|
Getting your Trinity Audio player ready...
|
TL;DR: Data hackers have been on a roll recently, as the FBI warned its employees to assume hackers already have their personal data. Meanwhile, Singapore experienced its first AI-related data breach this year. Elsewhere in the United States, the Arizona Court said that a cyberattack may have exposed 1.3 million records of personal data, as a new report revealed that 9 in 10 Americans encountered a cyber scam.
Key Takeaways:
- The FBI told employees to assume their data had been exposed after ShinyHunters claimed it had stolen 2 to 3 terabytes from FBIjobs.gov.
- ShinyHunters claims it holds names, phone numbers, home addresses, and spouse details for nearly all FBI agents and applicants.
- Singapore’s PDPC confirmed its first AI-related data breach, exposing the email addresses of 95,364 Bee Cheng Hiang customers.
- Arizona Courts warned about 1.3 million people that their names, case numbers, and Social Security numbers may have been exposed.
- Consumer Reports found 90% of U.S. adults surveyed had encountered a cyber scam or attack, and 17% said they lost money.
FBI warns employees that hackers may have already breached their personal data
On September 29, the Federal Bureau of Investigation (FBI) released a memo reportedly telling employees to assume that a hacker group called “ShinyHunters” had stolen their personal data following the breach of FBIjobs.gov, Reuters reported.
ShinyHunters said it holds data on almost all FBI agents and on everyone who applied for FBI jobs on the agency’s platform, according to the FBI. The hacker group claimed 2-3 terabytes of data from FBI agents, which includes names, phone numbers, home addresses, and even spouse details.
The intrusion reportedly began on the night of September 21, and by September 22, visitors to FBIjobs.gov saw a banner that read, “This site has been seized by ShinyHunters.”
“We hacked the FBI. We hold data on all FBI employees and applicants,” a ShinyHunters representative told 404 Media.
The group added that they made their way in through a previously known bug in Oracle’s PeopleSoft—software that an organization uses to run HR. In cybersecurity, people commonly call this “Zero-Day” a bug the vendor doesn’t know about. However, this information has not yet been confirmed by the FBI.
According to reports, an FBI advisory triggered the ShinyHunter’s hack. On May 15, the FBI warned that ShinyHunters uses “real or exaggerated claims of access” that hold victims and sometimes family members to “commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.”
ShinyHunters denied the swatting allegations and told Axios that “low-skilled threat actors” borrowed their name. They also told The Register that it gives the FBI one week to retract its warning.
Following the recent breach, Cyber Division Chief Brett Leatherman posted a video on X on September 29, claiming that they “know how to find” the hackers. He even urged them to “reach out first while the choice is still yours.”
100,000 customers exposed in first AI-related data breach in Singapore
Elsewhere in Singapore, nearly 100,000 customers of Bee Cheng Hiang—a famous food company in the city-state—were exposed in an AI-related data breach, which Singapore’s Personal Data Protection Commission (PDPC) said on September 30 was the first of its kind in the city-state, Channel News Asia (CNA) reported.
“The incident was caused by a human error in developing the email distribution code with an AI tool,” the PDPC told CNA.
The breach occurred in April, following a Bee Cheng Hiang employee’s use of an AI tool to generate a Python script for its marketing email. The code made the recipients’ email addresses publicly visible, affecting 95,364 customers.
The PDCP clarified via its website post on September 21 that the incident was “not a malfunction in the AI tool,” but a result of the AI prompt the employee used. In which they explained that the staff prompted the AI tool to write a program to send a “mass email using a local list” without specifying to hide the email addresses of the other recipients.
“The employee did not realise the error before deploying the script, as testing was done by checking activity logs without reviewing the contents of the actual test email,” said PDPC.
“[The affected data] was not managed, processed, or generated by any AI-powered operation or process,” it added. They also said that there was “no evidence of further misuse” of the data.
The Commission said that the company has already taken remedial actions, including immediately stopping the bulk marketing email distribution, correcting the script, and informing affected customers.
“Prior to adopting AI tools to enhance the efficiency of their business operations, organisations should carry out appropriate data protection impact assessments; develop policies and processes; and implement testing and review mechanisms, to ensure that their employees use AI tools responsibly and safeguard personal data,” it said.
Arizona Court: Cyber attack may have exposed 1.3 million people’s data
Another data breach occurred in Arizona last week, with the U.S. state court system alerting about 1.3 million people that their personal information may have been compromised during a recent cyberattack.
“Last Thursday in the afternoon sometime, when we received notification from a security vendor that we have, who said that, ‘Hey, it looks like a lot of documentation is being downloaded from one of your servers.’ So, because it was an inordinate amount, we immediately shut it down to try to then see, well, what’s happening with that,” Chief Justice of the Arizona Supreme Court Ann Timmer said.
“From what we have determined so far, it appears that an employee was searching for something and thought that a legitimate link came up, but it was something masquerading as the legitimate link, clicked on it, and that was it.”
According to the court, three data sets were identified as copied during the cyberattack, with one of the datasets coming from the statewide FARE Collection Program, which helps courts collect unpaid court-ordered debt, such as fees, fines, and victim restitution. The court said the data that was breached included names, case numbers, and the victims’ Social Security numbers.
At the time of writing, the forensic investigation is still ongoing, and the explanation of how the attack happened is not yet clear.
Officials said that the information was copied from a backup server, wherein data is highly compressed. Following the breach, some Arizona residents with protective orders were contacted.
The Arizona Court said it has found no evidence that the affected data was accessed, read, or shared with anyone. Notifications are still going out to those who may be affected. People in the FARE program are said to receive notifications via text, while a warning has been added to collection notices through the mail.
Officials also recommend that people who may be affected consider placing a fraud alert on their credit accounts or freezing them.
9 in 10 Americans encountered cyber scam as AI fuel fraud: Consumer Reports
According to a new “Consumer Cyber Readiness Report” by Consumer Reports, Aspen Digital, and the Global Cyber Alliance, nine in 10 Americans have been targeted by cyberattacks and scams, with 17% saying they’ve lost money to a digital security breach.
Experts noted that AI is lowering the barrier to carrying out fraud that was previously costly and complex. “The tech is driving more data breaches because it allows scammers to quickly synthesize information, which they use to create personalized traps,” one expert told CBS News.
“People have stereotypes about who gets scammed, but it is truly everyone now, and AI is just going to accelerate that,” Stacey Higginbotham, a Consumer Reports cybersecurity fellow, told CBS News. “I don’t think we’ve seen even the beginning with the number and quality of scams reaching people.”
“AI is making fraud faster, cheaper and more personal, and no one can outsmart that alone. Companies need to be held accountable. Governments need real guardrails. That’s the bar we’re setting – for ourselves and for them,” Consumer Reports president and CEO Phil Radford said.
In its survey, Consumer Reports found that 90% of nearly 5,000 U.S. adults it polled in March and April said they had encountered a digital scam or cyberattack. Another survey found that consumers are increasingly concerned about the safety of their personal data, including financial account hacks.
In conclusion, Consumer Reports highlighted the need for multi-factor authentication and encouraged everyone to practice good password hygiene. In addition, they pointed out that governments have a role to play too.
“Enacting proposed laws such as the bipartisan SCAM Act or New York’s False Social Media Advertising Prevention Act would hold social media platforms accountable for turning their sites into a playground for scammers and make it easier for consumers to report fraudulent and scammy activity,” they said.
FAQs:
Did ShinyHunters hack the FBI?
ShinyHunters claims it did, and the FBI told employees to assume their data is compromised. The FBI has not confirmed how the intrusion happened or how much data was taken.
What data did ShinyHunters say it stole from the FBI?
The group claims to have 2 to 3 terabytes of data, including names, phone numbers, home addresses, and spouse details for nearly all FBI agents and job applicants. These claims remain unverified.
Who is ShinyHunters?
ShinyHunters is a hacking and extortion group that sells stolen databases and helped run BreachForums. It claimed about 1.5 billion Salesforce customer records in 2025.
What was Singapore’s first AI-related data breach?
It was a Bee Cheng Hiang breach announced on September 30. An employee used an AI tool to write a marketing email script that exposed 95,364 customers’ email addresses.
Did AI cause the Bee Cheng Hiang breach?
Not directly. The PDPC said it was not an AI malfunction but a result of the employee’s prompt, which never asked to hide recipients’ addresses.
How many people were affected by the Arizona Courts’ cyber attack?
About 1.3 million people may be affected. The data includes names, case numbers, and Social Security numbers. The court found no evidence that it was accessed or shared.
How many Americans have encountered a cyber scam?
9 in 10, according to Consumer Reports. About 90% of nearly 5,000 U.S. adults polled said they had encountered a digital scam or cyberattack.
How can I protect myself after a data breach?
Place a credit freeze or fraud alert on your accounts, turn on multi-factor authentication, and use strong passwords. Be wary of unexpected calls, texts, or links.
Watch: Cybersecurity fundamentals in today’s digital age with AI & Web3




