FBI investigating claim hackers have stolen details of all its agents
The FBI is investigating a claim by a cyber-crime group that it has stolen sensitive information on all bureau staff - around 38,000 people.
The group, Shiny Hunters, says it has every agent's name, role, badge number and personal details including home address, phone numbers and spouse information.
Professor Ciaran Martin, the former head of the UK's National Cyber Security Centre, said - if confirmed - it was "as serious as it gets when it comes to data breaches."
In a statement posted on X, the FBI said it was aware of the claim and the agency was "actively and aggressively investigating the matter".
The criminals claim to have breached the FBI's servers on Monday night and began contacting reporters on Tuesday sharing samples and screenshots of the stolen data.
The BBC has seen a small portion of the data, which appears to be genuine.
According to Reuters, some of the data contains details about officials' job assignments, including sensitive work against Chinese spies, Russian intelligence and drug cartels.
ShinyHunters is an international collective of hackers, believed to have originally started in France. It has been behind a number of high-profile breaches including on Rockstar Games in April and a highly disruptive hack on education platform Canvas in May.
The group claims to have found a vulnerability in the Oracle cloud storage system used by the FBI to breach multiple systems including FBIJOBS, FBI BEAST, which does background checks on employees and applicants, FBI MedLink, which holds agent's medical records and FBI BICS, which holds investigation information.
In its message on the dark web, the group said it did not hack the FBI system for money.
Instead, the cyber-criminals are asking the agency to retract an advisory that it issued in May about the gang, saying it was "offended" by its characterisation.
That FBI's public service announcement, external described ShinyHunters as "threat actors" who often "use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims".
"They target major companies across tech, finance, and retail, often stealing millions of customer records at once," the advisory said.
ShinyHunters said it would give the bureau one week to correct or remove what it says are false allegations or they would publish the full databases.
The FBI did not respond to multiple requests for comment from the BBC.
In its statement on X, the agency said it was trying to determine whether or not the hackers had breached its systems or a third party.
"We are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk," the post said.
In a statement to the BBC, a cyber-security expert said it was a "retaliation attack", which demonstrated that "no organisation is safe from the group".
"The group clearly wants to control the narrative around their activities, ensuring nothing is said that could dent their reputation," said William Wright of Closed Door Security.
Meanwhile Andrew Brandt of cyber-security firm Huntress said it may provoke the FBI to track down and prosecute members of the hacking group.
"ShinyHunters must feel pretty confident they won't get caught to threaten a government agency like this," he said.