The hacking group ShinyHunters claims it has broken into several FBI-related services and stolen data on every bureau employee and applicant. A representative of the group told 404 Media the haul includes agents’ names, home addresses, phone numbers and information about their spouses. “We hacked the FBI. We hold data on all FBI employees and applicants,” the representative said. The group shared with 404 Media what it described as a sample covering 5,000 alleged agents.

The claim is unverified, but its weight is plain. Criminals in the same circles as ShinyHunters have used stolen data of this kind, phone records among them, to track, intimidate and harass the FBI agents investigating them. A foreign intelligence service would pay for such a map of one of America’s chief law enforcement and intelligence bodies. And in other criminal hands, the data would put agents and their spouses in real danger.

According to a ShinyHunters spokesperson who spoke to The Register, the gang got in through a zero-day flaw in Oracle PeopleSoft on the FBI’s jobs webpage, which it says allowed remote code execution on the servers. It then defaced the site, putting up a banner that read “This site has been seized by ShinyHunters.” At the time of The Register’s report, the jobs page said only that it was “currently down for maintenance but will be back up soon!”

The group says it then moved from the compromised site onto the FBI’s managed servers on AWS GovCloud and downloaded 2 TB to 3 TB of data belonging to current, former and prospective employees. The systems it lists as breached include human resources, MedLink and the Criminal Justice Information Services division. Neither Oracle nor AWS answered The Register’s questions, including whether Oracle knows of a PeopleSoft zero-day of this kind, and the FBI did not respond either.

What makes the episode odd is the price. ShinyHunters is an extortion outfit; its ordinary business model is to steal data and demand millions to keep it private. This time, it says, there is no ransom demand. “This is NOT financially motivated,” the spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.”

The statements at issue are in an FBI bulletin of May 15, issued soon after the gang broke into Instructure’s Canvas platform and claimed data tied to hundreds of millions of students, teachers and staff. The bureau said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” It added that extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.”

The gang says none of this describes it, and that it has attacked the FBI’s own people to make the point. “I have been doing my very best to combat these allegations,” the spokesperson said. “And this is the best way to do it.”

One may note the logic on display. A group accused of harassing families and menacing victims answers the charge by publishing the home addresses of federal agents and their spouses, or claiming to. If the FBI’s bulletin called the gang cruel and its claims unreliable, the gang’s reply, in substance, is to hand the bureau a reason to think itself right. The persons who will pay for this quarrel, if the data is real, are not the officials who wrote the bulletin. They are the agents, and the husbands and wives, whose home addresses are now said to be in a criminal group’s pocket. The FBI had said nothing publicly by the time of both reports.