FBI hacked: Cyber gang claims it has sensitive data of agents and operations

Read the original at The Sydney Morning Herald ↗
The Sydney Morning Herald · collected 2026-09-23 · by Raphael Satter, AJ Vicens

Quick Summary

ShinyHunters, a hacking group, claims to have stolen sensitive data from the FBI, including personal information and job details for thousands of current and former employees. The alleged theft includes names, addresses, phone numbers, social security numbers, and emergency contacts, along with specifics about assignments in units dealing with Chinese spies, Russian intelligence, and drug cartels. Reuters has verified over 22 records by cross-referencing the data with public information. The FBI acknowledged awareness of the breach but stated that its cause remains undetermined and is under investigation.
Written locally by qwen2.5:14b on 2026-09-24, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.

The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.

The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.

Written for “FBI Data Breach” on 2026-10-05, grounded in this article and the 22 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
29
claim-shaped sentences
Uncertain
28%
8 of 29 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
61.2
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
23
Crime & Law
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-24 · how these are computed

Story

📰 FBI Data Breach
Crime & Law · 23 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 28% of its claims. Each row says how that neighbour differs.
The Straits Times · 0.90 cosine similarity
⚖️ leaning not scored 🔴 29% hedged 6 of 21 📰 publisher trust 59
“Both articles report on ShinyHunters claiming to have breached the FBI and stolen data on bureau employees, including detailed information about job assignments.”
CBS News · 0.87 cosine similarity
⚖️ leaning not scored 🔴 33% hedged 10 of 30 📰 publisher trust 66
“Both articles describe a single incident where the hacking group ShinyHunters claims to have stolen data from FBI personnel and job applicants, involving extensive details about employees' personal information and assignments.”
The Hindu · 0.86 cosine similarity
⚖️ leaning not scored 🔴 62% hedged 5 of 8 📰 publisher trust 60
“Both articles describe ShinyHunters claiming to have breached and stolen data from the FBI on September 22, 2026.”
Daily Mail
⚖️ leaning not scored 🔴 20% hedged 4 of 20 📰 publisher trust 65
“Both articles describe a hacking incident involving ShinyHunters stealing data from the FBI, including personal information of agents and job applicants.”
NBC News · 0.92 cosine similarity
⚖️ leaning not scored 🔴 36% hedged 9 of 25 📰 publisher trust 95
“Both articles refer to the FBI investigating claims by a hacking group about a data breach involving sensitive information on FBI employees and operations.”
Times of India · 0.92 cosine similarity
⚖️ leaning not scored 🔴 22% hedged 5 of 23 📰 publisher trust 59
“Both articles report on a cyberattack by ShinyHunters claiming to have stolen large amounts of sensitive data from FBI's job application website, affecting thousands of employees and applicants.”
The Straits Times · 0.90 cosine similarity
⚖️ leaning not scored 🔴 24% hedged 7 of 29 📰 publisher trust 59
“Both articles describe a single data breach by ShinyHunters against the FBI, revealing personal and sensitive information about FBI staff on nearly identical dates.”
The Guardian · 0.90 cosine similarity
⚖️ leaning not scored 🔴 42% hedged 5 of 12 📰 publisher trust 60
“Both articles report on the same hacking incident involving ShinyHunters claiming to have stolen sensitive data from the FBI's jobs website.”
The Straits Times · 0.89 cosine similarity
⚖️ leaning not scored 🔴 17% hedged 2 of 12 📰 publisher trust 59
“Both articles describe the hacking incident by ShinyHunters targeting the FBI on the same date and include similar details about stolen data involving employee information and sensitive work assignments.”
ABC News (AU) · 0.88 cosine similarity
⚖️ leaning not scored 🔴 32% hedged 7 of 22 📰 publisher trust 61
“Both articles describe the same cyber attack by ShinyHunters on the FBI, involving stolen data about current and former employees.”

Publisher

The Sydney Morning Herald · 2362 article(s) · 4 correction(s) detected
Running correction rate · 4 correction(s)
2026-10-03
Tennessee’s prisons chief to resign after failed execution of Christa Pike
2026-09-28
Inside the prison left abandoned for years – now set to reopen as DV offenders weigh on system
2026-09-19
What will happen to your most cherished possessions when you die? You don’t want to know
2026-09-18
What will happen to your most cherished possessions when you die? You don’t want to know

Who wrote this

AJ Vicens
2 article(s) here · 1 carrying a prediction
🔮 said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May.
🔮 In response, Chinese foreign ministry spokesperson Mao Ning said on Wednesday that China's progress was driven by "achieving high-level science and technological self-reliance." "We hope the U.S. will earnestly implement the important consensus reached by the leaders of both countries and refrain from making false accusations and smearing China," Mao said.
Also by AJ Vicens
Nothing else under this byline is closely related to this article, so these are simply their most recent.
Raphael Satter
1 article(s) here · 1 carrying a prediction
🔮 said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May.
The only article under this byline in the corpus.

Topics

China FBI Reuters ShinyHunters Washington

Subjects

FBI ORG · 11× China GPE · 5× ShinyHunters ORG · 5× Reuters ORG · 2× Washington GPE · 2× Chinese NORP · 1× Eric O’Neill PERSON · 1× FBIJobs.gov ORG · 1× O’Neill PERSON · 1× Russian NORP · 1×

Narrative

’Trevor Hilligoss, chief intelligence officer for cybersecurity company SpyCloud Eighteen others are listed as working with “data intercept” or “telecom intercept” technologies, or in the FBI’s “clandestine technical operations” unit, or its “covert access section,” or in video, audio, or electronic surveillance roles.
framing: mixed · carried by 1 article(s) · first seen 2026-09-24
🔮 said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May.
2026-09-24 · The Sydney Morning Herald
FBI hacked: Cyber gang claims it has sensitive data of agents and operations · mixed framing

Claims (29 extracted, 8 hedged)

Washington - FBI data allegedly stolen by the hacking group ShinyHunters carries granular detail about scores of bureau officials’ job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels, and more, Reuters has found. uncertain
Reuters → steal → spies
The 5000-line spreadsheet – said by the hackers to represent only a small piece of their claimed two- to-three-terabyte trove – includes names, addresses, telephone numbers, dates of birth, social security numbers, and emergency contact details for what they claimed were thousands of FBI employees. asserted
they → say → employees
It also includes details of assignments to specific field offices and, in some cases, to units engaged in high-stakes intelligence, security, or counterespionage work. asserted
It → include → work
In a statement, the FBI said it was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information”. asserted
it → say → information
The bureau said the cause of the breach was still undetermined, but that it was “actively and aggressively investigating the matter.” The hackers said on Tuesday (Washington time) that they had breached the FBI, stealing data on a large number of current and former FBI employees. asserted
they → say → employees
said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May. uncertain
bureau → say → May
Former FBI counterintelligence operative Eric O’Neill said the data allegedly stolen by ShinyHunters was “a foreign intelligence service goldmine.” “China would be incredibly interested to know the individuals who are working against it,” said O’Neill who founded the cybersecurity company Nexasure AI after his stint at the bureau. uncertain
who → say → bureau
He predicted that other hostile intelligence services would be eager to get their hands on the data, along with disgruntled extremists in the United States. asserted
services → predict → States
“If I were on that list I would be very concerned,” he said. asserted
he → say → list
ShinyHunters said in a statement on Wednesday that it was trying to keep the personnel information from circulating widely in the meantime. asserted
it → say → meantime
“If the 5000 sample data records leak, it’s not because of us,” the group said. asserted
group → leak → us
Although Reuters has not been able to authenticate the entire spreadsheet, it has been able to individually verify the details of more than 22 people by cross-referencing information in the hacked data with credit records and previous data leaks carried by the dark web intelligence platform District 4 Labs. asserted
it → authenticate → platform
Some of the assignment details in the ShinyHunters’ data are indistinguishable from what employees themselves might say publicly, noting agents at field offices in Baltimore or Newark, New Jersey, for example. But in some cases, the data referred to FBI units or initiatives that were sensitive or whose existence has not previously been disclosed. uncertain
existence → say → units
The data names 14 staffers focused on China-related matters, including members of the “China criminal enterprise unit,” the “China tech transfer analysis unit,” and the “China intelligence section.” asserted
data → name → section
Nine others are listed as serving in Russia-related roles, including two in the “Russia Operations Section” and one working on “Russia Critical Infra and Tech Threat.” asserted
others → list → Threat
Three people are listed as working in Iran- or Hezbollah-focused intelligence roles. ‘ asserted
people → list → roles
You don’t have to look far to find examples of undercover agents being harmed when their cover is blown. asserted
cover → have → examples
’Trevor Hilligoss, chief intelligence officer for cybersecurity company SpyCloud Eighteen others are listed as working with “data intercept” or “telecom intercept” technologies, or in the FBI’s “clandestine technical operations” unit, or its “covert access section,” or in video, audio, or electronic surveillance roles. asserted
others → list → roles
A further 11 FBI staffers are listed as working in HUMINT, or human intelligence, jobs, including several listed as working in the “Humint program management section.” asserted
staffers → list → section
Trevor Hilligoss, a former Army investigator who worked with the FBI, said the information tying specific named people to human intelligence work was particularly troubling. “You don’t have to look far to find examples of undercover agents being harmed when their cover is blown,” he said. asserted
he → work → examples
Hilligoss, now the chief intelligence officer for cybersecurity company SpyCloud, said his concerns were heightened by the inclusion of emergency contacts – often spouses or children – “who may have less operational security knowledge than their relative that works in a sensitive field.” uncertain
that → say → field
Reuters could not verify that all the job assignments were authentic or up-to-date, but it was able to match the career details or titles of eight people whose data was leaked to information in court filings, news articles, or public profiles on LinkedIn or to online posts on sites such as Instagram. uncertain
data → verify → Instagram
ShinyHunters previously claimed credit for the purported theft of millions of business records from video game developer Rockstar Games, the maker of Grand Theft Auto, and an intrusion focused on the education tool Canvas that triggered widespread disruption across US schools. asserted
that → claim → schools
In May, the FBI said ShinyHunters sometimes used “exaggerated claims of access to sensitive or personal information to prompt payment from victims.” uncertain
ShinyHunters → say → victims
ShinyHunters said its “threats and claims are very real”, adding that the FBI’s statement was why it targeted the bureau. uncertain
it → say → bureau
Reuters has not been able to verify what else the hackers are holding. asserted
hackers → verify → what
ShinyHunters previously said they obtained files related to the vetting of employees and applicants, the contracting of background investigations, and agents’ sensitive medical data, but said on Wednesday it would not release any further data. asserted
it → say → data
O’Neill, the former FBI operative, cautioned against drawing conclusions about what the hackers hold. asserted
hackers → caution → what
“They’re really trying to scare the hell out of the FBI,” he noted. asserted
he → try → FBI
💬Give feedback
🕘History 🎫Support