US Edition
Your source for latest news
USCybersecurity

FBI investigates hackers' claim of massive breach at bureau's jobs website

A group calling itself ShinyHunters says it stole terabytes of data on FBI agents and job applicants after breaching FBIjobs.gov, and is threatening to publish the files unless the bureau retracts an earlier warning about the group.

PW
By PressTemps Washington DeskPublished Today, 01:32 ET · 6 min read
FBI investigates hackers' claim of massive breach at bureau's jobs website
The J. Edgar Hoover Building, FBI headquarters in Washington. Illustrative photo, not of the breached website or any individual involved. (Photo: Ajay Suresh / Wikimedia Commons, CC BY 2.0.)
What to know
ShinyHunters claims it stole 2-3 terabytes of data on nearly all FBI agents and job applicants by breaching the FBIjobs.gov recruitment portal, a claim the FBI has not confirmed
The FBI says it is aware of the claimed compromise and is "actively and aggressively investigating," while the jobs portal remains offline
The hackers say they exploited an Oracle PeopleSoft server, then moved into an Amazon-hosted government cloud system, and gave the bureau a one-week deadline to retract a May advisory about the group or face full publication of the data
ShinyHunters was previously named in an FBI/IC3 advisory tied to its breach of Instructure's Canvas platform, which exposed student and staff data at thousands of U.S. schools and colleges

The FBI is investigating a claim by a cybercriminal group that it stole sensitive personal data on nearly all FBI agents and job applicants after breaching the bureau's recruitment website, FBIjobs.gov. The site remained offline as of Wednesday morning while the bureau worked with outside technology providers to determine how the intrusion occurred, according to The Associated Press's report carried by ABC News.

The group behind the claim, which calls itself ShinyHunters, defaced the jobs portal this week and posted a message on a dark-web leak site saying it had "compromised very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job." The FBI has not confirmed the extent of any theft. In a statement, the bureau said it was "aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information" and that it was "actively and aggressively investigating this matter."

The numbers

ShinyHunters told NBC News it had taken between two and three terabytes of files after first breaching the jobs portal and then pivoting into other FBI-linked systems, a claim NBC said it could not independently verify, according to NBC News's reporting on the breach claims. The group provided roughly 5,000 sample records to reporters, including names, home addresses, phone numbers and spouses' information, which outside reviewers said appeared to match public records for real FBI personnel. According to TechCrunch's account of the technical details, the hackers said they exploited a vulnerability in an Oracle PeopleSoft server used for recruitment functions, then moved laterally into an Amazon-hosted government cloud environment holding agent and applicant records. ShinyHunters gave the bureau a one-week deadline to retract portions of a May public-service announcement the group disputes, or face publication of the full dataset.

How we got here

The FBI's May 15 announcement, issued jointly through its Internet Crime Complaint Center, warned that ShinyHunters was behind a wave of extortion attacks and that its members "commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting," according to the FBI's public service announcement on IC3.gov. That alert followed the group's breach months earlier of Instructure's Canvas learning-management system, which is used by schools and universities nationwide. The Department of Education's Federal Student Aid office told colleges in an alert that the Canvas intrusion exposed "usernames, email addresses, course names, enrollment information, and messages" after hackers exploited free, unverified teacher accounts that lacked multifactor authentication, per the Federal Student Aid alert to colleges and universities. Instructure's own account of that episode, posted on its incident-response page, said the company found "no evidence that passwords, birth dates, government IDs, or financial information were involved" and that it later reached an agreement that resulted in the stolen data being destroyed, according to the company's incident update page.

ShinyHunters has disputed the FBI's characterization of the group, telling The Register that the bureau's harassment and swatting allegations do not apply to it and insisting "this is NOT financially motivated," according to The Register's interview with the group. The group has framed the FBI breach as retaliation for what it calls a false report rather than a straightforward extortion attempt, though it has still tied removal of the advisory to whether it releases the data. Security researchers have separately linked clusters of ShinyHunters-affiliated activity to the broader collective sometimes referred to as Scattered Spider, which has claimed credit for breaches at major retailers, airlines and telecommunications firms over the past two years.

Anthropic, the AI company, said in a threat-intelligence report published this month that it had detected and disrupted several ShinyHunters-affiliated operators who used its Claude models to automate parts of cybercrime campaigns, including scanning cloud infrastructure for exposed credentials and orchestrating supply-chain intrusions that exposed thousands of corporate access tokens within hours, according to Anthropic's September 2026 threat-intelligence report. The report illustrates how the group has been able to scale operations with a relatively small number of people.

Who is affected

Current and former FBI employees, along with anyone who has applied for a bureau job through the online portal, are the immediate subjects of concern. The sample data reviewed by reporters reportedly included home addresses and phone numbers not just for agents but for their spouses, raising the risk that the information could be used to locate or harass people connected to law enforcement personnel rather than the employees alone. Because FBI agents routinely sign search-warrant applications, court filings and other public documents tied to ongoing investigations, exposure of their home addresses carries a distinct physical-safety dimension beyond typical data-breach fallout. The bureau's applicant pool, which includes people who applied for jobs but were never hired, is also implicated, meaning the potential population affected extends well beyond current staff.

Reaction and what happens next

Cybersecurity specialists said the breach, if confirmed at the scale claimed, would be unusually serious because of who is exposed. Former FBI deputy cyber director Cynthia Kaiser told NBC News that publishing agent information "could be used by criminals to target or physically harm FBI agents, personnel and their families," and cautioned that threat actors typically mix true and exaggerated claims to increase pressure on a target. Andrew Brandt, an incident responder at the security firm Huntress, told NBC that stolen law-enforcement data of this kind could be resold to criminal or nation-state groups and "abused in a multitude of ways."

"The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information," the bureau said in its statement, adding that the point of entry "is still undetermined" and that it was working with third-party providers supporting the site "to mitigate any and all risk."

The FBI has not said whether it will comply with ShinyHunters' demand to retract language from the May advisory, and outside experts consider that unlikely given the bureau's practice of not negotiating with extortionists. That sets up a standoff ahead of the group's self-imposed one-week deadline, after which it has threatened to publish the full dataset it claims to hold. The jobs portal remained down for what the bureau described as maintenance and investigation, delaying part of the FBI's ordinary hiring pipeline in the meantime. Kaiser and other former officials noted that attacks targeting federal law enforcement directly tend to draw an outsized investigative response, and the bureau's cyber division, which has separately been tracking ShinyHunters-linked intrusions across the education and retail sectors this year, is expected to fold this case into that broader effort. No arrests connected to this specific intrusion had been announced as of Thursday morning.

More on this story

All US