The FBI is investigating a major security incident after the cybercriminal group ShinyHunters claimed to have breached FBIjobs.gov and stolen sensitive personal data on thousands of agents and job applicants. The hackers demand that FBI Director Kash Patel retract a May 2026 advisory detailing their extortion tactics. While the group claims the attack is not financially motivated, cybersecurity experts warn the data is highly valuable to foreign intelligence services.
ShinyHunters FBI breach claim
- ▪ShinyHunters claimed that after exploiting an alleged Oracle PeopleSoft zero-day vulnerability, the group accessed servers in Amazon Web Services' GovCloud environment and exfiltrated two to three terabytes of data
- ▪ShinyHunters claimed to have gained access to FBI networks on September 21, 2026, by exploiting a previously unknown zero-day vulnerability in Oracle's PeopleSoft software
- ▪The cybercriminal group ShinyHunters claimed on September 22, 2026, that it breached the FBI and stole sensitive personal data on current and former employees and job applicants
Stolen FBI personnel data
- ▪Reuters partially verified the authenticity of the FBI personnel data leaked by ShinyHunters in its claimed September 2026 breach of FBIjobs.gov by matching names, addresses, and Social Security numbers against credit bureau records and District 4 Labs databases
- ▪A sample of 5,000 records shared by ShinyHunters after its claimed September 2026 breach of FBIjobs.gov reportedly contained names, home addresses, phone numbers, dates of birth, and details on spouses and siblings of FBI personnel
FBI investigation response
- ▪The FBI issued a statement on September 22, 2026, confirming it is aware of claims made by ShinyHunters regarding unauthorized activity affecting FBIjobs.gov and is currently investigating
- ▪The FBI's job application portal, FBIjobs.gov, and its Special Agent Applicant Portal were taken offline and displayed maintenance or unavailability notices on September 22, 2026
Story comments
Loading comments…