‘We hacked the FBI’: ShinyHunters claims massive breach of FBI employee data
The hacking group ShinyHunters claims to have breached the FBI's online recruitment portal and stolen sensitive information belonging to current and former bureau employees, as well as job applicants.

The FBI confirmed on September 23 that it was investigating claims of unauthorized activity involving its FBIJobs.gov portal and potential exposure of employee personally identifiable information (PII). However, the agency has not confirmed the full extent of the alleged breach or whether its internal systems were compromised.
In messages posted online, the group declared, "We have compromised the FBI," claiming it had obtained between 2 and 3 terabytes of data covering nearly all FBI agents and people who had applied for jobs with the agency.
The incident has raised concerns about the exposure of sensitive personnel information, particularly if records belonging to intelligence analysts, investigators and surveillance specialists were accessed.
Hackers claim Oracle vulnerability enabled intrusion
According to ShinyHunters, the attack began with a previously unknown vulnerability in Oracle PeopleSoft, a human resources management platform used by the FBI's recruitment operation.
The group claims the vulnerability allowed attackers to execute malicious code remotely on the compromised servers. It then allegedly moved from the recruitment portal into FBI-managed infrastructure hosted on Amazon Web Services GovCloud, downloading data belonging to current, former and prospective employees.
ShinyHunters said the compromised services included human resources systems, MedLink and Criminal Justice Information Services.
The group also claimed responsibility for defacing the FBI recruitment website, which displayed a system-unavailable notice following the incident.
Neither Oracle nor Amazon Web Services had publicly confirmed the alleged vulnerability or data theft at the time of reporting. The FBI said investigators were still determining whether the initial compromise involved a third-party provider or the bureau's own enterprise systems.
Sample data reportedly includes sensitive employee information
Although the FBI has not verified the total volume of stolen information, several news organizations have examined samples allegedly supplied by the hackers.
Nextgov/FCW reported that a sample contained approximately 5,000 employee entries, including names, home addresses, telephone numbers and information about spouses and siblings. The publication also reported that some records identified personnel involved in intelligence gathering, electronic surveillance and other sensitive operations.
Reuters and 404 Media also reported that portions of the supplied data appeared to correspond to real FBI and Justice Department personnel. However, the findings do not independently establish that the information originated from the FBI's internal systems or verify the full scope of the alleged theft.
If confirmed, the exposure could create risks beyond conventional identity theft. Personal details linked to employees' official roles could make it easier for criminals or foreign intelligence services to identify, target or harass personnel and their families.
Attack allegedly triggered by FBI warning
ShinyHunters says the intrusion was motivated by a dispute with the FBI over a May 2026 cybersecurity warning that described the group's alleged tactics.
The warning accused ShinyHunters-linked actors of stealing data, demanding payments and using harassment, threatening communications and, in some cases, swatting against victims and their relatives.
The hackers rejected those characterizations, arguing that the bureau had made false allegations about their activities. They gave the FBI one week to correct or retract the statements, saying the latest operation was not financially motivated.
The FBI has not publicly indicated whether it intends to amend the warning or how it will respond to the group's demands.
Mounting Cyber Incidents
The alleged breach adds to a series of cybersecurity incidents involving the FBI and its personnel in 2026.
In March, the bureau disclosed suspicious cyber activity affecting a system containing unclassified law enforcement information and personally identifiable information connected to criminal investigations. FBI Director Kash Patel's personal email account was also targeted in a separate incident.
The current investigation is focused on identifying the initial point of access, determining which systems were affected, and assessing whether sensitive employee information was exposed.
For now, the FBI has confirmed the investigation, not the hackers' claim that they possess records on virtually its entire workforce.












