FBI Investigates ShinyHunters Breach Claim, Plus 4 Stories
There is a very serious FBI breach claim making the rounds this morning. There is also an important difference between what the hackers say happened and what has actually been established.
ShinyHunters says it stole FBI employee data. Here’s what we actually know
The cybercrime group ShinyHunters says it breached the FBI and stole information on nearly all current and former employees, along with people who applied for FBI jobs. The group gave reporters a sample it says contains data on roughly 5,000 agents. 404 Media first reported the claim Tuesday, and Reuters later examined part of the sample.
Reuters says the sample appeared to contain names, home addresses, Social Security numbers, assignments and, in some cases, names of family members. It partially verified details in at least 10 cases, including information associated with FBI Director Kash Patel, using credit-bureau records and previously breached data.
That does not establish that ShinyHunters got into the FBI’s internal network. Reuters says it could not determine where the data came from. The FBI’s statement is narrower still: the bureau says it is investigating claims involving unauthorized activity affecting FBIjobs.gov. The FBI jobs site and Special Agent Applicant Portal were unavailable Tuesday.
That distinction matters. Partially verifying identities tells us the sample isn’t obviously fictional. It doesn’t tell us which system was compromised, how much data was taken or whether the attackers have everything they claim.
The potential harm is real either way. Home addresses, Social Security numbers, work assignments and family information can be useful for identity theft, harassment and targeting. A former FBI official told Reuters that information from a 2016 leak is still used to harass agents a decade later. Stolen personal data has a very long shelf life.
For everyone outside the bureau, there isn’t a useful action to take yet. For affected employees or applicants, the FBI will need to establish the actual scope before anybody can give precise advice. Until then, “ShinyHunters says it hacked the FBI” is a claim under investigation, not a completed forensic report.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
F5’s BIG-IP APM zero-day is already being exploited
This one does come with an immediate action item. F5 disclosed CVE-2026-94127 Tuesday, a critical heap-based buffer overflow in BIG-IP Access Policy Manager. F5 says attackers have already exploited it, and CISA added it to the Known Exploited Vulnerabilities catalog.
The flaw can allow an unauthenticated attacker to send malicious traffic to a vulnerable BIG-IP virtual server and execute code. The important qualifier is configuration: F5 says the vulnerability is present when BIG-IP APM is acting as an OAuth Authorization Server. Deployments using APM only as an OAuth client or resource server aren’t affected by this particular flaw.
OAuth is the system that lets one service authorize another without handing over the user’s password. An authorization server is the piece that issues those access tokens. In this case, malformed traffic can trigger a memory corruption bug in the component processing that traffic. “Buffer overflow” is old-school terminology, but there’s nothing quaint about unauthenticated remote code execution on an edge appliance.
Affected branches include BIG-IP APM 17.1.0 through 17.1.3, 17.5.0 through 17.5.1, and 21.1.0 before the relevant hotfixes. CERT-EU recommends preserving forensic evidence first, applying the F5 hotfix, and then checking for indicators of compromise. F5 also has a temporary iRule mitigation available through support if a hotfix can’t be applied immediately.
CISA gave federal civilian agencies until September 25 to remediate it. That’s a three-day clock, which is a pretty good indication of how seriously an actively exploited internet-facing vulnerability should be treated.
If you administer an affected BIG-IP system, don’t just patch and declare victory. Check the configuration first to see whether the vulnerable OAuth authorization-server role is actually in use, preserve useful logs, apply the fix, and review F5’s indicators. A patch prevents the next attempt. It doesn’t prove the last one failed.
AI shopping agents are getting close enough to your wallet that banks are nervous
Several large banks are warning that AI shopping agents are moving faster than the payment protections around them. NatWest, Bank of America, ING, Capital One, Commonwealth Bank of Australia and ASB Bank are among the institutions calling for clearer rules as AI assistants move from recommending products toward actually making purchases.
This isn’t a hypothetical market. British retailer John Lewis says searches coming from AI agents rose from 0.3% to 2.5% in a year. OpenAI, Anthropic, Google and Meta are all building toward agents that can select products and transact for users.
Choosing a toaster and spending your money are different job descriptions.
The banks’ concern is what happens when an agent requests card details, enters them into a merchant site, chooses a payment method with weaker protections, buys the wrong item, gets manipulated by a scam, or simply spends more than the user intended. Consumers may not know whether the bank, merchant, AI provider or payment network is responsible when something goes wrong.
That’s the interesting part to me. Agentic commerce doesn’t merely need a smarter recommendation engine. It needs boring things like identity, authorization, spending limits, receipts, dispute handling and a reliable record of what the user approved. Those are the parts of commerce we notice after they fail.
The banks are proposing disclosure when an AI agent participates in a transaction, stronger data safeguards, more transparency and interoperability. That’s still a policy proposal, not a settled standard.
This also follows Sunday’s Raymond Tec News discussion of Amazon blocking Meta’s Muse agent from shopping on its site. The same trust problem keeps showing up from different directions: an agent may be acting for a real person, but websites, banks and merchants still need a way to know what that agent is allowed to do.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
BigCommerce’s Ribon incident is another third-party trust problem
BigCommerce is notifying merchants after credentials belonging to the third-party Ribon and Ribon 1.5 apps were compromised. BigCommerce says the credential theft resulted from a compromise at Fastr, the company behind Ribon, and that the stolen API access was used between September 13 and September 17.
The attackers used that access to retrieve shopper data and inject malicious scripts into a small number of merchant storefronts. UK retailer Master of Malt says exposed customer information included names, email addresses, phone numbers and shipping addresses. BigCommerce says payment-card data and account passwords are stored separately and weren’t exposed through this incident.
Just as important: BigCommerce says its core platform wasn’t breached. The attackers compromised a key held by an installed third-party application and then used the permissions that application already had.
That may sound like a distinction written by a lawyer, but technically it’s the whole story. An integration key is authority. If an app can read customer records or alter storefront behavior, whoever steals that app’s credential may inherit the same abilities without breaking into the ecommerce platform itself.
BigCommerce removed the affected applications from merchant stores to revoke access and has been providing logs to affected merchants. If you received a notification, the useful response is to review the supplied logs, check storefront scripts and app activity during the affected period, and follow whatever customer-notification requirements apply to the data that was actually exposed.
This is also very close in spirit to Saturday’s Brevo supply-chain incident. Different mechanism, same uncomfortable lesson: you can secure your own server beautifully and still inherit risk from software and services you intentionally trusted.
Automation & integrations
If somebody in your business keeps copying information from one system into another, there’s a decent chance the computers should be doing it instead. Raymond Tec builds integrations and automations around the systems businesses already use.
Britain may put ChatGPT and Perplexity on Google’s search-choice screens
The UK Competition and Markets Authority proposed new rules Wednesday that would require Google to give Android and Chrome users more control over their default search provider. That alone isn’t especially surprising. The interesting part is what the CMA now considers a search provider.
Under the proposal, AI assistants that meet technical and security requirements could appear alongside traditional search services on the choice screens users see when setting up Android or opening Chrome. The examples Reuters gives are ChatGPT and Perplexity. Users would also be prompted once a year to reconsider their default.
The CMA also wants search providers to fairly attribute publisher content so people can identify and reach the original sources. The proposal is open for consultation through October 9, with a final decision expected by the end of the year, so nothing changes on anyone’s phone this morning.
Still, this is a useful marker. Regulators are no longer treating conversational AI and web search as completely separate products. People are already using assistants to answer the question they once typed into Google, and policy is starting to catch up with that behavior.
For publishers and small businesses, that shift matters because discovery is changing with it. Being the best blue link on a results page is one thing. Being the source an AI system chooses to cite, summarize or recommend is something else, and nobody has finished writing the rules for that market yet.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- 404 Media: “We Hacked the FBI:” Hackers Say They Have Data on All FBI Employees
- Reuters: ShinyHunters hackers say they breached FBI, stole data on bureau employees
- CERT-EU: Critical Vulnerability in F5 BIG-IP APM
- SecurityWeek: Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
- Reuters: Banks warn AI shopping bots raise scam, fraud and data-privacy risks
- SecurityWeek: BigCommerce Data Stolen via Ribon Apps Hack
- BleepingComputer: BigCommerce alerts merchants of data breach linked to Ribon apps
- Reuters: Google faces UK push to put AI assistants on Android, Chrome choice screens
