2026-09-29 03:17:06

The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data.
The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical addresses, job roles, names of spouses, and medical records, represents a significant national security and counterintelligence threat. Criminals in the same ecosystem as the hacking group, called ShinyHunters, have previously used hacked phone data to track and harass the FBI agents investigating them. When 404 Media first broke news of the breach, the group sent the personal data of an agent and their spouse who they said was investigating the group.
Although any potential damage will be less if ShinyHunters doesn’t publish the data publicly, the theft happening at all still presents much of those same national security risks, with the data providing granular insight into how the FBI operates.
“Since the very beginning we had made our decision that we would never publish this data. We have never intended to nor have we ever planned to,” a representative of ShinyHunters told 404 Media on Monday.
Last week, ShinyHunters provided 404 Media with a sample list of 5,000 FBI officials, in many cases including details on their spouses too. 404 Media verified this data by cross-referencing it with open source records available in the research tool OSINT Industries, and previously compromised data in Darkside, a tool made by cybersecurity company District 4.
At the time of the breach, the ShinyHunters representative said the exfiltrated data totalled between two and three terabytes. In a since-deleted announcement posted to their leak site, ShinyHunters wrote, “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.”
ShinyHunters said on its site that it was “allowing you [the FBI] a time of 1 week to correct” or remove a previously published FBI report. In that report, the FBI said that ShinyHunters exaggerates its claims of access to sensitive data to elicit payment, and that the group sends threatening text messages and phone calls to victims and their families. Typically, ShinyHunters extorts victims by threatening to publish their data online if the target organization doesn’t pay up.
In the new statement on Monday, ShinyHunters told 404 Media “Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated. However, the public and media has misinterpreted this for an extortion and have assumed that if the victim entity does not comply within 1 week which we all know including ourselves that they would never comply, we would publish all the data.”
“This was all a marketing campaign to protect our business and actively combat disinformation. If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. We’d have been ignored and disregarded. However, now everyone knows what the issue is and what we are doing. Everyone is reading about it. We proved our points on several occasions. We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts,” the statement added.
The FBI told 404 Media in a statement “The FBI is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple Bureau wide communications within 24 hours of public reporting. The FBI treats the security of its information and the safety of its workforce as top priorities, and our investigation is ongoing.”
Last week, Reuters reported some of the personnel in the 5,000 officials sample include those assigned to investigate China or Russia, presenting a serious national security threat. 404 Media found the hack also exposed the names and personal data of some members of the FBI’s secretive hacking team, called the Remote Operations Unit. The BBC reported the breach included Special Agents’ blood and urine test results. Reuters reported the hack also impacted mental health evaluations.
“We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. Nothing will happen. We are way past this situation in our business’s operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations,” ShinyHunters told 404 Media on Monday.
The data of 5,000 FBI employees has spread, though. On its site ShinyHunters said it only provided the data to “a select group of prominent U.S. media organizations solely to verify our claims.” Soon after, the cybersecurity researcher and YouTuber John Hammond said they obtained a copy too. Hammond declined to tell 404 Media how he obtained the data when asked last week.
This information, as well as the alleged two to three terabytes of overall stolen data, is likely of high interest to foreign intelligence agencies, potentially making anyone who has obtained it a target. In a separate case that shows the potential danger of stolen data, a man linked to the hack of all AT&T customer metadata records communicated with an email address he believed belonged to a foreign country’s military intelligence service, and attempted to sell the data to that country, 404 Media previously reported. Asked last week if ShinyHunters planned on selling the hacked FBI data to a foreign intelligence agency, the representative said, “No definitely not.”
On Monday, the New York Times reported the FBI sent a memo to staff saying it would offer virtual briefings and instructed employees to remain vigilant while at home and their place of work. “Bureau leadership remains committed to supporting the safety of you and your family,” the memo reportedly said.
On Monday, Krebs on Security reported authorities in the Netherlands had arrested a 23-year-old on suspicion of aiding ShinyHunters. The representative told 404 Media “the Dutch police are incompetent. That individual has no association with us. Frankly, we are laughing.”
2026-09-28 21:37:16

Facial recognition is everywhere now. It’s in surveillance cameras; it’s soon going to be in Meta’s RayBan pervert glasses, and some students already did that. You now have massively viral accounts that take clips of people, run them through facial recognition software, and then post their name and other personal info for everyone to see. We haven’t fully come to terms with what it means to live in a world where anyone can basically dox anyone else now.
To talk through this, Joseph spoke to Kashmir Hill. She’s a reporter at the New York Times, and the author of Your Face Belongs to Us: A Tale of AI, a Secretive Startup, and the End of Privacy.
Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for early access to these interview episodes and to power our journalism.If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.
2026-09-28 21:26:31

This piece contains references to eating disorders. If you or someone you know needs help, support is available.
Human contractors hired to improve Microsoft’s Copilot AI chatbot are constantly bombarded with lewd or sexually explicit photo editing requests and images that users have uploaded, including upskirt photos or putting women into sexual positions. These contractors are then asked to review whether the generated image successfully fulfilled the prompt — such as, did the image generator make the woman’s AI-enlarged breasts big enough.
When a Copilot user uploads a picture of themselves or someone else, they probably expect that image to remain private between just them and the AI tool. In reality, a workforce of at least hundreds of human reviewers are sometimes looking at that prompt and whatever images they upload. And in many cases, those contractors are inundated with requests to make foot fetish images of children’s cartoon characters, shorten a real woman’s skirt, or put people into sexual positions.
The news, based on a cache of internal contractor documents seen by 404 Media, shows that AI companies are using human workers to review not just AI chatbot users’ text prompts, but the pictures they upload and wish to edit too. Earlier this month, 404 Media revealed OpenAI has thousands of contractors who in some cases review ChatGPT users’ real prompts. That approach also extends to Microsoft and Copilot.
“Faces are always uncensored, and many of the prompts are sexual in nature and dubiously consensual,” one person who works on the prompts told 404 Media. 404 Media granted the person anonymity as they weren't permitted to speak to the press.
404 Media obtained a set of internal documents related to the contractors reviewing Copilot prompts and images, including instruction guides, real Copilot user prompts and pictures, and conversations between contractors on an internal message board.
In a thread on the internal message board, a contractor discussed prompts asking Copilot to make a woman’s skirt shorter, or enlarge her breasts, or show more leg while wearing stilettos. She-Hulk images come up a lot, the person who works on the prompts told 404 Media. Other contractors also wrote they were presented with pro-anorexia content.
“I recoiled,” one contractor wrote about seeing that content. Another person wrote that one of the prompts they reviewed asked Copilot to make an image of Ariana Grande with anorexia. Another reported a prompt that seemed to be designed to create a lewd or suggestive image of a group of young girls.
These contractors are not being hired to flag or vet offensive or inappropriate content. They are being paid to review the quality of Copilot’s output, including in these cases of sexual imagery.
“Who is writing these prompts and who is deciding that basically generating porn is what Copilot is now focused on? It’s hard to take things seriously when my focus has to be what model generated the appropriate bust size or which middle aged woman was put in the appropriate sexually suggestive position,” one contractor said in the thread.
Microsoft is explicitly interested in the contractors’ human intuition on which image looks better, according to the documents. “Trust your intuition — when you glance at the two edited images side by side, which one immediately feels like the better edit? Your gut reaction as a human viewer matters,” a set of instructions given to the contractors reads.
“When in doubt go with your first impression,” the instructions continue. “Human intuition is good at catching subtle quality differences that are hard to articulate.”
Human contractors being exposed to horrific, unpleasant, or traumatizing material is, of course, not new. Big tech companies, and especially social networks, have used armies of contractors for years to moderate user generated content. AI companies, too, have used poorly paid workers overseas to train their AI models or, in the case of OpenAI, make them less toxic. What is different in this latest Copilot episode, and 404 Media’s reporting on contractors at other AI companies like OpenAI, is that the content humans are reviewing are prompts and uploads that chatbot users may assume are private, and that the contractors are not looking at this material to train the models to filter out offensive images or for some other safety concern. The training is to make the responses by the chatbots better: more informative, friendly, and clearer.
The instructions seen by 404 Media focus on what contractors do when a Copilot user asks the AI to edit an image. The contractor is shown the user’s original prompt, the uploaded picture, and then two Copilot-generated edits. The contractor has to pick which is the better edit, based on four things: does the edited image correctly follow the edit instructions; are bits of the image that should remain unchanged preserved — for example, if the prompt is to “add a cup on the table,” nothing else should be changed except the cup — does the edited image contain any visible artifacts like distortions or unnatural textures; and the overall quality of the AI-generated edit.
Some of the Copilot contractors complained in the private forum about accepting “tasks” that they unknowingly contained explicit unsafe or even potentially illegal images. “I just came across an image set that consisted of eight upskirt photos,” the contractor wrote, while asking for superiors to add an unsafe content flag to the task. On the same thread, another contractor said they had seen images of “some sort of animal sacrifice,” and a third said they had seen prompts that were for sexual moves and positions.
At least one of the companies which hires the contractors for this work is called Prolific. One service Prolific mentions on its website is “Human feedback from representative populations — for preference tuning, safety evals, and benchmarks you can defend.”
In another thread, a contractor quotes Prolific’s own guidelines, which highlight it can be difficult to ensure that trainers aren’t presented with sexual imagery: “Particular caution around disturbing or explicit content should be taken with generative AIs. This is because, unlike traditional content, researchers cannot fully control what is shown to participants.”
Prolific did not respond to a request for comment. A Microsoft spokesperson told 404 Media in an email “Microsoft uses customer data as described in our terms of use, including to improve our products and enforce our code of conduct.”
Microsoft’s AI tools have a long history of being abused by people to make nonconsensual, AI-generated images of people. Members of 4chan and AI porn focused Telegram channels used Microsoft’s tools, for example, to generate porn of Taylor Swift that later went viral on Twitter. Microsoft fixed the loophole those people were using in Microsoft Designer after 404 Media’s reporting.
In 2024, 404 Media documented how Copilot would answer, then delete, answers to potentially controversial or sexual prompts in real time. In March, a top Senate administrator approved Copilot for use in the Senate, along with ChatGPT and Google’s Gemini. A memo said Copilot “can help with routine Senate work, including drafting and editing documents, summarizing information, preparing talking points and briefing material, and conducting research and analysis.”
2026-09-27 05:59:39

Welcome back to the Abstract! Here are the studies this week that sailed alien seas, beat the heat, went retro, and got caught in the food web.
First, scientists make the case that Saturn’s moon Enceladus could resolve one of humanity’s greatest questions—are we alone in the universe?—if only we would just send a spacecraft there already. Then: an amoeba in hot water, a backwards-ass planet, and the prandial ouroboros we call life on Earth.
As always, for more of my work, check out my book First Contact: The Story of Our Obsession with Aliens, or subscribe to my personal newsletter the BeX Files.
In a double-whammy pair of studies, scientists have offered more proof that Enceladus—the tiny moon of Saturn—might host alien life, and that it would be relatively easy to find out for sure.
Enceladus is only 300 miles in diameter, but it contains marine multitudes. Underneath its outer ice shell, the moon hosts a subsurface ocean and hydrothermal vents on its seafloor, which are hotspots of life here on Earth.
What’s more, Enceladus squirts out watery plumes from its ocean through geysers on the surface, which can be sampled by passing probes. Indeed, the Cassini spacecraft—which orbited Saturn from 2006 to 2017—ran through this space sprinkler several times, providing our first taste of an extraterrestrial sea. However, that mission was not equipped to detect signs of life, known as biosignatures.
In the first of two new studies, researchers created a simulated version of Enceladus’s “soda ocean” (meaning it is alkaline and carbonate-rich). The team then dropped the heat-loving microbe Methanothermococcus okinawensis to live in this earthly ersatz Enceladus. This species was selected because it lives on deep-sea hydrothermal vents on Earth.

It turned out that M. okinawensis fared even better in this habitat than expected, a discovery that potentially widens “the habitability window of Enceladus’ subsurface soda ocean,” said researchers led by Vanessa Helmbrecht of Ludwig-Maximilians-Universität München.
In the other study, a team revisited Cassini’s observations of ice grains sprayed out into space by Enceladus. They discovered that the ocean droplets freeze slowly in space, causing organic molecules to separate out into concentrations of similar compounds. If these droplets contain biosignatures, they may be conveniently pre-sorted for any instrument that captures them.
“In the plume grains, each separated compound can then be found at strongly elevated concentrations in a relatively small fraction of ice grains,” said researchers co-led by Frank Postberg and Zenghui Zou of Freie Universität Berlin. “This is good news for future plume sampling missions investigating Enceladus’ promising habitability provided that they can sample and analyze ice grains individually.”
For years, mission concepts to Enceladus have been floated but never formally greenlit, including NASA’s Enceladus Life Finder or the European Space Agency’s L4 mission. Hopefully, something gets off the drawing board and into space eventually, because Enceladus is low-hanging fruit, astrobiologically speaking.
In other news…
Speaking of weird heat-loving microbes, meet Incendiamoeba cascadensis, a newly discovered amoeba that has shattered the heat tolerance record for eukaryotic life.

Scientists found this novel species simmering in water temperatures exceeding 64°C (147°F) inside Hot Springs Creek at Lassen Volcanic National Park in California (for reference, the average hot tub is around 100°F). While simple “procaryotic” organisms can survive much hotter water—the microbe Methanopyrus kandleri tops out at a balmy 252°F—the upper thermal limit for more complex “eukaryotic” lifeforms was previously thought to be 60°C (140°F).
“Incendiamoeba cascadensis proliferates at temperatures beyond what was thought possible for any eukaryote,” said researchers led by Beryl Rappaport of Syracuse University. “This discovery raises questions about the true maximum temperature a eukaryotic cell can endure.”
If a human were exposed to these water temperatures, they would suffer third-degree burns in seconds—so let the amoebas have their win and leave the deadly hot springs to them.
If you’ve been feeling like the vibes are off, it’s probably because the planet GJ 3090 b is in retrograde—permanently. This world, which is about 4.5 times as massive as Earth, is the “first planet on a retrograde orbit discovered around an M dwarf,” a type of small star more commonly known as a red dwarf, according to a new study.
In our solar system, the concept of a planet being “in retrograde” refers to the optical illusion of planets appearing to move backwards in their orbits from our perspective on Earth. But GJ 3090 b is actually orbiting in the opposite direction of the rotation of the star, which is located 60 light years away.
Exoplanets with similar retrograde orbits have been observed before, but GJ 3090 b is distinct because there is no massive object (a star or planet) in the system that seems to have set it into reverse. Most retrograde orbits are caused by gravitational disruptions from such colossal companions, but this exoplanet may have just been born this way—meaning that it formed from a disk of material that was out-of-whack from the jump.

“Whereas highly misaligned orbits are commonly attributed to gravitational interactions with a massive companion, the architecture of the GJ 3090 system instead favors a primordial misalignment of the protoplanetary disk,” said researchers led by Yann Carteret of the University of Geneva.
The discovery is a reminder that star systems take on a wild variety of configurations shaped by countless interactions and factors. Contrary to the proverb, there is something new under every sun.
From the simplest microbe to the mighty blue whale, all life on Earth has one thing in common—we gotta eat. But given the dazzling complexity of food webs around the world, it can be tough to track what species end up in what bellies (or belly-equivalent) out in the wild.
That’s a problem that scientists are now inviting the public to help solve with the new online database: Who Eats Whom? In a partnership with the popular platform iNaturalist, the tool has catalogued some 14,000 observations of food-web interactions captured by nearly 2,000 observers from more than 100 countries, according to a new study about its progress.

“Who Eats Whom is, to our knowledge, the first attempt to create a global food web derived specifically from verifiable citizen science photographs,” said researchers led by Bradley C. Allf of Colorado State University. “Beyond our scientific goals, we are designing the project as a tool for education and public engagement in science.”
You can search for specific animals in the database (for example, searching for the red fox reveals a brave Australian python-eater, as well as this excruciating picture of the last moments of an Eastern chipmunk in Ontario with the caption: “not a great day”). I was also delighted to learn that coyotes, in addition to chasing down prey, apparently go on persimmon binges that leave behind seed-filled scat.
To get a sense of the bigger picture, you can check out this interactive global food web of species. We are, after all, what we eat—and what we eat eats, and so on forever.
Thanks for reading! See you next week.
2026-09-26 04:56:21

We debated for a long time about whether to write about the following video, which comes from a murder trial in which a man named Caleb Flynn is accused of killing his wife. The crime is very serious, and very sad, and yet the following video demonstrates something about where we are as a society.
The trial has received national attention and has been streaming live. Toward the end of the proceedings Thursday, the prosecution played two versions of an AI love song that Flynn, a former American Idol contestant, generated for his mistress. Investigators found the AI song files as well as lyrics for the song in Flynn’s Notes app after using the forensic tool GrayKey to break into his phone.
“We found audio files on Caleb’s iPhone that seem to have been AI generated and related to his relationship with [his mistress],” Joseph Wilhelm, a forensic investigator testified. “They’re in two different keys. One’s like a happy or upbeat sad song if that makes any sense, and one’s a sad, sad song. I think one’s in a minor key, one’s in a major key, but I’m not a music professional.”
“Permission to publish, your honor?,” the prosecutor says.
“You may,” the judge says.
What follows feels like it should be from an I Think You Should Leave skit or a Nathan Fielder bit. It is real, however. Everyone in the court spends the next few minutes trying not to laugh during what is, again, a murder trial. It simply must be seen to be believed:




When the songs mercifully end, the court goes silent for several seconds. The judge then says: “We’re going to break for the day. It’s 10 after 4 [p.m.] We will reconvene tomorrow.”
Earlier in the day, Flynn’s mistress was asked to read various text messages he wrote her into the public testimony. “I’ve spent a lot of time on my own and in Cleveland. I finished the lyrics to our song. To your song. Although it may mean nothing to you, I wanted to give them to you. I have the music which is completely different to what you’ve heard to this point and I was going to record it but I know there will be no way I would ever be able to actually sing it again,” Flynn wrote.
“Do you want to hear the song I wrote for you with an AI voiceover,” Flynn also wrote. “I have this software called ElevenLabs where I loaded the song on piano and sent it with my computer microphone to which I can pick an AI voice to sing it better.”
“I don’t know if I’m ready to listen to this yet. I’m sorry,” she responded. “Send me the song and I’ll save it to my phone and I’ll listen when I’m ready, even if it’s a month from now. I don’t want it to be erased.”
“Are you sure? It messed up the outro as it’s supposed to be done and the vocals aren’t exactly how I want it, it was a little rock-ier at times but the melody is correct. I tried to sing it with passion and AI took it and went a little extreme.”
“It’s OK,” she said.
The investigation into the murder is actually 404 Media-relevant for several reasons. The AI-generated songs were found after Wilhelm used both Cellebrite and Graykey to try to break into Wilhelm’s phone.
Ultimately Wilhelm used Graykey’s Magnet tool to unlock and examine Flynn’s phone, which gave him a “full file system extraction.” Wilhelm then obtained Flynn’s messages, the AI audio files, cell phone location history, sleep data from Flynn’s Oura Ring, heart rate data from an Apple Watch, learned that Flynn deleted an app called “AI music song generator” days before the murder, and AirPod connection and disconnection information.
2026-09-25 23:58:26

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss some small changes, an AI song, and internet soup.
JOSEPH: We’re making a couple of changes that might sound boring to someone who doesn’t read or listen to our work, but I’m actually legit excited about them, and I think they will be better for all of you too. I’ll talk about one now and maybe the other next week.