The FBI Confirms Its Jobs Portal Was Compromised but Not What Was Taken

The compromise is confirmed. The route in and the alleged theft of employee data are not. The distinction matters because recruitment systems hold unusually revealing records.

The compromise is confirmed. The route in and the alleged theft of employee data are not. The distinction matters because recruitment systems hold unusually revealing records.
The takeover proved control of what visitors saw. It did not by itself prove possession of Clop's server logs, source code or Tor private keys.

A working app can still expose a key to private systems. Anthropic describes a 1.8 million-APK credential hunt in Claude-assisted criminal operations, while separate cases show how quickly stolen tokens can become wider access.

The passkey was only the pretext. Microsoft says attackers are calling personal phones, capturing cloud sessions and quietly collecting files and email for hours or days.

Jack Henry says ShinyHunters used vishing to enter a non-production environment, exposing PII associated with fewer than ten clients.

McKesson confirmed unauthorised access to third-party applications and data exfiltration. ShinyHunters claims 284 million patient-related data rows, but the scale and data types remain unverified.

ReliaQuest says a stolen password and approved MFA push produced a valid session, but device trust blocked every attempt to reach company applications.