A hacking group calling itself ShinyHunters says it broke into FBIJobs.gov, the online portal the FBI uses to recruit agents and staff, and walked away with sensitive personal data. The FBI confirmed on September 23, 2026 that it is investigating “claims regarding unauthorized activity affecting FBIjobs.gov,” according to The Guardian. Nearly a week later, the picture is still split between what the bureau has acknowledged and what the hackers claim, and the gap between those two accounts is where most of the real story sits.
This piece lays out what is actually confirmed as of September 29, 2026, what remains an unverified claim, who ShinyHunters is, and how this incident stacks up against other extortion campaigns and past government data losses. Numbers below are attributed to the outlets that reported them, not assumed.
What ShinyHunters Is Claiming About the FBI
ShinyHunters posted a message claiming it had breached the bureau, telling reporters “We have compromised the FBI,” a line carried by The Hacker News. The group went further, telling Reuters it holds “very sensitive data on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.” A representative for the group separately claimed the haul runs to 2 to 3 terabytes of files.
Those are the group’s own words, not confirmed facts. The FBI has not validated the “almost all agents” framing, and no independent party has verified the 2 to 3 terabyte figure or the completeness of what ShinyHunters says it took. What is verifiable is narrower: reporters received a sample of data, and the FBI opened a formal investigation into unauthorized activity tied to the jobs portal.
Timeline: How the FBIjobs.gov Story Broke
The claim surfaced in the third week of September 2026, when ShinyHunters began circulating data and statements to journalists. Reuters reported on the group’s assertion that it had breached the bureau on September 22. The FBI issued its first public acknowledgment the following day, September 23, telling The Guardian it was aware of the claims and investigating. 404 Media reviewed a sample of the leaked material and reported it appeared to concern roughly 5,000 FBI employees, a figure that has since been cited across other outlets covering the story.
By September 25, The Register had reached a ShinyHunters spokesperson directly. The group told the outlet it wanted to “demonstrate our technical capabilities and directly refute the misinformation disseminated by the FBI, journalists, and industry researchers,” a statement that reads as much like a public relations move as a technical disclosure. That pattern, claim first, technical proof later or never, has become something of a signature for extortion-driven hacking crews over the past two years, and this site has tracked a similar dynamic in ShinyHunters’ earlier hack of Clop’s own leak site, where the group demanded an eight-figure sum before Clop denied any deal and relocated its site within days.
The FBI’s Response, in Its Own Words
The bureau’s public statements have stayed narrow and deliberately noncommittal on scope. Its core line, as relayed to The Guardian, is that it is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” A fuller version of that statement described the situation as involving “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII).”
Crucially, the FBI has said the point of entry has not been determined. Investigators have not said whether the intrusion, if confirmed, ran through a third-party contractor that supports FBIJobs.gov or through the bureau’s own systems. The FBI said it is working with the outside providers that support the jobs portal as part of that effort. That distinction matters enormously for how bad this turns out to be: a breach of a vendor’s system handling recruitment data is a serious incident, but a breach reaching into FBI-run infrastructure would be a different order of problem entirely.
What’s Actually in the Data Sample
According to reporting reviewed by multiple outlets, the sample provided to journalists included names, home addresses, phone numbers, Social Security numbers, job assignments, and in some cases the names of family members. That is a meaningful set of personally identifiable information, the kind that fuels identity theft, targeted phishing, and in a law enforcement context, potential safety risks for the individuals named.
What is not established is how far that sample extends. 404 Media’s review pointed to information concerning around 5,000 employees, which is a specific and sourced figure, but it describes the sample that was reviewed, not necessarily the full scope of whatever ShinyHunters actually holds. Anyone applying figures beyond that reported sample size to the whole incident is speculating, not reporting.
Confirmed vs. Unconfirmed: A Reality Check
Breach stories move fast and claims tend to outrun verification. Here is where the FBIjobs.gov story actually stands, broken into what has been confirmed by an official source versus what remains an assertion from the hackers or unverified reporting.
| Claim | Status | Source |
|---|---|---|
| FBI investigating unauthorized activity affecting FBIjobs.gov | Confirmed | FBI statement via The Guardian |
| Sample data includes names, addresses, SSNs, phone numbers | Confirmed (sample reviewed by reporters) | Multiple outlets |
| Sample concerned roughly 5,000 employees | Reported, sourced | 404 Media |
| Point of entry (vendor vs. FBI systems) | Undetermined | FBI statement |
| ShinyHunters holds data on “almost all” agents and applicants | Unconfirmed claim | ShinyHunters, via Reuters |
| 2 to 3 terabytes of files stolen | Unconfirmed claim | ShinyHunters representative |
| Breach exploited a PeopleSoft vulnerability | Unconfirmed | Not established by FBI |
| Full sample authenticity and origin | Unconfirmed | Not independently verified |
Who Is ShinyHunters? Profile of an Extortion-Focused Crew
ShinyHunters has built a reputation over the past several years as a data-theft and extortion operation rather than a classic ransomware crew that encrypts networks. Its playbook leans on stealing large data sets, then pressuring victims publicly, often by contacting journalists directly, posting samples, and negotiating (or claiming to negotiate) payment to avoid a full release. Researchers who track the group generally describe it as opportunistic and social-engineering heavy, favoring compromised credentials, exposed cloud storage, and third-party vendor weaknesses over custom malware.
That approach was on display earlier this year when ShinyHunters hacked Clop’s own extortion leak site and demanded an eight-figure sum, an episode this site covered in detail, including Clop’s denial of any deal and its move to a new onion address within six days. Dutch authorities have also moved against the group directly. Police in the Netherlands arrested a 24-year-old suspect linked to ShinyHunters activity, a reminder that law enforcement pressure on the group has been building even as it continues to claim new victims.
How ShinyHunters Compares to Other Extortion Groups
ShinyHunters sits in a crowded field of data-theft and extortion operations that have dominated breach headlines through 2025 and 2026. The table below compares its publicly reported approach against a handful of other groups that show up regularly in incident reports, based on how each has been characterized in security reporting.
| Group | Primary Method | Public Posture | 2026 Activity Noted by This Site |
|---|---|---|---|
| ShinyHunters | Data theft and extortion, vendor/credential compromise | Media-facing, contacts journalists directly | Clop leak site hack, FBIjobs.gov claim |
| Clop | Mass exploitation of file-transfer software, bulk data theft | Leak-site publication, denies deals publicly | Denied ShinyHunters deal, relocated site |
| Scattered Spider | Social engineering, help-desk impersonation | High-profile targeting of large enterprises | Frequently cited in cross-sector breach reports |
| LockBit | Ransomware-as-a-service, encryption plus extortion | Affiliate network, leak-site deadlines | Continued affiliate activity despite prior takedowns |
| ALPHV/BlackCat | Ransomware-as-a-service, double extortion | Rust-based tooling, high ransom demands | Largely diminished after 2024 law enforcement action |
The distinction worth noting is that ShinyHunters, at least in this case, is not claiming to have deployed ransomware or locked anyone out of systems. It says it copied data and is using disclosure, or the threat of it, as leverage. That is a lower-friction attack than a full ransomware deployment and one that is often faster to pull off if it starts with a compromised vendor or exposed credential rather than a deep network intrusion.
Historical Context: When Government Personnel Data Gets Stolen
Federal personnel data has been a target before, and the stakes have historically been high. The Office of Personnel Management disclosed in 2015 that intruders had accessed records on more than 21 million current and former federal employees, contractors, and job applicants, including background-investigation files, according to government reports issued at the time. That breach reshaped how federal agencies think about contractor access and background-check data, and it remains the benchmark against which government personnel breaches tend to get measured.
The FBIjobs.gov claim is smaller in scale by every confirmed figure so far, but it touches a more sensitive population. Job applicants and employees of a federal law enforcement agency carry a different risk profile than general civil servants, since exposure of names, addresses, and family details can translate into safety concerns, not just fraud exposure. That is likely part of why the FBI’s public language has stayed cautious rather than dismissive, even while it has not confirmed the scope ShinyHunters is claiming.
Why a Federal Jobs Portal Is an Attractive Target
Recruitment portals are a soft spot across large organizations, government and private sector alike. They collect exactly the kind of personal data attackers want, names, Social Security numbers, addresses, employment history, and they are frequently run or partly operated by third-party vendors rather than an agency’s core IT team. That vendor layer widens the attack surface and can complicate incident response, since an agency has to coordinate with an outside provider to even determine what happened.
The FBI’s own statement leans into that ambiguity, noting investigators have not yet determined whether the point of compromise sits with a third party supporting FBIJobs.gov or within the bureau’s own systems. Recruitment and HR platforms rarely get the same security investment as mission-critical case-management systems, even though the data they hold can be just as damaging in the wrong hands.
The PeopleSoft Question and Why Attribution Is Hard
Some coverage has floated the idea that a vulnerability in Oracle PeopleSoft software played a role in the incident. That claim has not been confirmed by the FBI or independently verified, and it should be treated as speculation until an official source or a credible technical writeup backs it up. This site’s earlier report on FBIJobs.gov being down for six days with a PeopleSoft bug cited tracked that same unconfirmed thread as it developed.
Attribution in cases like this is hard for a structural reason. When an attacker exfiltrates data through a compromised vendor credential or a third-party contractor, the compromised organization often cannot immediately tell whether the underlying flaw sits in its own code, a partner’s code, or somewhere in between. That is exactly the situation the FBI has described here, and it is one reason official statements in the first week of a breach tend to stay vague on root cause even when they are specific about what data was exposed.
Market and Industry Fallout
A claimed breach of a federal law enforcement agency draws a different kind of scrutiny than a breach at a retailer or a SaaS vendor. Congressional oversight committees typically request briefings quickly when an agency like the FBI is involved, and federal IT contractors who support recruitment or HR systems across agencies often face renewed security reviews once one vendor relationship comes under the microscope, regardless of whether that specific vendor was the entry point here.
For the broader identity-protection and breach-monitoring industry, incidents involving Social Security numbers and home addresses tend to drive a short-term spike in credit-monitoring signups and identity-theft protection interest, a pattern that has repeated after nearly every major personnel-data incident over the past decade. Security vendors that sell to government agencies, meanwhile, will likely point to this case in sales conversations emphasizing vendor risk management and third-party access controls, an area this site has covered as extortion groups increasingly shift toward pure data theft over encryption-based ransomware.
What Was Said: Statements From Both Sides
Four statements, drawn directly from reporting, capture where each side stands. The FBI, in its most direct public comment, told The Guardian: “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.”
ShinyHunters, for its part, has not been shy about staking a broad claim. Speaking to Reuters, a representative for the group said: “We hold very sensitive data on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.” In comments to The Hacker News, the group put it even more bluntly: “We have compromised the FBI.” And in an interview with The Register, a ShinyHunters spokesperson framed the disclosure as a response to skepticism, saying the group wanted to “demonstrate our technical capabilities and directly refute the misinformation disseminated by the FBI, journalists, and industry researchers.”
Read together, those statements show a familiar gap in breach reporting: the victim organization speaking in careful, investigation-pending language, and the attacker speaking in maximalist, unverifiable terms designed to pressure a response.
What FBI Employees and Applicants Should Do Now
Anyone who has applied for an FBI position or currently works for the bureau should treat this as a live risk regardless of how the investigation resolves. That means watching bank and credit accounts for unfamiliar activity, placing a credit freeze with the major bureaus if one is not already in place, and being alert to phishing attempts that reference specific personal details, since stolen data of this type is often used to make follow-on scams look convincing.
The Federal Trade Commission’s IdentityTheft.gov site remains the standard starting point for anyone who suspects their information has been exposed, offering a step-by-step recovery plan tailored to the type of data involved. Suspected identity theft or fraud tied to this incident can also be reported to the FBI’s own Internet Crime Complaint Center at IC3.gov, which is a separate reporting channel from the jobs portal itself.
What Security Teams Everywhere Should Take From This
Outside of anyone directly affected, this incident is a useful prompt for security teams to revisit vendor risk assessments for HR and recruitment platforms specifically, since those systems are frequently overlooked relative to production or customer-facing infrastructure. It is also a reminder that strong authentication on internal and vendor-facing accounts matters as much for back-office systems as it does for anything customer-facing, a point this site has made in guidance on rolling out passkeys and what security teams should tell employees before doing so.
Incident response plans should also account for the vendor-attribution problem seen here. If a third party supports a public-facing portal, response playbooks need pre-agreed steps for joint investigation, shared logging access, and communication ownership, rather than figuring that out for the first time mid-crisis.
Predictions: Where This Investigation Goes From Here
- The FBI will likely issue a follow-up statement within the coming weeks that narrows the confirmed scope of affected individuals, once its review of the sample and any vendor logs is further along.
- Expect at least one congressional inquiry or oversight letter requesting a briefing, given the sensitivity of law enforcement personnel data and the precedent set by the 2015 OPM breach.
- ShinyHunters will probably continue its pattern of media outreach rather than a full public data dump, consistent with its approach in the Clop leak-site episode, using selective disclosure as ongoing leverage.
- If a third-party vendor is confirmed as the entry point, expect renewed scrutiny of that vendor’s other government contracts, not just its relationship with the FBI.
- Whether or not the PeopleSoft claim is ever confirmed, expect other agencies running similar HR or recruitment software to face pressure to audit and patch proactively, simply to avoid being next.
Frequently Asked Questions
Has the FBI confirmed it was hacked?
No. The FBI has confirmed it is investigating claims of unauthorized activity affecting FBIjobs.gov and has acknowledged a sample of data was reviewed by reporters, but it has not confirmed the scope ShinyHunters claims or how the intrusion occurred.
Who is ShinyHunters?
ShinyHunters is a hacking group known for data-theft and extortion campaigns rather than encryption-based ransomware. It has been tied to other 2026 incidents tracked by this site, including a hack of Clop’s own leak site.
What data was reportedly exposed?
According to reviewed samples, the data includes names, home addresses, phone numbers, Social Security numbers, job assignments, and in some cases family members’ names, concerning a sample reported by 404 Media to involve roughly 5,000 people.
Is the claim that ShinyHunters has data on almost all FBI agents true?
That is an unverified claim made by the group itself, reported by Reuters. It has not been confirmed by the FBI or any independent source.
Did the breach involve a PeopleSoft vulnerability?
That has been floated in some coverage but is not confirmed by the FBI. It should be treated as an unverified claim, not an established fact, until official confirmation.
What should I do if I applied for an FBI job or work there?
Monitor financial accounts, consider a credit freeze, watch for targeted phishing, and use IdentityTheft.gov for a structured recovery plan if you believe your information was exposed.
How does this compare to the 2015 OPM breach?
The OPM breach affected more than 21 million people according to government reports at the time, far larger than any confirmed figure in this case so far. The FBIjobs.gov claim involves a more sensitive population by role, even though the confirmed scope is currently smaller.
Where can I report suspected fraud related to this breach?
Suspected fraud or identity theft can be reported to the FBI’s Internet Crime Complaint Center at IC3.gov, separate from the jobs portal itself, or through IdentityTheft.gov for a personalized recovery plan.




