Ep. 84 - ShinyHunters Leaked 5,000 Agents' Home Addresses Over One FBI Advisory

ShinyHunters breached FBIJobs.gov, leaked personal data on roughly 5,000 Bureau personnel—including 14 staffers tied to China-focused counterintelligence—and triggered arrests in Amsterdam and Jordan.

We separate what the FBI confirmed from what the crew claimed: the unverified Oracle PeopleSoft zero-day, the vishing and OAuth token abuse behind 140+ breaches, and why the arrests wound the brand but not the playbook. Plus, the four controls worth validating this week, starting with FIDO2.

00:00 What happened when ShinyHunters picked a fight with the FBI?

03:17 Who are the normal ShinyHunters victims?

03:50 How did ShinyHunters breach FBIJobs.gov?

05:58 How did ShinyHunters deface the FBI job site?

08:01 Why did a SaaS extortion crew target the FBI?

09:44 What happened after the ShinyHunters deadline passed?

15:47 Is ShinyHunters finished after the arrests?

17:00 What four controls should security teams validate now?

More on this crew in Ep. 27, The Evolution of ShinyHunters: https://www.safebreach.com/podcast/the-evolution-of-shinyhunters/

And on Jaguar Land Rover in Ep. 34: https://www.safebreach.com/podcast/inside-the-jaguar-land-rover-cyberattack/

#cybersecurity #infosec #CISO #ShinyHunters #ScatteredSpider #FBI #SaaSSecurity #BAS