DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Before Their Telegram Channel Was Banned Again, ScatteredLAPSUS$Hunters Dropped Files Doxing Government Employees (2)

Posted on October 18, 2025October 20, 2025 by Dissent

On October 16 and 17, the ScatteredLAPSUS$Hunters Telegram channel repeatedly violated Telegram’s TOS by leaking personal information on people — and in this case, information on employees of the Department of Justice (DOJ/FBI), U.S. Attorneys Office (DOJ/USAO), the Department of Homeland Security (DHS), and the Federal Aviation Authority (FAA).

DataBreaches did not report on it at the time precisely because the files were still exposed. Instead, DataBreaches contacted Telegram to inquire why the channel hadn’t been banned again for leaking sensitive information about government employees. Today, DataBreaches received a response from Telegram, stating that the channel had been removed for breaching their TOS. They added:

Publishing private information (doxing) is explicitly forbidden by Telegram’s terms of service, and such content is removed whenever discovered. Moderators empowered with custom AI tools proactively monitor public parts of the platform and accept reports to remove millions of pieces of harmful content each day, including doxing.

Daily stats and more details about Telegram’s moderation here: Telegram.org/moderation.

But how many people accessed and downloaded the four .csv files before the channel was banned? How many sites reported on the leak while the files were still exposed? DataBreaches is aware of one popular site that did report on the leak quickly, while the files would still be freely accessible to everyone.

Types of Information

The .csv file with information on FBI employees contained 174 entries with employees’ email addresses, first and last names, phone numbers, and postal addresses. The entries did not reveal what the individuals’ titles or roles were or are. DataBreaches did not check every entry, but a random sample checked did find current or former agents with those names. The addresses and phone numbers appeared to be mainly work-related.

The .csv file for USAO employees contained 197 entries with the same kinds of information. Spot checks of the names revealed that not everyone in the file was an attorney; some had other roles in the department.

The .csv file for Homeland Security contained 680 entries from different parts of the Department of Homeland Security, such as Federal Emergency Management Agency (FEMA), Customs & Border Protection (CBP), Citizenship & Immigration (USCIS), Transportation Security Administration (TSA), the U.S. Secret Service (USSS), and Immigration & Customs Enforcement (ICE). The data included the same kinds of information as the previous spreadsheets, and a spot check of some addresses revealed that some employees may have listed home addresses and not work addresses.

The .csv file with data from FAA employees contained 416 entries with the same types of information.

None of the files seemed to have any internal organization. Entries were not sorted by state or alphabetically by name, and none included the individual’s title or date of hire. It is not clear what the source of those files might be and whether they had ever been leaked before.

DataBreaches emailed DOJ/FBI, DHS, ICE, and CBP to ask whether employees were being notified of this incident. An auto-reply was received from CBP that indicated that the inquiry would be addressed on the next business day (M-F). This post will be updated if we get any replies.

Update 1: On Sunday, a DHS spokesperson responded to our email with: “DHS is investigating this matter.”
Update 2: On Monday, a DOJ spokesperson responded to our email with: “No comment, thanks.”

Category: Breach IncidentsGovernment SectorU.S.

Post navigation

← Scenes from a “No Kings” Protest, 10-18-25
A business’s cyber insurance policy included ransom coverage, but when they needed it, the insurer refused to pay. Why? →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Checkout.com Discloses Data Breach After Extortion Attempt
  • Washington Post hack exposes personal data of John Bolton, almost 10,000 others
  • Draft UK Cyber Security and Resilience Bill Enters UK Parliament
  • Suspected Russian hacker reportedly detained in Thailand, faces possible US extradition
  • Did you hear the one about the ransom victim who made a ransom installment payment after they were told that it wouldn’t be accepted?
  • District of Massachusetts Allows Higher-Ed Student Data Breach Claims to Survive
  • End of the game for cybercrime infrastructure: 1025 servers taken down
  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • OpenAI fights order to turn over millions of ChatGPT conversations
  • Maryland Privacy Crackdown Raises Bar for Disclosure Compliance
  • Lawmakers Warn Governors About Sharing Drivers’ Data with Federal Government
  • As shoplifting surges, British retailers roll out ‘invasive’ facial recognition tools
  • Data broker Kochava agrees to change business practices to settle lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.