
Hackers say they grabbed data on almost every FBI agent and applicant—then splashed their calling card across the bureau’s jobs site.
At a Glance
- ShinyHunters claimed they stole sensitive data on nearly all FBI staff and applicants.
- A 5,000-record sample reviewed by a news outlet included employee personal details.
- The FBI jobs portal showed a “seized by ShinyHunters” message and went offline.
- The FBI said it is investigating unauthorized activity affecting FBIjobs.gov.
Hackers claim sweeping theft of FBI personnel and applicant data
ShinyHunters posted a statement saying they hold very sensitive data on almost all FBI agents and people who applied for jobs at the bureau. That claim appeared on the group’s leak site and was reported by multiple outlets on September 22.
The group framed the theft as broad and deep, covering current and former staff plus applicants. The volume suggested by their rhetoric would be historic if fully borne out, because it targets the people behind the badge, not just a public-facing portal.
Reporters at an independent outlet said the hackers provided a sample of 5,000 alleged employee records. The sample included names, home addresses, phone numbers, dates of birth, and spouse information.
The outlet said some of those details matched public records, which supports that at least part of the dataset is real. That type of match check is a basic test professionals use. It does not prove scale, but it does show the data is not a random paste.
Defacement of FBI jobs portal raises the stakes
The FBI jobs website displayed a seizure-style banner that read, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS,” according to coverage that captured the message. The site then went offline during the incident window.
The Special Agent Application Portal was also reported as unavailable. Portal defacement often signals access beyond a simple login page, but it does not alone prove a database was drained. The timing and the public message, however, forced swift attention to the breach claim’s seriousness.
The Federal Bureau of Investigation (FBI) said it is aware of “claims regarding unauthorized activity affecting FBIjobs.gov” and is investigating. That public confirmation of an active probe shows the bureau treated the incident as more than online noise.
Federal agencies tend to speak carefully while they gather facts, but the signal here was clear: something touched their recruitment infrastructure and drew an immediate response.
The cybercriminal organization ShinyHunters claimed Tuesday it breached FBI systems and stole sensitive personal information belonging to all of the bureau's employees and applicants. https://t.co/0idvAfMDJ1
— NEWSMAX (@NEWSMAX) September 23, 2026
Alleged path: PeopleSoft zero-day to cloud pivot
Security reports relayed the attackers’ stated intrusion chain. The group claimed they exploited a new flaw in Oracle PeopleSoft, then moved into systems hosted on Amazon Web Services’ government cloud.
That path, if accurate, tracks with real-world playbooks that start with an enterprise application and end with cloud assets that hold crown-jewel data.
Coverage also noted the hackers demanded a retraction of a prior threat advisory that named them, which adds a pressure tactic to the narrative.
Technical details in public reports describe personnel fields beyond basic contact data. Outlets cited records categories such as home addresses, phone numbers, spouse details, and protected health information.
Those categories turn a breach from an annoyance into a life-impact event. For law enforcement families, home and spouse data can raise safety risks. For any worker, health-related data can create exposure that is hard to undo once posted online.
What matters now: people risk, patching, and proof
The human impact sits at the center. If employees and applicants face doxxing or harassment, the bureau and Congress must respond fast with identity protection, safety guidance, and outreach.
A focused plan should lock accounts, rotate credentials, and brief anyone whose data might be in scope. That is not window dressing. It is the first shield against criminals who prey on fear.
"Extortion Group ShinyHunters Claims Massive FBI Data Breach Targeting Current & Former Staff"
➡️ The extortion group known as ShinyHunters claimed on Tuesday that it breached the Federal Bureau of Investigation & stole data covering almost all current FBI agents & individuals… pic.twitter.com/eWbGWFK14H
— BreakinNewz (@BreakinNewz01) September 22, 2026
The systems side must move in parallel. If the entry point was an Oracle PeopleSoft flaw, leaders should demand a clear patch timeline and confirm version status for every instance tied to personnel or recruiting.
If cloud resources were involved, audit logs can show access and exfiltration paths. That evidence tells responders what left the building and when. Rapid, disciplined forensics will also guide any law enforcement action to disrupt resale or extortion.
How to read the early evidence without getting spun
Early breach stories always mix three elements: a bold claim, a sample that looks real, and a bigger number that may take time to pin down.
This case has all three. The public defacement and the FBI’s investigation notice add weight. The sample reviewed by journalists adds texture.
The larger assertion of “almost all” staff drives headlines, but the people on the ground—agents, analysts, applicants, and their families—need timely, specific answers and practical help now. A single line caveat: the FBI has not yet published a final incident finding.
Sources:
techcrunch.com, 404media.co, redstate.com, hackread.com, securityweek.com, news9live.com














