FBI Probes ShinyHunters Claim Of Massive Breach Of FBI Personnel Data
On September 22, 2026, the cybercrime group ShinyHunters claimed on its dark-web site to have stolen more than 2 terabytes of data tied to FBI personnel and applicants.[1]
An FBI spokesperson said the bureau is aware of claims of unauthorized activity affecting FBIjobs.gov and is investigating.[1] Cybersecurity researchers told Axios the attack appears legitimate, and 404 Media obtained a sample that included data on about 5,000 alleged FBI agents.[1] ShinyHunters posted that stolen files include names, agent status, emails, phone numbers, home addresses, spouse information and Social Security numbers.[1]
ShinyHunters said it exploited a zero-day vulnerability in Oracle PeopleSoft to gain access to FBIjobs.gov and to seize and deface the bureau's jobs webpage.[1] The FBI jobs page was still offline Tuesday afternoon.[1]
If verified, the data could expose current and former employees to identity theft and could pose operational and safety risks for personnel. The FBI has not disclosed how many people may be affected as the investigation continues.[1]
Show source details & analysis (1 source)
📌 Key Facts
- On September 22, 2026, ShinyHunters claimed on its dark-web site to have stolen over 2 terabytes of data tied to FBI personnel and applicants.
- An FBI spokesperson said the bureau is aware of claims of unauthorized activity affecting FBIjobs.gov and is currently investigating.
- Cybersecurity researchers told Axios the attack appears legitimate; 404 Media obtained a sample including data on about 5,000 alleged FBI agents.
- ShinyHunters says the stolen data includes names, agent status, emails, phone numbers, home addresses and sometimes spouse information and Social Security numbers.
- The group claims it broke in via a zero-day in Oracle PeopleSoft and seized and defaced the FBI jobs webpage, which was still offline Tuesday afternoon.
📰 Source Timeline (1)
Follow how coverage of this story developed over time