FBI investigating hacking group’s claim of massive breach of agent info

Read the original at NBC News ↗
NBC News · collected 2026-09-23 · by Kevin Collier

Quick Summary

The FBI is investigating claims made by the hacking group ShinyHunters that they have breached the FBI’s jobs portal and stolen between 2 and 3 terabytes of sensitive files, including personal information about agents. The alleged hack occurred in retaliation for a public service announcement against the group released by the FBI in May. While the extent of the breach remains unverified, cybersecurity expert Cynthia Kaiser warns that exposing such information could endanger FBI personnel and their families by providing criminals with details necessary to target or harm them physically.
Written locally by qwen2.5:14b on 2026-09-23, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.

The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.

The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.

Written for “FBI Data Breach” on 2026-10-05, grounded in this article and the 22 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
25
claim-shaped sentences
Uncertain
36%
9 of 25 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
95.1
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
23
Crime & Law
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-23 · how these are computed

Story

📰 FBI Data Breach
Crime & Law · 23 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 36% of its claims. Each row says how that neighbour differs.
The Straits Times · 0.93 cosine similarity
⚖️ leaning not scored 🔴 29% hedged 6 of 21 📰 publisher trust 59
“Both articles report on ShinyHunters claiming a breach of the FBI's FBIjobs.gov portal, and the FBI's subsequent investigation of this claim.”
The Guardian · 0.93 cosine similarity
⚖️ leaning not scored 🔴 42% hedged 5 of 12 📰 publisher trust 60
“Both articles discuss the FBI's investigation into a breach of its jobs website, FBIjobs.gov, with claims by hackers to have stolen sensitive data.”
Times of India · 0.90 cosine similarity
⚖️ leaning not scored 🔴 22% hedged 5 of 23 📰 publisher trust 59
“Both articles describe the identical cyberattack on the FBI's job application website, with claims by ShinyHunters of stealing massive amounts of data, and the FBI confirming an investigation into unauthorized activity affecting FBIjobs.gov.”
The Hindu · 0.90 cosine similarity
⚖️ leaning not scored 🔴 62% hedged 5 of 8 📰 publisher trust 60
“Both articles describe the same hacking incident involving ShinyHunters claiming a breach of the FBI's FBIJobs.gov portal on the same day, September 22, 2026.”
The Independent · 0.85 cosine similarity
⚖️ leaning not scored 🔴 31% hedged 4 of 13 📰 publisher trust 59
“Both articles report on the same alleged hacking incident involving the FBI's recruitment website, with similar timing and content.”
Daily Mail
⚖️ leaning not scored 🔴 20% hedged 4 of 20 📰 publisher trust 65
“Both articles report on the same hacking incident involving ShinyHunters claiming to have stolen data from FBI agents, including details posted on the FBI's jobs website.”
The Sydney Morning Herald · 0.92 cosine similarity
⚖️ leaning not scored 🔴 28% hedged 8 of 29 📰 publisher trust 61
“Both articles refer to the FBI investigating claims by a hacking group about a data breach involving sensitive information on FBI employees and operations.”
ABC News (AU) · 0.90 cosine similarity
⚖️ leaning not scored 🔴 32% hedged 7 of 22 📰 publisher trust 61
“Both articles report on a cyber attack by ShinyHunters claiming to have stolen data from current and former FBI employees, with the FBI responding that it is investigating.”
CBS News · 0.88 cosine similarity
⚖️ leaning not scored 🔴 33% hedged 10 of 30 📰 publisher trust 66
“Both articles describe a claim by a hacking group called ShinyHunters about stealing FBI personnel data on the same date and refer to an ongoing investigation.”
The Straits Times · 0.88 cosine similarity
⚖️ leaning not scored 🔴 24% hedged 7 of 29 📰 publisher trust 59
“Both articles discuss a cyber-attack on FBIJobs.gov by ShinyHunters, involving stolen data of FBI staff.”

Publisher

NBC News · 962 article(s) · 0 correction(s) detected
No corrections detected for this publisher. That may mean careful reporting, or simply that nothing has been checked.

Who wrote this

Kevin Collier
2 article(s) here · 1 carrying a prediction
🔮 In a post on its website viewed by NBC News, ShinyHunters said the alleged hack was retaliation for a public service announcement about the group that the FBI posted in May.
🔮 The researchers, from a small company called Hacktron, found that by chaining together two unknown vulnerabilities, one in a third-party company called Discourse and one in how OpenAI validates its employees, they could access employees’ ChatGPT accounts.
Also by Kevin Collier
Nothing else under this byline is closely related to this article, so these are simply their most recent.

Topics

FBI FBIJobs.gov Halcyon NBC News ShinyHunters

Subjects

FBI ORG · 16× ShinyHunters ORG · 7× NBC News ORG · 4× FBIJobs.gov ORG · 3× Kaiser ORG · 3× U.S. NORP · 2× Anthropic ORG · 1× Cynthia Kaiser PERSON · 1× Halcyon GPE · 1×

Narrative

The hacking group, ShinyHunters, a cyber-extortion outfit that routinely hacks companies to steal their data and threatens to publish it on the dark web if not paid, said Wednesday that it had hacked into the FBI’s jobs portal and used that access to steal a major tranche of sensitive files, including ones that detail individual agents’ personal information.
framing: mixed · carried by 1 article(s) · first seen 2026-09-23
🔮 In a post on its website viewed by NBC News, ShinyHunters said the alleged hack was retaliation for a public service announcement about the group that the FBI posted in May.

Claims (25 extracted, 9 hedged)

The FBI said Wednesday that it is investigating a notorious hacking group over its claims to have stolen data on agents. uncertain
it → say → agents
“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the FBI said in a statement. asserted
FBI → claim → statement
“While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.” asserted
that → investigate → risk
The hacking group, ShinyHunters, a cyber-extortion outfit that routinely hacks companies to steal their data and threatens to publish it on the dark web if not paid, said Wednesday that it had hacked into the FBI’s jobs portal and used that access to steal a major tranche of sensitive files, including ones that detail individual agents’ personal information. asserted
that → hack → information
In a post on its website viewed by NBC News, ShinyHunters said the alleged hack was retaliation for a public service announcement about the group that the FBI posted in May. uncertain
FBI → view → May
“We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to ‘disrupt’ our operations, an effort that ultimately proved unsuccessful,” it said. asserted
it → disappoint → operations
It disagreed with the FBI’s characterizations in its PSA and said it would publish hacked data in a week if the PSA was not retracted. asserted
PSA → disagree → week
A representative of the group claimed to NBC News that they hacked the FBI’s job portal Monday and then gained access to other agency programs, stealing between 2 and 3 terabytes of files. asserted
they → claim → files
NBC News was not able to verify the extent of their claims. uncertain
News → verify → claims
An agency spokesperson said: “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” uncertain
FBI → say → FBIjobs.gov
Cynthia Kaiser, the former deputy cyber director of the FBI and a senior vice president at the cybersecurity company Halcyon, told NBC News that the alleged breach was worrying, as exposing personal information on FBI agents, who often sign their names to court documents used to prosecute criminals, endangers them. asserted
who → tell → them
“This type of information could be used by criminals to target or physically harm FBI agents, personnel and their families,” Kaiser said. uncertain
Kaiser → use → agents
“So I get concerned when you start thinking about physical addresses, who people’s spouses are, all of that.” asserted
spouses → get → that
Kaiser said that ShinyHunters was unlikely to be outright lying about its access but that like most cybercriminal extortionists, it tends to exaggerate its claims. uncertain
it → say → claims
“You often see a mixture of truth and lies when you’re dealing with threat actors like this,” she said. asserted
she → see → this
“They’re trying to show people, ‘Look what I have. asserted
I → try → what
You’re so scared of what I might show next, so you should do exactly what I should tell you to do, right?’” uncertain
I → ’re → you
ShinyHunters is a loosely defined group, with members scattered around the globe. asserted
members → define → globe
AI company Anthropic released one clue about its operations in a threat intelligence report earlier this month, when it said it had since December repeatedly disrupted clusters of ShinyHunters affiliates trying to use the company’s AI in their hacking operations. asserted
it → release → operations
While some cybercriminals can operate with relative impunity in countries that do not extradite to the U.S., the FBI does regularly arrest cybercriminals directly or with the help of law enforcement in countries friendly to the U.S. Antagonizing the FBI might tempt the agency to make more of an effort to arrest ShinyHunters members, Kaiser said. uncertain
Kaiser → operate → members
“That’s normally a recipe for a takedown. asserted
That → ’ → takedown
There’s going to be more resources against them,” she said. asserted
she → go → them
The ShinyHunters spokesperson said it was aware of that risk. asserted
it → say → risk
“We have been working on this since the release of the FBI FLASH report they made on us in May. uncertain
they → work → May
This was well planned and coordinated,” the spokesperson said. asserted
spokesperson → plan → ?
💬Give feedback
🕘History 🎫Support