Skip to content
Live Intelligence
Clash Report
World

FBI's Hacking Unit Was Part of Those Exposed by Hacking Breach

A breach involving data on 5,000 alleged FBI officials included personnel tied to the Remote Operations Unit, exposing personal details linked to one of the bureau’s most secretive technical teams.

Clash Report
A member of the FBI in Orlando, June 13, 2016 - AFP
24 Sept 2026 · 11:06 GMT · 2 MIN READ
Google Search

Choose Clash Report as a preferred source and see our reporting first in Top Stories.

Members of the FBI unit responsible for developing and deploying hacking tools were among personnel exposed in a breach involving thousands of alleged bureau employees, according to data reviewed by 404 Media.

The leaked records include three entries referring to “remote operations units,” potentially identifying personnel connected to the FBI’s Remote Operations Unit, or ROU.

The ROU is a secretive technical team that develops tools used to gain access to targeted devices.

Personal Details Exposed

ShinyHunters, the group claiming responsibility for the breach, provided 404 Media with a list of 5,000 alleged FBI officials.

The records include addresses, phone numbers and employment information. In some cases, the data also identifies spouses and lists their phone numbers.

404 Media said it verified parts of the material using open-source records available through OSINT Industries and previously compromised data accessible through Darkside, a tool developed by cybersecurity company District 4.

One phone number linked to an alleged ROU official was tied through previously breached data to someone who had worked for the Secret Service.

Another entry apparently relates to a “student workforce trainee.”

FBI Investigates Breach

The FBI said it was examining claims that its FBIJobs.gov portal had been compromised, while stressing that it had not established the source of the breach.

The bureau said it “is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII).”

“While the point of breach is still undetermined, whether a third-party or the FBI’s enterprise, we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

The exposed dataset includes job titles and units, along with personal information. Titles cited in the records include Special Agent, Threat Intake Examiner and Major Cyber Crimes Unit.

Reuters reported that some positions listed in the data were linked to investigations involving China or Russia.

A Secretive Hacking Team

Public information on the ROU is limited.

A 2020 report from the Office of the Inspector General said the unit had spent much of the previous decade developing and deploying technical tools for investigations involving the dark web.

The report said the ROU was “instrumental” in developing a network investigative technique, or NIT, used by the FBI to identify visitors to a dark web child abuse site that the bureau operated for two weeks.

The FBI uses NIT as terminology for a hacking tool.

According to the report, budget reductions later shifted the ROU’s focus toward developing tools for national security investigations. Significant portions of the report dealing with the unit were redacted.

Exposure Reaches the FBI’s Offensive Capability

The presence of ROU personnel in the leaked data means the breach may have revealed members of a unit whose composition, technical capabilities and operations are rarely disclosed publicly.

That creates a different level of sensitivity from the exposure of routine personnel records, particularly because the compromised information includes home addresses, phone numbers and family details.

The ROU has also previously used classified hacking tools in ordinary criminal investigations, raising questions over whether defendants could adequately scrutinize the methods used to collect evidence against them.

About the Author

Ahmet Koçak

Clash Report

Ahmet Koçak is a news editor at Clash Report based in Istanbul. He previously served as Deputy Managing Editor at Türkiye Today, helping launch the digital news platform in 2023, and spent three years as Senior Editor at Daily Sabah. His work focuses on breaking news, geopolitics, international affairs, and digital journalism.

Google Search

Choose Clash Report as a preferred source and see our reporting first in Top Stories.

Sources404 Media
0:00
0:00
Now playing · ClashPoint
EP 147

When the front line moves overnight

Guest: Daniel Reyes
0:00
0:00