express gazette logo
The Express Gazette
Wednesday, September 30, 2026

FBI Investigates Cyberattack Claims, Hackers Allege Sensitive Personnel Data Stolen

The FBI is investigating claims by the cybercriminal group ShinyHunters that it breached the FBIJobs.gov portal and stole sensitive personal information of FBI employees and job applicants.

US Politics • 2 hours ago
FBI Investigates Cyberattack Claims, Hackers Allege Sensitive Personnel Data Stolen

The FBI is investigating claims made by the cybercriminal group ShinyHunters that it successfully breached the FBIJobs.gov portal and obtained highly sensitive personal data related to current and former FBI personnel, as well as individuals who applied for jobs at the Bureau. The group alleges the stolen information extends beyond basic contact details.

In a statement released on September 23, the FBI acknowledged the cybercriminal group's claims and stated that it was "actively and aggressively investigating" the incident. Investigators had not yet determined whether the breach originated within an FBI system or through a third-party provider supporting FBIJobs.gov. At the time of the FBI's statement, samples of the alleged stolen data provided to journalists contained sufficient verifiable information to warrant serious concern.

ShinyHunters claims to have exfiltrated between two and three terabytes of data. The group alleges the breach was achieved by exploiting a previously unknown vulnerability in Oracle PeopleSoft, software used for human resources functions. FBI documents reportedly indicate that its recruiting operations utilize PeopleSoft and AWS GovCloud, although this does not confirm the hackers' claimed method of attack.

The FBI announced on September 26 that it had taken action, arresting an alleged leader of ShinyHunters in the Netherlands through a joint operation with Dutch authorities. Dutch police reported the arrest of a 24-year-old man in Amsterdam on September 15.

ShinyHunters has stated that its motivation for the attack was retaliation, not financial gain. The group cited FBI warnings issued earlier in 2026 regarding ShinyHunters-related cyber activity. An advisory from the FBI's Internet Crime Complaint Center on May 15 described ShinyHunters as a cybercriminal organization specializing in large-scale data breaches and extortion, warning that actors associated with the group might use fabricated or exaggerated claims about stolen data to pressure victims. ShinyHunters disputes certain aspects of the FBI's description of its activities and claims it targeted the FBI in response to the May warning, demanding the Bureau rescind the advisory while holding the allegedly stolen data.

Information provided by ShinyHunters to journalists reportedly includes a spreadsheet containing approximately 5,000 alleged FBI personnel records. According to Reuters, this data included names, home addresses, phone numbers, dates of birth, Social Security numbers, and emergency contact information. In some instances, it also reportedly contained details about field-office assignments and sensitive intelligence or counterespionage work.

While Reuters could not authenticate the entire spreadsheet, reporters independently verified details for over 22 individuals by cross-referencing the information with credit records and previously leaked data. Career information or job titles for eight individuals were matched against court filings, news reports, public profiles, and online posts. 404 Media also reported that the sample data included information about FBI employees' spouses.

The alleged inclusion of job-related information raises additional security concerns beyond personal privacy. Reuters reported discovering records identifying individuals connected to China-related investigations, Russian intelligence operations, human intelligence activities, and electronic surveillance. Other entries referenced covert access, clandestine technical operations, and telecommunications interception. This type of information, if coupled with personal details like home addresses and emergency contacts, could significantly increase risks for FBI employees working in sensitive positions.

This incident highlights broader concerns about data security, even for individuals not directly affiliated with the FBI. Organizations often collect extensive personal information, including Social Security numbers, birth dates, and employment history. The potential for this data to be exposed through breaches at these organizations or their third-party vendors underscores the widespread vulnerability of personal data. As the FBI noted, the exact point of breach—whether an FBI system or a third-party provider—remains undetermined, mirroring common data security challenges across various sectors.

For individuals whose information may have been compromised, precautions include verifying any unexpected communications from the FBI, warning family members and emergency contacts, placing a credit freeze, considering an IRS Identity Protection PIN, and closely monitoring financial, tax, and medical accounts. Strengthening online account security with unique passwords and two-factor authentication, maintaining antivirus protection, and reducing the amount of publicly available personal information are also recommended steps. The FBI advises against paying or engaging with threat actors and recommends reporting cybercrime through IC3.gov.


Sources