
Hackers say they grabbed a trove of FBI personnel and applicant data, then slapped a seizure banner on the bureau’s jobs site to prove they were inside.
At a Glance
- ShinyHunters claims it stole sensitive data on almost all FBI agents and applicants.
- 404 Media reviewed a 5,000-record sample with names, addresses, and spouse details.
- The FBI jobs portal showed a “seized” message and went offline during the incident window.
- The FBI said it is investigating unauthorized activity affecting FBIjobs.gov.
Hackers Announce a Broad Raid and Show a Data Sample
ShinyHunters posted that it took “very sensitive data on almost ALL FBI agents and individuals who filed an application with the FBI for a job,” placing the claim on its leak site where reporters could see it.
The group sent a 5,000-record sample to a news outlet that described names, addresses, phone numbers, dates of birth, and spouse information for alleged employees.
Reporters said they matched parts of that sample to public records, adding weight to the claim that at least some data is real.
The cybercriminal organization ShinyHunters claimed Tuesday it breached FBI systems and stole sensitive personal information belonging to all of the bureau's employees and applicants. https://t.co/0idvAfMDJ1
— NEWSMAX (@NEWSMAX) September 23, 2026
Coverage described the haul as far beyond basic contact info. Reports said categories included home addresses, spouse details, and protected health information, the type of material that puts families at risk and complicates routine security clearances.
The group framed the breach as leverage, tying it to demands over public reporting about its tactics. That narrative fits a wider trend where cybercriminals blend publicity, pressure, and partial proof to drive outcomes.
Visual Defacement Turns a Claim Into a Public Spectacle
The Federal Bureau of Investigation’s recruiting portal displayed a seizure-style message reading “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS,” a taunt that moved the event from underground forums to the open web.
Reporters noted the jobs site and the Special Agent Application Portal were unavailable after the defacement, signaling active disruption while teams responded.
The visible banner served a purpose beyond mockery; it told applicants and staff that the attackers could reach official pages, which heightens fear and attention.
The FBI acknowledged it was investigating “claims regarding unauthorized activity affecting FBIjobs.gov,” a standard statement that confirms attention without spilling technical detail.
That stance is normal in early hours when agencies preserve logs, contain access, and coordinate with other responders.
Meanwhile, public focus shifted to what data classes were in play and how many current, former, and prospective employees might be exposed to doxxing or spear-phishing.
The Alleged Intrusion Path Points to Classic Weak Links
Multiple outlets reported that ShinyHunters claimed it used a new flaw in Oracle PeopleSoft to gain a foothold, then moved into Amazon Web Services GovCloud where sensitive systems may reside.
PeopleSoft supports human resources and recruiting workflows across government, so an opening there could be powerful.
A pivot into cloud infrastructure would explain how one front-door break could reach deeper data stores. That chain, if accurate, matches many breaches: find the unpatched edge, harvest credentials, then move fast.
Security teams in both government and industry should treat this as a blunt lesson. Patch hygiene and access controls across human resources and recruiting stacks matter as much as the crown-jewel case systems. The bad guys go where the paperwork lives.
Personnel records hold addresses, family info, and medical notes. That material is gold for extortion, blackmail, and targeted scams.
What Exposure Means for Agents, Applicants, and Families
Agents and analysts train to handle risk. Their spouses and kids do not. If attackers hold addresses, phone numbers, and health details, then harassment, fake service calls, and tailored phishing can follow.
Adversaries can also cross-reference with earlier leaks to build rich profiles. The right response is fast notification, credit monitoring, and direct guidance on social engineering threats. The better response is cutting data sprawl, shrinking who can see it, and logging every touch with alerts that bite.
"Extortion Group ShinyHunters Claims Massive FBI Data Breach Targeting Current & Former Staff"
➡️ The extortion group known as ShinyHunters claimed on Tuesday that it breached the Federal Bureau of Investigation & stole data covering almost all current FBI agents & individuals… pic.twitter.com/eWbGWFK14H
— BreakinNewz (@BreakinNewz01) September 22, 2026
Applicants deserve attention, too. Many entered data while seeking to serve their country. They did not sign up for a lifetime of spam, scams, and fear. Government systems should treat their records with the same rigor as active staff.
That means short retention by default, encryption at rest and in use, and strong identity checks before any large export. Congress and agency leaders should insist on simple proof: patch timelines, access logs, and a clean bill of health before portals relaunch.
Sources:
techcrunch.com, 404media.co, redstate.com, hackread.com, securityweek.com, news9live.com, cyberscoop.com












