'We hacked the FBI:' Hackers say they have data on all FBI employees (404media.co)
jacobgold an hour ago
China hacked 22.1 million records of US government employees:
https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...
Taek an hour ago
1attice 29 minutes ago
redanddead 24 minutes ago
tdhz77 an hour ago
titzer an hour ago
lotsofpulp an hour ago
I guess your parking history around town could be valuable if someone is targeting you.
ceejayoz an hour ago
The card number?
Barbing an hour ago
When your lifetime of credit card transactions leaks, that could be financially painful, embarrassing, etc. (can be discriminated against, including with pricing)
I do dislike creating a log of where I park on some random company’s server. Nice that ALPRs/govt.-funded corp spycams/Ring/etc. make sure the quarter method is minimally marginally effective at protecting privacy.
ceejayoz an hour ago
I had to fight a bank for months over a clearly fraudulent charge. Sometimes it's easy; other times it isn't.
chrsstrm an hour ago
dylan604 an hour ago
bluGill an hour ago
asdff 14 minutes ago
dylan604 13 minutes ago
pixl97 30 minutes ago
One, how much money is in your pocket so you can eat?
ok, you'll use your second ca.... oh, it has to be cancelled now too.
Ok, lets wait a few days for another card, and lets go use it the first time, what hacked already, I guess I need to wait a few more days.
>As long as you're not using a debit card, this is not a big deal.
So screw 60% of all transactions done on a card? This doesn't seem workable.
dylan604 an hour ago
ceejayoz an hour ago
Consumers aren't gonna notice the difference if the site gets hacked and that JS is swapped out for a malicious set.
pixl97 28 minutes ago
dylan604 11 minutes ago
ceejayoz 6 minutes ago
"I'm only talking about long-term storage" is itself a goalpost move!
simur an hour ago
ChosenEnd an hour ago
coldpie an hour ago
For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.
The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.
sippingabonedry an hour ago
passwordoops an hour ago
Does this answer your question?
/s
sippingabonedry 44 minutes ago
People flaunting their credentials in multiple languages, then sweating bullets and apologizing profusely when they see
int t = 4;
You can either code or you can't; the language is merely a vehicle.BoxwoodSeed 22 minutes ago
It might even help in figuring out whether Haskell would be a good fit. Something I couldn't do, as I do not know the language. Then again, it's not a question that really gets asked much in a corporate setting. Most things are just solved in a few popular languages, whether that makes the most sense or not.
shepherdjerred an hour ago
The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.
It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.
Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.
throwup238 43 minutes ago
Admiral Adama says otherwise.
shepherdjerred 35 minutes ago
Even just consider banks and e-commerce. They are hugely lucrative and making them even a tiny bit less accessible directly impacts their revenue. As an example, Amazon seeing that latency has a measurable effect on purchase behavior.
Maybe the military (fictional or otherwise) can go back to the ARPANET but most economic activity created by the internet cannot afford to disconnect
SilentM68 34 minutes ago
pixl97 32 minutes ago
In the real (fake?) world the toasters would shoot smart dust all over your crap that would assemble back on your circuits creating radios between all the different components. They were fighting an adversary that was far more advanced than them.
kridsdale1 15 minutes ago
BoxwoodSeed 35 minutes ago
If there's too much security in the way, it seems to me that work becomes impossible.
coldpie 26 minutes ago
pixl97 34 minutes ago
Adding AI into this really is just changing it to how much money your adversary is willing to spend to break in. The moment one crack in the armor shows up countless agents with unending patience can start embedding themselves everywhere in timeframes way faster than human actions. You could quickly find out all the special sauce for your company has been copied who knows where.
Working with banks when the Glasswing/Mythos first came out and they were given access to it has given me direct access to their infosec departments that are panicked. They've been sitting on piles of bugs for years that were low risk enough, and they have seen in their own tests how fast they can be probed.
Worse those infosec systems that have identified the risks in their software that aren't yet fixed are nuclear waste vats just waiting to get spilled to the wide world.
skybrian 30 minutes ago
drdaeman 21 minutes ago
Remove the complexity (all the way down to the hardware quirks), and security will be doable again.
GolfPopper 19 minutes ago
shockwaverider 15 minutes ago
sekh60 11 minutes ago
josephg 10 minutes ago
Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.
We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.
kakacik an hour ago
primitivesuave 44 minutes ago
clickety_clack 7 minutes ago
reactordev 2 hours ago
mikeyinternews 2 hours ago
mjhagen an hour ago
gchamonlive an hour ago
ishouldstayaway an hour ago
In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.
28304283409234 an hour ago
ronburgandy28 33 minutes ago
jshier an hour ago
joshheitzman an hour ago
That is exactly the canon.
reverius42 an hour ago
I think you missed the point of "no networking", you have to actually physically sit in front of the computer. There is no remote access.
dylan604 an hour ago
corvad 2 hours ago
ctkhn an hour ago
paimapi an hour ago
tencentshill 3 hours ago
Perhaps firing expertise and hiring incompetents wasn't a good idea.
nateb2022 2 hours ago
lenerdenator 2 hours ago
nateb2022 2 hours ago
AI now makes it possible to build this kind of software in-house, offering a 2nd choice, though it'll only be as good as the standards of the teams using it. Only time can tell.
sarchertech 2 hours ago
Bespoke software can be orders of magnitude less complex. There are many reasons companies choose to use vendor solutions, but for large organizations it’s usually not “we literally can’t hire enough engineers to build it.”
There are so many counter examples.
0cf8612b2e1e 2 hours ago
nateb2022 an hour ago
Not in government. For payroll/HR, we're talking about hundreds of pages of legislative mandates, union bargaining rules, Title 5 statutory compliance, and FISMA/NIST regs. Just customizing something like PeopleSoft to fit is a large task in itself, let alone trying to implement bespoke software using an engineering pool that isn't even large enough to modernize the software it currently owns.
Bespoke sounds nice and works well in startups but that's not the context we're discussing. Check out Phoenix Pay: https://en.wikipedia.org/wiki/Phoenix_pay_system and understand the US is even more complex.
Zigurd 2 hours ago
quickthrowman an hour ago
mc32 2 hours ago
lenerdenator 2 hours ago
It's okay. Larry got another island.
jmclnx an hour ago
If anything Oracle will "contribute" a lot to congress people's midterm reelection and in a few months all will be forgotten and Oracle will get more Gov. contracts.
dylan604 an hour ago
Do they have any positive reputation left, or is it just more negative from the previous negative position?
jandrese 43 minutes ago
Tangurena2 32 minutes ago
Betelbuddy 2 hours ago
rayiner 2 hours ago
freejazz an hour ago
consumer451 an hour ago
baggachipz 2 hours ago
classified an hour ago
debo_ an hour ago
Bengalilol 23 minutes ago
sippingabonedry an hour ago
The expertise that told them to buy PeopleSoft years ago, or do you actually believe the FBI home-rolled its own HRMS in the last year?
Are they related to the expertise that was supposed to lead to the immediate, irreparable offlining of Twitter after they were all fired?
TutleCpt an hour ago
johnnyApplePRNG an hour ago
Tangurena2 31 minutes ago
autoexec 6 minutes ago
JumpCrisscross 5 minutes ago
1970-01-01 an hour ago
1992 was 33 years ago; this is almost an unremarkable event. It will be superseded by whatever happens in AI news by the end of the month.
whynotmaybe an hour ago
That's lot of data for a list of employees.
AraneaDev an hour ago
Tangurena2 26 minutes ago
We as a country need to start treating PII as radioactive - that touching it or keeping it anywhere near your computer network is a company-ending disaster about to happen. The legal standard needs to be strict liability like CSAM or DUI.
asdff 12 minutes ago
Well, that would require such leaks to result in a company ending disaster. Instead they keep chugging as normal and the customers who got their information leaked don't even move off the platform for greener pastures. What a boring dystopia we live in.
Buttons840 30 minutes ago
This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?
Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.
pixl97 27 minutes ago
smalltorch 4 hours ago
If your systems are compromised and need to coordinate, what do you even do if you can't trust anything, assuming the attacker is still inside the network?
lenerdenator 2 hours ago
If the goal is to exfiltrate data, I guess it is. If the goal is to make the people working in the FBI feel vulnerable - and pushing out this sample data would suggest that it is - I don't think it is. You could probably do the same with data from social media sites and data brokers.
smalltorch 2 hours ago
Consider open investigations with covert agents. Leaking their identitys could compromise entire investigations.
Hopefully there was some foresight in washing undercover agents from these systems to other secure ones or something otherwise that's pretty bad.
dylan604 an hour ago
Are you saying that Ethan Hunt was involved?
Joel_Mckay 2 hours ago
dvh 2 hours ago
Joel_Mckay 2 hours ago
corvad 2 hours ago
john_strinlai 2 hours ago
augment_me an hour ago
steveBK123 an hour ago
Wondering about pets..
KronisLV 2 hours ago
dgellow 4 hours ago
ben_w 2 hours ago
Of course if I was the FBI, I would make it so hackers trying to breach the system get a honeypot where all the data is fake, and with LLMs (even poor ones) it would be very easy to fake an entire alternative reality.
S-E-P an hour ago
alexjplant an hour ago
Tangurena2 25 minutes ago
S-E-P 16 minutes ago
iAMkenough 2 hours ago
https://www.tomshardware.com/tech-industry/artificial-intell...
giancarlostoro 2 hours ago
Apocryphon an hour ago
bearjaws an hour ago
Every day 2 major organizations get hacked, whether by groups or state actors, and America continues to sit on its hands.
The government should be creating a new digital defense department to better defend our country, and fund the defense of our nation, but instead it is busy renaming lakes and renaming "AI".
Almost like its run by a bunch of 80 year olds...
kelseyfrog 3 hours ago
TZubiri 2 hours ago
clint 2 hours ago
bitwize 2 hours ago
mech422 2 hours ago
yepyoukno an hour ago
They say glowie because they see Jews are n*s who are white. They “glow” (they’re not dark.)
It’s crazy hearing main stream mention this slur slang without awareness of its root or meaning.
phainopepla2 an hour ago
DaSHacka an hour ago
https://www.urbandictionary.com/define.php?term=Glowie
The term itself has nothing to do with jews, but its a fun self-report you think jews are disproportionately federal agents, the group constantly mired in human rights controversies towards minorities and abnormal connections to pedophiliac islands as of late.
Horseshoe theory, I suppose :)
levocardia 2 hours ago
DaSHacka an hour ago
There are many people that run open weight LLMs. And unsurprisingly, they don't all have a copy of the FBI employee database.
If you mean "using" an open weight LLM in combination with other tools or even potentially frontier models, then that's a lot more likely.
fwip 7 minutes ago
jgalt212 2 hours ago
Ancapistani an hour ago
Qilin allegedly hacked BATFE about a month ago, and the files were never posted to their site.
Jamesbeam an hour ago
Oracle enterprise applications are a gold mine for attackers precisely because nobody treats them as security-critical systems.
In 2025 the Clop ransomware gang discovered that Oracle E-Business Suite has a critical vulnerability (CVE-2025-61882) that allows unauthenticated remote code execution.
Graceful Spider (tracked as Clop affiliates) started exploiting this in early August, well before Oracle issued a patch in October. That’s a two-month window where attackers had free rein.
All you need to know about Clop is that they got fucked by SH as well just a few days ago.
ShinyHunters defaced Clop's Tor leak site and added its own branding and messages. SH claims it stole source code, system logs, plugins, and Tor onion service keys. SH says it plans to give Clop 72 hours to respond to an extortion message.
Say what you want but these kids got balls. Won’t help them once SOCOM starts dealing with them, but they had a good run so far. I think hacking the FBI is as close as you can fly to the sun before the hammer drops.
In February this year they breached Wynn Resorts and lifted data on 800,000-plus employees. Can you guess the entry point?
If you guessed Oracle PeopleSoft, you were right.
Now you’d think the FBI IT people would have noticed that oracle software is a potential national security risk, if multiple ransomware groups keep focusing specifically on the shit Larry Elison personally have to seem vibe coded, over and over.
But Ka$h replaced most of the competent people at the FBI with Ka$h people and by pure luck Oracle won a $396m HR government contract this summer. Who wouldn’t want to supply the most secure software product to manage some of the most sensitive data within the agency, if not the Oracle Moscow branch.
https://mesoclever.com/2026/06/11/oracle-wins-396m-hr-contra...
They even mentioned in the above June article:
> Separately, the cybercrime group ShinyHunters claimed to have exfiltrated student, financial-aid, immigration, health, and administrative records from PeopleSoft instances at more than 100 organizations, predominantly universities. The group stated it had previously targeted an *FBI PeopleSoft server* before pivoting to educational institutions already compromised in earlier campaigns. Oracle has not publicly confirmed the scope or remediation status of these incidents.
So the FBI knew, and had it coming, and if stuff like this happens, THE HEAD needs to roll. And all of his buddies in IT should permanently get to spend their time outside the government at the seafood buffet at Ka$hs favorite gentleman’s club as well.
Fookin Big Idiots.
Simulacra 2 hours ago
applfanboysbgon 2 hours ago