The Sydney Morning Herald
· collected 2026-09-23 · by Raphael Satter, AJ Vicens
ShinyHunters, a hacking group, claims to have stolen sensitive data from the FBI, including personal information and job details for thousands of current and former employees. The alleged theft includes names, addresses, phone numbers, social security numbers, and emergency contacts, along with specifics about assignments in units dealing with Chinese spies, Russian intelligence, and drug cartels. Reuters has verified over 22 records by cross-referencing the data with public information. The FBI acknowledged awareness of the breach but stated that its cause remains undetermined and is under investigation.
Written locally by qwen2.5:14b on 2026-09-24,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.
The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.
The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.
Written for “FBI Data Breach” on 2026-10-05,
grounded in this article and the 22 other(s) covering the same event.
Washington - FBI data allegedly stolen by the hacking group ShinyHunters carries granular detail about scores of bureau officials’ job assignments, including sensitive work against Chinese spies, Russian intelligence, drug cartels, and more, Reuters has found.
uncertain
Reuters → steal → spies
The 5000-line spreadsheet – said by the hackers to represent only a small piece of their claimed two- to-three-terabyte trove – includes names, addresses, telephone numbers, dates of birth, social security numbers, and emergency contact details for what they claimed were thousands of FBI employees.
asserted
they → say → employees
It also includes details of assignments to specific field offices and, in some cases, to units engaged in high-stakes intelligence, security, or counterespionage work.
asserted
It → include → work
In a statement, the FBI said it was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information”.
asserted
it → say → information
The bureau said the cause of the breach was still undetermined, but that it was “actively and aggressively investigating the matter.”
The hackers said on Tuesday (Washington time) that they had breached the FBI, stealing data on a large number of current and former FBI employees.
asserted
they → say → employees
said it is holding the data hostage until the bureau rescinds an unflattering statement about the group issued in May.
uncertain
bureau → say → May
Former FBI counterintelligence operative Eric O’Neill said the data allegedly stolen by ShinyHunters was “a foreign intelligence service goldmine.”
“China would be incredibly interested to know the individuals who are working against it,” said O’Neill who
founded the cybersecurity company Nexasure AI after his stint at the bureau.
uncertain
who → say → bureau
He predicted that other hostile intelligence services would be eager to get their hands on the data, along with disgruntled extremists in the United States.
asserted
services → predict → States
“If I were on that list I would be very concerned,” he said.
asserted
he → say → list
ShinyHunters said in a statement on Wednesday that it was trying to keep the personnel information from circulating widely in the meantime.
asserted
it → say → meantime
“If the 5000 sample data records leak, it’s not because of us,” the group said.
asserted
group → leak → us
Although Reuters has not been able to authenticate the entire spreadsheet, it has been able to individually verify the details of more than 22 people by cross-referencing information in the hacked data with credit records and previous data leaks carried by the dark web intelligence platform District 4 Labs.
asserted
it → authenticate → platform
Some of the assignment details in the ShinyHunters’ data are indistinguishable from what employees themselves might say publicly, noting agents at field offices in Baltimore or Newark, New Jersey, for example.
But in some cases, the data referred to FBI units or initiatives that were sensitive or whose existence has not previously been disclosed.
uncertain
existence → say → units
The data names 14 staffers focused on China-related matters, including members of the “China criminal enterprise unit,” the “China tech transfer analysis unit,” and the “China intelligence
section.”
asserted
data → name → section
Nine others are listed as serving in Russia-related roles, including two in the “Russia Operations Section” and one working on “Russia Critical Infra and Tech Threat.”
asserted
others → list → Threat
Three people are listed as working in Iran- or Hezbollah-focused intelligence roles.
‘
asserted
people → list → roles
You don’t have to look far to find examples of undercover agents being harmed when their cover is blown.
asserted
cover → have → examples
’Trevor Hilligoss, chief intelligence officer for cybersecurity company SpyCloud
Eighteen others are listed as working with “data intercept” or “telecom intercept” technologies, or in the FBI’s “clandestine technical operations” unit, or its “covert access section,” or in video, audio, or electronic surveillance roles.
asserted
others → list → roles
A further 11 FBI staffers are listed as working in HUMINT, or human intelligence, jobs, including several listed as working in the “Humint program management section.”
asserted
staffers → list → section
Trevor Hilligoss, a former Army investigator who worked with the FBI, said the information tying specific named people to human intelligence work was particularly troubling.
“You don’t have to look far to find examples of undercover agents being harmed when their cover is blown,” he said.
asserted
he → work → examples
Hilligoss, now the chief intelligence officer for cybersecurity company SpyCloud, said his concerns were
heightened by the inclusion of emergency contacts – often spouses or children – “who may have less operational security knowledge than their relative that works in a sensitive field.”
uncertain
that → say → field
Reuters could not verify that all the job assignments were authentic or up-to-date, but it was able to match the career details or titles of eight people whose data was leaked to information in court filings, news articles, or public profiles on LinkedIn or to online posts on sites such as Instagram.
uncertain
data → verify → Instagram
ShinyHunters previously claimed credit for the purported theft of millions of business records from video game developer Rockstar Games, the maker of Grand Theft Auto, and an intrusion focused on the education tool Canvas that triggered widespread disruption across US schools.
asserted
that → claim → schools
In May, the FBI said ShinyHunters sometimes used “exaggerated claims of access to sensitive or personal information to prompt payment from victims.”
uncertain
ShinyHunters → say → victims
ShinyHunters said its “threats and claims are very real”, adding that the FBI’s statement was why it targeted the bureau.
uncertain
it → say → bureau
Reuters has not been able to verify what else the hackers are holding.
asserted
hackers → verify → what
ShinyHunters previously said they obtained files related to the vetting of employees and applicants, the contracting of background investigations, and agents’ sensitive medical data, but said on Wednesday it would not release any further data.
asserted
it → say → data
O’Neill, the former FBI operative, cautioned against drawing conclusions about what the hackers hold.
asserted
hackers → caution → what
“They’re really trying to scare the hell out of the FBI,” he noted.
asserted
he → try → FBI