Hackers Claim They Stole Personal Data on Nearly All FBI Employees
A criminal extortion group says it exfiltrated roughly two to three terabytes of records from the FBI's hiring and personnel systems, including Social Security numbers and, in some cases, medical files. The bureau has confirmed a breach but not verified the hackers' full claims.

The FBI is investigating a claim by a criminal hacking group that it broke into the bureau's employment and personnel systems and stole personal data on thousands of current and former agents, support staff and job applicants. The bureau has confirmed that an intrusion occurred and has told employees internally that it is treating the matter as a "cyber security incident," but it has not verified the full scope of what the hackers say they took.
The extortion group ShinyHunters claimed responsibility on Sept. 22, defacing the bureau's job-application site with its own banner and later posting screenshots of what it said was FBI personnel data on a dark-web leak site. The FBI's public-facing hiring portal, FBIJobs.gov, and its associated application site went offline within days and remained inaccessible to prospective applicants as the investigation continued. By late last week, according to reporting on an internal notice sent to staff, the bureau had escalated its own classification of the episode to a formal cyber security incident, telling employees that their names, addresses, job titles and Social Security numbers may have been exposed.
The numbers
ShinyHunters says it obtained roughly two to three terabytes of data by breaching an Oracle PeopleSoft human-resources server and then pivoting into an Amazon-hosted cloud environment that stored FBI personnel and applicant records. The group told reporters the haul touches records tied to several internal FBI systems it named as Criminal Justice, HR, Medlink, FBIJobs, PEGA and Phire.
- A sample the hackers shared with journalists contained records on roughly 5,000 FBI employees.
- Fields in the sample included names, home addresses, phone numbers, dates of birth and, in some entries, the names of spouses or other family members.
- Some records reportedly included Social Security numbers and job-assignment details; a subset of descriptions referenced sensitive functions such as human intelligence collection, telecommunications intercept work and clandestine technical operations.
- The Medlink files the group described allegedly include medical and psychiatric information tied to the FBI's employee health system, among them prescription and diagnostic records.
None of those figures has been independently verified in full, and the FBI has publicly confirmed only a fraction of what the hackers describe. The bureau has said the "point of breach" — whether inside its own network or at a third-party provider that supports FBIJobs.gov — remains undetermined. Cybersecurity researchers who reviewed the leaked sample have said it is structurally consistent with the kind of records a PeopleSoft HR deployment would generate, without confirming its full provenance or authenticity beyond that.
How a hiring database became a counterintelligence problem
The intrusion traces back to a vulnerability that hit dozens of organizations months before the FBI was targeted. In late May and early June, ShinyHunters exploited an unauthenticated flaw in Oracle's PeopleSoft PeopleTools software, catalogued as CVE-2026-35273, to compromise more than 100 organizations, the large majority of them universities and colleges running PeopleSoft for student records, payroll and human resources. Oracle shipped an emergency, out-of-band patch on June 10, and the Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog two days later, ordering federal civilian agencies to remediate any exposed instances on an expedited timeline. The FBI breach suggests either that an agency-linked PeopleSoft instance was patched too late or that ShinyHunters retained separate access it established before the flaw became public.
ShinyHunters is a loosely organized extortion crew, not a traditional ransomware operation, that has claimed breaches of large retailers, ticketing platforms and financial firms in recent years, typically by stealing data rather than encrypting systems and then pressuring victims to pay to avoid a public leak. In May, the FBI's Internet Crime Complaint Center issued a public service announcement naming ShinyHunters after the group breached the Canvas learning-management platform used by schools nationwide, warning potential victims not to pay and describing the group's pattern of harassment, spearphishing and swatting threats against people whose data it steals. ShinyHunters has since said, in its own dark-web posting, that targeting the FBI directly was retaliation for that advisory — a claim that, if accurate, would make this one of the more overtly retaliatory attacks on a federal law enforcement agency in recent memory. It is also a departure from the group's usual approach: in other recent cases tied to the same PeopleSoft flaw, ShinyHunters demanded payments described as a percentage of a victim company's net worth, while in the FBI case it has told reporters the intrusion was "not financially motivated."
Who is affected
The bureau reported having approximately 38,000 employees as of April 2025, according to a Congressional Research Service overview of the agency, a workforce that includes special agents, intelligence analysts, language specialists and other support staff. If the hackers' broader claim — that they hold data on "almost all" FBI agents and applicants — proves accurate, the exposure would reach far beyond current staff to include job applicants who never worked for the bureau, retirees, and family members whose names appear in background-check or emergency-contact fields going back years.
The population of greatest concern to security officials is not the general workforce but agents in the roles the leaked sample singled out: those working counterintelligence, counterterrorism and undercover assignments, whose home addresses, family details and duty assignments are ordinarily withheld from any public-facing or vendor-managed database precisely because of the risk exposure now under discussion. For job applicants, the potential exposure could include material submitted during background investigations, which routinely probes financial history, past drug use, foreign contacts and other personal disclosures never intended for public release.
Reaction
The FBI's public statement has been narrow. It has said it is "aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information," and that it is "actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk." It has not confirmed the volume of data taken, whether Social Security numbers were exposed for the full employee population, or whether the intrusion reached beyond the hiring system into other bureau networks.
Outside national-security specialists have been considerably more alarmed than the bureau's own language suggests. In an analysis published this week, researcher Justin Sherman, who tracks state-linked and criminal cyber operations, argued that the exposure of agents' addresses, family members and assignment histories hands foreign intelligence services a ready-made targeting list.
The breach represents "a counterintelligence disaster for the United States," exposing personnel to profiling, phishing and potential recruitment or coercion attempts by adversary services — a risk Sherman warns could persist for years as junior employees whose data was exposed move into more sensitive postings.
Other researchers have separately flagged the risk of "swatting" and harassment campaigns against individual agents, a tactic ShinyHunters and affiliated groups have used against other victims whose data they leaked previously, including university students and staff caught up in the earlier wave of PeopleSoft breaches this year.
What happens next
The FBI has not said publicly whether it will notify individual employees and applicants directly, though the internal message described in reporting this week told staff their names, addresses, job titles and Social Security numbers may have been exposed. Officials inside the Justice Department are reportedly weighing whether the intrusion meets the federal definition of a "major incident," a designation that would trigger mandatory, time-limited notification to congressional oversight committees.
FBIJobs.gov and the bureau's special-agent application portal remained offline as the investigation continued, delaying hiring at an agency that has spent much of this year publicly campaigning to recruit more special agents. ShinyHunters, for its part, has said its goal is not a ransom payment but the removal of the FBI's May advisory naming the group — a demand the bureau has given no indication it intends to meet. Security researchers say the episode is likely to be cited for years as a test case for how the federal government secures the vendor software, in this instance Oracle's PeopleSoft platform, that quietly underpins routine functions like payroll, benefits and hiring across dozens of federal agencies and universities alike.

Massachusetts Report Finds Catholic Clergy Abused 944 Children Across Three Dioceses

Becerra and Hilton clash over Trump, taxes and immigration in lone California governor debate

Treasury Begins Mailing $500 ACA Refund Checks to Nearly 1 Million Americans
