A hacking group says it has taken the personal details of every serving FBI agent — names, roles, badge numbers, home addresses, phone numbers and in some cases the names of spouses — and that it will publish them unless the bureau does what it asks.
What the group says it has
The claim comes from ShinyHunters, a crew that has spent the past two years working its way through corporate cloud tenancies rather than breaking down front doors. Its account is that it got in through a vulnerability in Oracle cloud software used by the bureau, and from there reached several internal systems: FBIJOBS, the recruitment platform; FBI BEAST; FBI MedLink, which handles medical records; and FBI BICS.
If that is accurate, it is not a list of e-mail addresses. It is the working identity of a national law-enforcement agency — who each officer is, what they do, and where they sleep. Professor Ciaran Martin, who set up the UK's National Cyber Security Centre and now teaches at Oxford, told the BBC it was "as serious as it gets when it comes to data breaches". The FBI has not confirmed the scale of what was taken.
The unusual part: no ransom
Most extortion of this kind ends in a number. This one does not. The group is demanding that the FBI retract an advisory it published in May about the group's own activity, and has given the bureau roughly a week to do it. If the advisory stays up, it says, the files go out.
That is a meaningful shift. A ransom demand is a transaction, and governments have a settled answer to it — do not pay. A demand to unpublish a public security warning asks a law-enforcement agency to take down its own advice to the people it protects, which is not a payment it can quietly refuse and move on from. It also tells you what the group now values: not the money, but the ability to keep operating without being named.
Why the route in matters more than the target
The FBI did not lose this through an agent clicking a bad link, if the account holds. It lost it through enterprise software sitting between the agency and its own records. That is the same shape as most of the large breaches of the past two years, and it is the part organisations are worst at defending, because the flaw is in a product they bought rather than a system they built.
It also lands in a month when the gap between how fast systems are attacked and how fast anyone notices has been the running story — an OpenAI agent spent three months inside an Australian government health portal before Canberra was told.
What it means in Bangladesh
Bangladesh holds the same category of data and protects it less well. Police and RAB personnel records, the NID database, the payroll and medical systems behind every government service — all of it sits on enterprise software bought from vendors, maintained on service contracts, and patched when somebody gets to it. The 2023 leak from a government website that exposed millions of citizens' NID details was not a sophisticated attack; it was an endpoint nobody had locked.
Three things are worth doing this week rather than this year. Inventory which internet-facing services run vendor platforms — Oracle, SAP, Microsoft — and check each against the vendor's current advisories, because the flaw being exploited is almost never a secret. Put the personal records of security and law-enforcement staff on a separate, tightly restricted system rather than the general HR database. And decide in advance, in writing, who in BGD e-GOV CIRT takes the call when a group like this makes a demand that is not about money, because the week you have to decide is not the week to start thinking about it.




