FBI investigates hackers' claim to have stolen sensitive employee data,
compromised jobs website
[September 24, 2026]
By ERIC TUCKER
WASHINGTON (AP) — The FBI said Wednesday that it was investigating a
criminal hacking group's claims that it had stolen “very sensitive data”
belonging to thousands of agents and applicants and that it had
compromised the bureau's jobs website.
“The FBI is aware of a cyber-criminal enterprise group claiming a
compromise of the FBIJobs.gov portal and alleged impact to FBI employee
personally identifiable information," the FBI said in a statement. It
said that while the “point of breach” was undetermined, "we are actively
and aggressively investigating this matter and working closely with
those third-party providers that support FBIJobs.gov to mitigate any and
all risk.”
The jobs website, the main portal for prospective employees to learn
about the FBI and initiate the application process, remained offline as
of Wednesday afternoon.
A message that circulated online from a hacking group known as
ShinyHunters claimed responsibility for the hack.

“We have compromised the FBI. We hold very sensitive data on almost ALL
FBI Agents and individuals who filed an application with the FBI for a
job,” said the ShinyHunters message, which was directed to FBI Director
Kash Patel and Brett Leatherman, the assistant director in charge of the
bureau's cyber division.
The claims could not immediately be verified. An email to an address
associated with ShinyHunters was not immediately returned.
The hackers are seeking retribution over an FBI advisory
Miriam Wugmeister, a lawyer specializing in data, privacy and cybercrime
who tracks hacking outfits like ShinyHunters, said that based on the
group's past practices, there was reason to believe the hackers' claims,
“so I think it’s likely that they were able to compromise this website
and they got some data.”
She said that though the data that appeared to be compromised was the
type of personal information that is routinely accessed during a breach,
the hack nonetheless had alarming national security implications given
that it could expose agents and their families to extortion, swatting
and other harassment and because the identities of spouses were also
said to have been obtained.
“Even if the agents and the analysts and the employees are
sophisticated, you worry about their families too,” she said.
In its message, ShinyHunters said it would give the bureau one week to
correct or remove what it said were false allegations contained in an
FBI public advisory from May that described the organization as a “cyber
criminal group specializing in large-scale data breaches and extortion.”

[to top of second column]
|

That advisory characterized ShinyHunters as “threat actors” who
often "use their real or exaggerated claims of access to sensitive
or personal information to prompt payment from victims," commonly
harass or threaten victims and “may falsely claim to have sensitive
or compromising information, including embarrassing photographs or
videos of victims, which frequently do not exist.”
ShinyHunters said in its message to the FBI that it was “offended”
by those characterizations and demanded that the FBI remove those
claims. It did not say what would happen if the FBI did not do so
within a week.
“This is not a ransom, coercion, or extortion. Your federal policies
do not apply here. This PSA is NOT financially motivated,” the
hacking group's message said.
ShinyHunters has a reputation for “causing trouble and being
disruptive,” Wugmeister said, as evidenced by the group’s
involvement in a hack last spring of Canvas, an online system used
by thousands of schools and universities. The breach created chaos
as students tried to study for finals and prompted the FBI’s
advisory that ShinyHunters is now objecting to.
There have been other cyber incidents concerning the FBI
The hack was first reported by 404 Media, an online technology
publication that said a representative of ShinyHunters shared what
appeared to be a sample of personal data of 5,000 FBI employees,
including addresses, phone numbers and some information on spouses.
The publication said the ShinyHunters representative said the group
carried out the hack through an apparent vulnerability in Oracle
PeopleSoft software, commonly used by companies and government
agencies for large-scale data processing and human resources
purposes. The FBI said in its statement that it had not determined
whether the “point of breach” involved a “third-party or the FBI’s
enterprise.”

The FBI, the nation's premier federal law enforcement agency, has
been a common target for hackers.
In March, the FBI disclosed that it was investigating “suspicious
activities” on an internal system that contains sensitive
information related to surveillance operations and investigations.
Also that month, a pro-Iranian hacking group claimed to have hacked
an account of Patel's and posted online what appeared to be
years-old photographs of him, along with a work resume and other
personal documents dating back more than a decade.
The FBI described the compromised information as “historical in
nature” and said it involved "no government information.”
All contents © copyright 2026 Associated Press. All rights reserved |