated with the home addresses of federal agents as collateral.
Why home addresses are not just another data field
If the stolen material really does include the personal details of agents and their families, the exposure is not abstract. Addresses and telephone numbers are the raw material of targeting: intelligence work, pressure, coercion. A hostile service does not need a dramatic breach to use them, only patience.
That risk is a possibility, not an event. Nothing so far shows that the data has been used, or by whom, or that the operation has the political character its authors give it. Both things are true at once: the harm has not been demonstrated, and the material is exactly the kind whose misuse cannot be undone once it starts.
It is also not an isolated year. In March the Bureau opened an investigation after unidentified intruders reached a system used to manage real time interception and warrants tied to foreign intelligence collection, a category of breach that could expose the targets of surveillance rather than the surveillance itself. Separately, in March, a pro Iranian group called Handala claimed access to the personal email account of the Bureau’s director, Kash Patel, and later published its contents, presenting the action as a response to American strikes on Iran. Claims again, and again the same pattern: the internal, unglamorous surfaces are the ones under sustained interest.
The consent click that no second factor stops
There is a second lesson in this story, and it does not come from Washington.
Andrea Galeazzi, an Italian technology YouTuber, lost his channel in fifteen seconds. He had two factor authentication switched on. He had, in his own account, every protection active. What he did not have was advanced protection, and what he did do was click approve on a link sent by a microphone company he was working with, asking him to validate the channel.
Twenty seconds later, he says, the attackers had registered a physical security token of their own, which locked him out for good. Three minutes later the channel had a new name, a new logo and a live stream running a cryptocurrency scam.
Two factor authentication does not defend against a permission the account holder grants with their own hand. That is not a flaw in the second factor. It is a description of what a second factor is for, and of a threat model that stopped being about stolen passwords some time ago. Phishing that is tailored, fluent and arriving from a genuine business relationship does not need to break anything. It needs one authorisation.
Galeazzi’s own conclusion, after the fact, was to separate his identities: one hardened mailbox for the channel, one for social accounts, one for private life. Sensible, and available to anybody, on any weekday that is not the weekday you get hit.
Advanced protection exists, and is switched off
Google’s Advanced Protection Program was designed for journalists and politicians at risk, and anyone can turn it on. It requires a passkey or a security key to prove identity, so that an unauthorised party cannot get in even with the username and the password. It blocks most third party application access and it makes account recovery slower and stricter, which is the point rather than the inconvenience.
Users can also review the state of their own account through Google’s security checkup, which walks through the ordinary list: third party connections, recovery address, enhanced safe browsing, recent activity, saved passwords. Always through the provider’s own settings, never through a link that arrives in a message, which is precisely how the last one arrived.
None of this is new, all of it is available to anybody who goes looking, and all of it is off by default. The industry has decided that friction at sign in costs more than the occasional catastrophe, and it has decided that on behalf of people who were never consulted.
Which brings the two halves of this story together. A YouTuber who authorised the wrong request pays with a channel. Federal agents whose home addresses may be circulating do not pay for a decision they made. They pay for one taken somewhere above them, by whoever concluded that personnel records could live on an HR platform and that this was somebody else’s problem.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html
