ShinyHunters Claims FBI Agent Data Stolen From Jobs Portal

ShinyHunters claims it stole data on nearly all FBI agents via the FBIJobs portal.

Read as article

ShinyHunters Claims FBI Agent Data Stolen From Jobs Portal

By @sharedot · · 8 pages

ShinyHunters claims it stole data on nearly all FBI agents via the FBIJobs portal.

What Happened

The FBI says it is investigating a cyber-criminal group's claim that it compromised the fbijobs.gov portal and obtained FBI employee personally identifiable information. In a statement, the bureau said the point of breach is still undetermined — whether it originated with a third party or the FBI's own enterprise — and that it is 'actively and aggressively investigating this matter' while working with the third-party providers that support the jobs site. The group ShinyHunters has taken responsibility, saying it stole information on nearly all FBI agents and job applicants.

Why It's a Reversal

Extortion crews routinely exaggerate what they hold, so the notable twist is that newsroom verification lends partial weight to ShinyHunters' claim. According to International Business Times, 404 Media reviewed a sample of roughly 5,000 purported FBI personnel records containing names, home addresses, phone numbers, dates of birth and spouse details, and reporters cross-checked some phone numbers against public records and found matches. Yet the FBI has not confirmed the breach source, the claimed terabyte-scale dataset, or the attackers' asserted scale — so the story is a claimed breach, not a confirmed one.

The Claimed Attack Path

ShinyHunters says it exploited a previously unknown zero-day in Oracle PeopleSoft to reach FBI infrastructure hosted on AWS GovCloud, and also claims to have accessed systems it identified as Criminal Justice, Human Resources and Medlink. According to International Business Times, CBS News confirmed the FBI's recruiting arm uses PeopleSoft and AWS GovCloud but noted that neither the alleged PeopleSoft vulnerability nor the claimed attack path had been independently verified. The alleged intrusion began on September 22, when apply.fbijobs.gov was defaced with a message styled as a law-enforcement seizure notice.

Why Personnel Data Matters

Retired FBI supervisory special agent Jason Pack told Fox News Digital there is a meaningful difference between obtaining personnel information and gaining access to classified investigative systems, and that based on what is known there is 'no indication they have the keys to the kingdom.' Still, he warned that combining personal details with assignment information makes scams far more believable and carries counterintelligence risk: a foreign service could associate individuals with assignments to identify people to approach or assess for recruitment.

The Extortion Playbook

The FBI itself has previously warned about ShinyHunters' methods. In a May 2026 warning cited by International Business Times, the bureau said threat actors associated with the group use real or exaggerated claims of access to sensitive information to prompt payment from victims, and may falsely claim to hold compromising material that does not exist.

What Comes Next

Investigators still need to determine what information was actually accessed, how the breach occurred, and who may have been affected, and the FBI is working with the third-party providers behind fbijobs.gov to mitigate risk. The unresolved question is where the intrusion originated — inside the bureau's enterprise or at a vendor — which will shape both remediation and any accountability. Until the FBI independently verifies the dataset's size and sensitivity, the group's claims remain claims, however convincing the leaked sample looks.

Sources

  1. foxnews.com › FBI says source of its jobs portal breach still unknown as hackers allege employee data compromised
  2. ibtimes.sg › Did ShinyHunters Really Steal FBI Employee and Applicant Data?

More on Cybersecurity