A sample of 5,000 alleged agents seen by 404 Media includes names, addresses, phone numbers, and details on FBI employees' spouses.

816 points•spenvo•8 days ago•614 comments•

614 comments

jacobgold8 days ago
At this point, no one seems capable of keeping a large database safe. I assume all medical and biographical information that exists is in the hands of the major state actors.

China hacked 22.1 million records of US government employees:

https://en.wikipedia.org/wiki/2015_Office_of_Personnel_Manag...

coldpie8 days ago
It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks. If you have a computer and it is connected to a network with access to the Internet, assume that computer is semi-public. Meaning, if someone was interested enough in accessing your computer, they could do it. Do not hook any computer with access to anything that would be devastating if it was made public to the Internet. Do not put anything that would be devastating if it was made public onto someone else's Internet-connected computers.

For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

The correct analogy for computer security is not locks and keys and doors and gates. It is a house in a floodplain. Your house will not survive the flood of it hits you. Do not store anything critical or irreplaceable in that house.

josephg8 days ago
> It is unthinkable to me that anyone believes there is such a thing as computer security after so many years of nonstop hacks and leaks.

Of course there is. For example, SeL4’s security and reliability proofs still hold in the world of LLMs. The problem is that most software isn’t written on that firm foundation. Instead, most software is made by people with the philosophy of “if it looks like it works, ship it”. You don’t get secure software by working like that, because security vulnerabilities aren’t visible.

We - humans - know how to write secure software. Just like we know how to make safe aeroplanes. The problem isn’t that we lack the capability to make secure computers. The problem is we don’t have a culture of security. Secure software is - somehow - niche. And as such, it’s much more expensive. And nobody wants to pay.

tsimionescu8 days ago
> For example, do not hook your goddamn water or traffic or electricity infrastructure up to the goddamn Internet, and then, do fire the guy who suggested it.

Ask the Iranians how impenetrable even physical isolation actually is - their centrifuges were still destroyed even though they were air gapped (the infamous Stuxnet). Ultimately all computerized systems are vulnerable to sufficiently determined cyber-adversaries.

You also need to make various cost-benefit analysis decisions for all of these things. Does the extra security you gain by keeping your system disconnected from the Internet actually increase all-around availability and resilience?

In particular, integrating highly variable power sources like solar and wind into the grid requires much more complex synchronization between producers, storage, and consumers in order to function properly. Trying to build a renewable grid without Internet access is doomed to extremely inefficient, if possible at all. Building an alternate network would be extremely expensive and ultimately useless (since every house in the country needs to connect to it, it would be just as vulnerable as the actual Internet anyway). So, ultimately you must connect your power grid to the Internet to actually provide service, despite the security risks.

Perhaps the situation with the water supply or traffic is different, so maybe this is not as applicable.

shepherdjerred8 days ago
It used to be that nothing was secure but that was OK because at least adversaries would have to expend effort. If you are one of a million companies why would anyone hack you. Maybe if you are a target you need a lot of investment, but most orgs only prevent the most egregious of vulnerabilities.

The calculus has certainly changed. Hacking is becoming even more frequent and… I’m not really sure what the equilibrium looks like.

It’s not really an option to stop using computers or networks. But it’s going to be way too expensive (or maybe even impossible) to secure even just critical systems.

Maybe banks and governments can secure themselves (and that’s a big IF) but it really feels like something fundamentally has to change.

Aurornis8 days ago
> It is unthinkable to me that anyone believes there is such a thing as computer security

Nobody I know in security hardening or vulnerability research has ever believed that anything is perfectly secure. It's not black and white. There are degrees to this.

I find this fatalistic thinking that every database should be assumed compromised to be subtly harmful. Everyone I know who thought that way waltzed right into lax security practices. "Good enough, what's the point, if anyone wants it bad enough they're going to get it anyway"

GolfPopper8 days ago
Many years ago, I regularly played cyberpunk tabletop RPGs with a number of other computer-inclined friends. We all used to laugh at ridiculousness of a key assumption of the game - the idea that giant corporations would ever connect their internal networks, full of valuable data, to the larger global telecommunications network.
tyre8 days ago
Yes, huge amounts of your medical information is for sale. In 2024, Change Healthcare (CHC) was hacked and held ransom. The hackers were in the system for over a week before everything was pulled offline.

CHC is the largest claims clearinghouse in the US; about 100m people's insurance claims go through there each year.

The hackers asked for a ransom ($35m iirc) to delete the data, which United Healthcare (who owns them, because of course they do) paid. But it seems that the collective negotiating on behalf of the actual hackers rug pulled, so the actual hackers didn't get paid.

This is more than simply medical records. It includes who is active duty military and their family. If you can map where soldiers are, you know roughly the size of different military bases. If you know which types of capabilities are operated out of which bases, you can get a pretty good look of how the US is allocating personnel.

It was crazy working on recovery from this at the time. It should have been front page news, but wasn't.

AndrewKemendo8 days ago
Where can I learn more about the rugpull?
casey27 days ago
Why would that be front page news? You can literally buy tracking data for soldiers in the field, not from hacks from Google, study their movement patterns as much as you want. This has already been done and resulted in attacks.
titzer8 days ago
And the city wonders why I don't want to put my credit card info in their crappy parking app and would instead prefer to put a quarter into the meter for 30 mins.
lotsofpulp8 days ago
What info can be gleaned from that? Surely the mere fact that you have a credit card means your name and billing address are floating around.

I guess your parking history around town could be valuable if someone is targeting you.

MrDrMcCoy8 days ago
That what services that offer disposable and merchant-locked virtual cards are for. I have had good experiences with Privacy.com and Revolut.
buildsjets8 days ago
Not just government employees, employees of government contractors who held or applied for security clearances. I’ve never worked for the government but the CCP got my SF-86. My employer’s infosec group told us they believe that the same group was also responsible for the Mariott data breach in the same timeframe and that it was believed to be part of an effort by the CCP to establish a complete dossier on each individual in the entire military-industrial complex. The best advice they could offer was to disable all social media accounts and lock down our credit reports. :shrug:
Transformanshen8 days ago
The fatalism is understandable, but "no one can keep a database safe" isn't quite right. Some organizations do a better job than others.All in all, of course, the best way to keep information secret is to keep it only in your own head, all other methods are less reliable
avinoth8 days ago
Rookie move. Missed the chance to claim that an AI Agent swarm hacked it autonomously and claim billions of VC investment.
estetlinus8 days ago
Loaned money is the new proxy for self-made success
almazglaz7 days ago
And also dodge legal issues.
ngruhn8 days ago
It's terrifying to me that posts like this keep getting upvoted so much here. It's akin to climate change denial. The risk of rogue agents is real. And it's made worse if everyone beliefs this is just a marketing stunt.

The HuggingFace incident was audited by independent third party analysts. To "orchestrate" that and keep it a secret is like faking the moon landing. To many people involved. It's not feasible.

OpenAI was founded to develop safe AI. Then Anthropic split off because OpenAI was not safety focused enough. These companies have been railing about AI safety long before they had these big boy valuations. Many people at OpenAI/Anthropic explicitly joined to help make AI safe. This is not some top-down company value.

Also, I seriously doubt that "making panic" is actually good for the stock price. Usually any companies natural reflex is to cover up safety risks. That's not to say that these companies are angles. Of course they're pulling some shit but that doesn't mean that everything out of their mouths must be lie.

avinoth8 days ago
It is not an allegation that they've faked it, or that there is no risk of rogue agents. I'm alluding to the scenario where the supposedly illegal/immoral activities are rewarded with increased valuation and funding as long as they are done with AI Agents rather than curtailed & punished.

Right after the HuggingFace incident, we all saw how every company clamored to claim how their AI models have also broken out of Sandbox, and hacked some stuff. As ridiculous as it was, they all used that to demonstrate their model's capabilities.

probably_wrong8 days ago
I don't think you're being objective either.

Yes, HuggingFace was audited by a third-party. But said third-party wrote that they had to use unreliable AI in their conclusions (page 26) because they had six days to analyse 1300 (page 70) chains of thought and 70000 messages.

> OpenAI was founded to develop safe AI.

If that were the case, then they would have followed their own report saying not to release GPT-3. Or, if they were following their own founding principles, they wouldn't have stopped releasing models due to (in their own words) the challenging market.

dgellow8 days ago
There is no such thing as rogue agent. None of the security issues so fare have anything to do with an agent going rogue. That framing is pure marketing nonsense to avoid legal liabilities for committing what is very likely felonies.

That doesn’t mean the AI vendors doing reckless testing isn’t itself dangerous, it very much is

TrickyRick8 days ago
Nobody (sane) is claiming it was faked. What sane non-AI-pilled people are claiming is "Our AI agent went rogue and hacked another company" is a much better story for the stock price than "Our human engineers screwed up a very basic sandboxing and allowed the agent access to things it shouldn't be able to access, and also they screwed up the task in the first place by accidentally giving the agent an impossible task". Only the latter reflects reality, the former is a marketing pitch.
xgulfie8 days ago
> I seriously doubt that "making panic" is actually good for the stock price

Given the "AI race" narrative, it makes them indespensible to the US government and too big to fail. An investor's dream

dyauspitr7 days ago
Trying to minimize it doesn’t make it less true.
reactordev8 days ago
There’s a scene in Battlestar Galactica (2004) where someone asks Captain Adama why the Galactica doesn’t have networked computers. So the cylons can’t hack the ship…
ishouldstayaway8 days ago
It's not just a scene; it's the whole premise of the setting. It's why the Galactica survived and the newer ships did not. It's why the new Vipers got wiped out and they had to pull the old ones out of mothballs.

In the pilot, the Galactica was literally being turned into a museum, and that's why they lived.

netcoyote8 days ago
It was even worse: the Galatica was a museum ship, and it was being decommissioned!
283042834092348 days ago
"What do you hear, Starbuck?"
dylan6048 days ago
There's also a scene where they do network the computers and are hacked nearly instantly.
whh8 days ago
I loved the writers giving every firewall its own LED indicator, so we knew exactly how far the toasters had got.
reactordev8 days ago
but thanks to Baltar's firewalls and code obfuscation, just barely are able to escape after calculating the jump and having to literally wipe and reinstall all code on all systems.
jshier8 days ago
Which was always pretty stupid. At best it means the Cylons can't hack the whole ship, just whichever part they exploited to gain access remotely in the first place. But really the Cylons would've needed exploits for each individual system anyway, since simply connecting them with wires shouldn't just do that. And unless those other systems are completely air gapped with no wireless or other access, it would be trivial for them to still gain remote access, or have one of their infiltrators provide a local connection of some kind. AFAIR that was never a plot point, which was odd.
joshheitzman8 days ago
> And unless those other systems are completely air gapped with no wireless or other access

That is exactly the canon.

reverius428 days ago
> whichever part they exploited to gain access remotely

I think you missed the point of "no networking", you have to actually physically sit in front of the computer. There is no remote access.

dyauspitr8 days ago
Have you watched the show because a lot of your assumptions are incorrect.
theplayerofgame7 days ago
They are in space, so they're air gapped by definition. Oh... you mean "air gapped", not "air gapped". Sorry.
binkHN8 days ago
Does this mean we'll see new startups in the sneaker-net space?
wetwater8 days ago
Never underestimate the bandwidth of a station wagon full of tapes hurling down the highway. - Andrew Tanenbaum
gchamonlive8 days ago
I think it's one of the first two special episodes right at the beginning of the series, and it's the sole reason why the fleet could sustain evading the cylons
rdtsc8 days ago
> When asked if ShinyHunters was going to attempt to extort the FBI, the representative said, “what we plan to do is not something I’d call extortion, maybe coercion... This is not financially motivated,” they added

They should try something like "100 agents at noon on Sep 23 do the chicken dance for 30 min in the middle of the street in DC, then we'll consider not releasing the info and not sell it to the Chinese".

Uehreka8 days ago
Man, that quote is gonna suck when it gets read out in the courtroom. Even with the FBI in the shambles it’s in under Kash Patel, if you’re dumb enough to say something like that on the record, you’re definitely not smart enough to evade capture.
jeroenhd8 days ago
It depends on where these people are from.

If they're just a bunch of common crimimals from China or Russia, I doubt they'll appear in court.

American courts are real scary when you live in a country that works together with the USA, but if you don't, all you need is to make sure your crimes aren't worth starting another invasion over.

aprilthird20218 days ago
Let's see in a year if they've been caught or dealt with? I have a feeling Patel is too loaded to even care about this
rdtsc8 days ago
Yup, stealing from the FBI is pretty bold, probably a state sponsored group. Or script kids who got lucky up to that point.
GeorgeOldfield8 days ago
that would brighten my day for once this year
lofaszvanitt8 days ago
Yeah... what could go wrong :D.
rdtsc8 days ago
The worst? 100 FBI agents to do the chicken dance in DC for 30 minutes and then the database is sold to the Chinese
Cider99868 days ago
Full text of Shinyhunters' box on their site about the FBI labeled, "PSA - READ THIS NOW":

https://rentry.co/shtext

>That defacement says, “this site has been seized by ShinyHunters,”

No archive but at least a screenshot: https://cyberinsider.com/wp-content/uploads/2026/09/fbi-site...

>https://news.ycombinator.com/item?id=49807388

The photo they put is a Pokemon so yeah probably their name is from it.

kelvinjps108 days ago
>hinder clients trust in our organisation hoping nobody pays us. I wonder what kinda of clients they have
Cider99868 days ago
I think it means their extortion victims. So we actually know who some of their "clients" are. Like instructure/canvas. We certainly know the ones who "don't become clients" because they are all posted.

They mention hindering trust because for an extortion gang, they want companies to trust that they won't leak the data in order to make it seem worthwhile to pay.

Read the full thread on Hacker News →

Related stories