Cybercriminal group claims it stole FBI personnel and applicant data

Read the original at CBS News ↗
CBS News · collected 2026-09-23 · by Nicole Sganga

Quick Summary

ShinyHunters, a cybercriminal group, claims it breached the FBI on Monday and stole 2 to 3 terabytes of data related to personnel and job applicants. The hackers allegedly used a new vulnerability with Oracle PeopleSoft, affecting criminal justice, human resources, and Medlink systems. While the FBI has acknowledged unauthorized activity on its jobs portal, it has not confirmed the breach or verified ShinyHunters' claims about stolen data.
Written locally by qwen2.5:14b on 2026-09-24, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.

The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.

The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.

Written for “FBI Data Breach” on 2026-10-05, grounded in this article and the 22 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
30
claim-shaped sentences
Uncertain
33%
10 of 30 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
65.5
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
23
Crime & Law
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-24 · how these are computed

Story

📰 FBI Data Breach
Crime & Law · 23 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 33% of its claims. Each row says how that neighbour differs.
The Sydney Morning Herald · 0.87 cosine similarity
⚖️ leaning not scored 🔴 28% hedged 8 of 29 📰 publisher trust 61
“Both articles describe a single incident where the hacking group ShinyHunters claims to have stolen data from FBI personnel and job applicants, involving extensive details about employees' personal information and assignments.”
BBC News
⚖️ leaning not scored 🔴 24% hedged 10 of 41 📰 publisher trust 78
“Both articles describe the same data breach of FBI personnel and applicant data by ShinyHunters on the same date.”
404 Media
⚖️ leaning not scored 🔴 11% hedged 5 of 45 📰 publisher trust 95
“Both articles discuss the same cyber attack by ShinyHunters on the FBI and mention the stolen data including personnel and applicant information, indicating they are reporting on the same specific incident.”
The Straits Times · 0.89 cosine similarity
⚖️ leaning not scored 🔴 29% hedged 6 of 21 📰 publisher trust 59
“Both articles describe ShinyHunters claiming to have breached the FBI on September 22, stealing data related to employees and job applicants.”
NBC News · 0.88 cosine similarity
⚖️ leaning not scored 🔴 36% hedged 9 of 25 📰 publisher trust 95
“Both articles describe a claim by a hacking group called ShinyHunters about stealing FBI personnel data on the same date and refer to an ongoing investigation.”
ABC News (AU) · 0.87 cosine similarity
⚖️ leaning not scored 🔴 32% hedged 7 of 22 📰 publisher trust 61
“Both articles describe a cyber attack by ShinyHunters on the FBI resulting in stolen data about current and former employees, with similar timing and context.”
The Hindu · 0.86 cosine similarity
⚖️ leaning not scored 🔴 62% hedged 5 of 8 📰 publisher trust 60
“Both articles describe ShinyHunters claiming to have breached the FBI on the same day (September 22, 2026), targeting personnel and applicant data using a new vulnerability in Oracle PeopleSoft.”
The Straits Times · 0.86 cosine similarity
⚖️ leaning not scored 🔴 24% hedged 7 of 29 📰 publisher trust 59
“Both articles describe ShinyHunters claiming to have stolen FBI personnel data, with Article B providing more detailed information about sensitive records included in the theft.”
The Independent · 0.85 cosine similarity
⚖️ leaning not scored 🔴 31% hedged 4 of 13 📰 publisher trust 59
“Both articles report on a cyber group claiming to have hacked the FBI's recruitment website and stolen data on employees and job applicants, with similar dates and details about the breach.”
The Straits Times · 0.85 cosine similarity
⚖️ leaning not scored 🔴 17% hedged 2 of 12 📰 publisher trust 59
“Both articles refer to ShinyHunters claiming a breach of FBI data on similar dates and provide details about stolen personnel information.”

Publisher

CBS News · 1955 article(s) · 6 correction(s) detected
Running correction rate · 6 correction(s)
2026-10-03
Tennessee prison system head to resign after failed Christa Pike execution
2026-10-02
Christa Pike unconscious, on ventilator after botched execution: Lawyers
2026-10-01
Rick Ross arrested on domestic violence charges in Miami Beach
2026-09-17
After nitrogen execution blocked, Alabama inmate to die by lethal injection
2026-09-14
The AI bubble is leaking air, some economists say. Should investors worry?
2026-08-24
Sean Grayson, convicted in killing of Sonya Massey, dies in prison, attorney says

Who wrote this

Nicole Sganga
6 article(s) here · 1 carrying a prediction
🔮 In May 2026, the FBI issued two warnings related to ShinyHunters-linked activity.
🔮 A cyberattack that penetrates those operational systems could potentially be weaponized or manipulated.
🔮 When asked for evidence that the administration's new mail voting rules — which are due to a series of court orders — would prevent fraud, the attorney general initially said that "there's a lot of evidence," arguing that it was inherently the case that "if you're using mail-in voting, the potential for fraud is greater than in-person voting with ID."Pressed further on what evidence he had that mail voting presents a greater risk of fraud than in-person voting with identification, Blanche maintained there is "a lot of evidence."
🔮 Attorney General Todd Blanche vowed that the federal government will continue releasing records related to the Sept. 11, 2001, terrorist attacks, doubling down on U.S. assertions that documents still being withheld are not being kept secret to protect Saudi Arabia or any other government.
🔮 Vice President JD Vance announced Monday the Trump administration will suspend roughly 870,000 people suspected of defrauding pandemic-era small business programs from receiving future federal loans.
🔮 "The latest date presents a painful question for the families of the victims: After so many missed deadlines and prolonged pre-trial proceedings, will this case move forward as planned?
Also by Nicole Sganga
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 6 articles by Nicole Sganga →

Topics

FBI FBIjobs.gov Justice Department PeopleSoft ShinyHunters

Subjects

FBI ORG · 22× ShinyHunters ORG · 7× FBIjobs.gov ORG · 3× CBS News ORG · 2× FLASH ORG · 2× Justice Department ORG · 2× Brett Leatherman PERSON · 1× FBI Cyber Division ORG · 1× Kash Patel PERSON · 1× Oracle ORG · 1×

Narrative

While the point of breach is still undetermined — whether a third party or the FBI's enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk." Reuters and 404 Media reported that portions of data supplied by the hackers to those media outlets correspond to real FBI or Justice Department personnel, though neither has established that the records came from FBI systems.
framing: mixed · carried by 1 article(s) · first seen 2026-09-24
🔮 In May 2026, the FBI issued two warnings related to ShinyHunters-linked activity.

Claims (30 extracted, 10 hedged)

A notorious cybercriminal group claims it breached the FBI on Monday and stole data about personnel and job applicants. uncertain
it → claim → personnel
The group, which calls itself ShinyHunters, claimed in communications posted on the dark web and exchanges with multiple media outlets that it stole 2 to 3 terabytes of data related to FBI and Justice Department workers. asserted
it → call → workers
The hackers claim to have used a new vulnerability with Oracle PeopleSoft, a human resources management program. uncertain
hackers → claim → PeopleSoft
RansomLook, an open-source ransomware intelligence archive that monitors data leak sites, has captured and archived two statements posted under the ShinyHunters identity concerning the group's claimed FBI breach. asserted
that → monitor → breach
On Tuesday, ShinyHunters claimed in a post that was addressed to FBI Director Kash Patel and FBI Cyber Division Assistant Director Brett Leatherman: "We have compromised the FBI." asserted
We → claim → FBI
The cybercriminals said they possessed sensitive information concerning nearly all FBI agents, as well as people who applied for FBI jobs. asserted
who → say → jobs
It listed criminal justice, human resources and Medlink systems among the services that were affected. asserted
that → list → services
On Tuesday, the home page for FBI careers had a "System Unavailable" message at the top of the page. asserted
page → have → page
It read, "Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable. asserted
Apply.fbijobs.gov → read → ?
We apologize for the inconvenience." asserted
We → apologize → inconvenience
The FBI has not confirmed the breach, but said Tuesday it was aware "of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." uncertain
it → confirm → FBIjobs.gov
On Wednesday, the agency offered a more detailed statement: "The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII). asserted
FBI → offer → information
While the point of breach is still undetermined — whether a third party or the FBI's enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk." Reuters and 404 Media reported that portions of data supplied by the hackers to those media outlets correspond to real FBI or Justice Department personnel, though neither has established that the records came from FBI systems. asserted
records → investigate → systems
CBS News has not independently verified these findings. uncertain
News → verify → findings
FBI documents confirm that the agency's recruiting arm uses PeopleSoft and AWS GovCloud. asserted
arm → confirm → PeopleSoft
The new software vulnerability, breach of the FBI's systems and large-scale data theft are plausible, though ShinyHunters' claims have not yet been verified by CBS News. uncertain
claims → verify → News
In the group's post, which was saved by RansomLook, ShinyHunters complained about an FBI FLASH report issued during the second quarter of 2026 and disputed the bureau's characterization of the group and its tactics. asserted
ShinyHunters → save → group
The group said the FBI had suggested that ShinyHunters sometimes exaggerates access, harasses victims or relatives, participates in swatting and falsely claims to possess compromising material. uncertain
ShinyHunters → say → material
The group also took issue with the FBI's description of ShinyHunters, denying that its demands are financially motivated and rejecting descriptions of their actions as ransom, coercion or extortion. asserted
demands → take → ransom
In May 2026, the FBI issued two warnings related to ShinyHunters-linked activity. uncertain
FBI → issue → activity
A May 8 FLASH bulletin described what it called the group's ecosystem — warning of stolen credentials, abuse of trusted vendor and cloud relationships, plus data theft and extortion sometimes involving harassment. uncertain
it → describe → harassment
A week later, an Internet Crime Complaint Center (IC3) advisory cautioned that actors using the ShinyHunters name may make real or exaggerated claims of access, threaten victims and relatives, engage in swatting and falsely allege they hold compromising material in order to pressure targets. uncertain
they → caution → targets
In both warnings, the FBI advised organizations not to pay or engage with their demands. asserted
FBI → advise → demands
The group gave the FBI a deadline of one week to "correct or remove" portions of the earlier FLASH report. asserted
group → give → report
Earlier this year, from May 25 through June 9, Google also documented ShinyHunters exploiting a different Oracle PeopleSoft zero-day vulnerability. uncertain
ShinyHunters → document → vulnerability
CBS News has reached out to Oracle for comment. asserted
News → reach → comment
While it is widely known for executing large-scale data and cloud theft, security researchers treat it not as one single, fixed entity, but rather as a shifting ecosystem of threat actors. asserted
researchers → know → actors
This is at least the third potentially major cyber incident to impact the FBI or its employees so far this year. asserted
This → impact → FBI
In March, the FBI revealed it had activity targeting one of its systems. asserted
it → reveal → systems
That system stores unclassified and law enforcement sensitive information, such as pen registers — which are surveillance tools that record phone numbers, IP addresses, signaling and other information, in real time — and trap-and-trace surveillance returns, as well as personally identifiable information related to subjects of FBI criminal probes. asserted
that → store → probes
💬Give feedback
🕘History 🎫Support