
Current and former FBI agents have expressed shock, fear and anger after a hack that appears to have exposed the private and personal information of the agency’s entire workforce.
"This is really bad for our undercover agents," said a former FBI cyber investigator who is now a security consultant, fearing the safety of his colleagues.
He and other agents, who meet in private group chats, worry that their personal data could soon be freely available to criminals and hostile nation‑state hackers. They also fear that criminals could use the stolen records to stage highly convincing phishing scams, bribery requests or violent threats.
ShinyHunters, the hacking group claiming responsibility, has threatened to publish the stolen databases and documents within four days unless its demands are met. The group has demanded the FBI retract an advisory published in May, which it says "offended" them. Unlike typical extortion takings, it has avoided asking for money.
"The agency is under extreme pressure," said former agent Michael McPherson, senior VP of security at ReliaQuest. "We are witnessing a threat that cuts to the core of agent safety, especially for their families."," explained McPherson. "Names, addresses, phone numbers, badge numbers and even medical information such as allergies and test results have been exposed."
The data includes thousands of agents, senior officials and even deputy directors. In addition to personal details, the breach reveals highly sensitive medical data—blood and urine test results—linked to each agent’s fitness‑for‑work assessments.
The FBI has acknowledged the breach, stating it is “aggressively investigating” how it occurred. Meanwhile, the group’s digital footprint shows that some stolen data are already circulating in online cyber‑research circles, suggesting the damage may be irreversible. "A lot of the damage may already be done," said Cynthia Kaiser, former Deputy Director of Cyber and current head of the Halcyon Research Centre.
Agents also fear physical attacks from criminals they have investigated and from “violence‑as‑a‑service” operations run by young online gangs. ShinyHunters has a history of evading law law enforcement with extortion attacks on companies such as Rockstar Games and the educational platform Canvas.
"The bureau doesn’t know what to do with teenage cyber criminals," said a former agent. "There is no doubt we are taking this extremely seriously and will use all our partners to bring them to justice.", said McPherson.
















