ShinyHunters, a cybercriminal group, claims it breached the FBI on Monday and stole 2 to 3 terabytes of data related to personnel and job applicants. The hackers allegedly used a new vulnerability with Oracle PeopleSoft, affecting criminal justice, human resources, and Medlink systems. While the FBI has acknowledged unauthorized activity on its jobs portal, it has not confirmed the breach or verified ShinyHunters' claims about stolen data.
Written locally by qwen2.5:14b on 2026-09-24,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.
The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.
The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.
Written for “FBI Data Breach” on 2026-10-05,
grounded in this article and the 22 other(s) covering the same event.
A notorious cybercriminal group claims it breached the FBI on Monday and stole data about personnel and job applicants.
uncertain
it → claim → personnel
The group, which calls itself ShinyHunters, claimed in communications posted on the dark web and exchanges with multiple media outlets that it stole 2 to 3 terabytes of data related to FBI and Justice Department workers.
asserted
it → call → workers
The hackers claim to have used a new vulnerability with Oracle PeopleSoft, a human resources management program.
uncertain
hackers → claim → PeopleSoft
RansomLook, an open-source ransomware intelligence archive that monitors data leak sites, has captured and archived two statements posted under the ShinyHunters identity concerning the group's claimed FBI breach.
asserted
that → monitor → breach
On Tuesday, ShinyHunters claimed in a post that was addressed to FBI Director Kash Patel and FBI Cyber Division Assistant Director Brett Leatherman: "We have compromised the FBI."
asserted
We → claim → FBI
The cybercriminals said they possessed sensitive information concerning nearly all FBI agents, as well as people who applied for FBI jobs.
asserted
who → say → jobs
It listed criminal justice, human resources and Medlink systems among the services that were affected.
asserted
that → list → services
On Tuesday, the home page for FBI careers had a "System Unavailable" message at the top of the page.
asserted
page → have → page
It read, "Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.
asserted
Apply.fbijobs.gov → read → ?
We apologize for the inconvenience."
asserted
We → apologize → inconvenience
The FBI has not confirmed the breach, but said Tuesday it was aware "of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
uncertain
it → confirm → FBIjobs.gov
On Wednesday, the agency offered a more detailed statement: "The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII).
asserted
FBI → offer → information
While the point of breach is still undetermined — whether a third party or the FBI's enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk."
Reuters and 404 Media reported that portions of data supplied by the hackers to those media outlets correspond to real FBI or Justice Department personnel, though neither has established that the records came from FBI systems.
asserted
records → investigate → systems
CBS News has not independently verified these findings.
uncertain
News → verify → findings
FBI documents confirm that the agency's recruiting arm uses PeopleSoft and AWS GovCloud.
asserted
arm → confirm → PeopleSoft
The new software vulnerability, breach of the FBI's systems and large-scale data theft are plausible, though ShinyHunters' claims have not yet been verified by CBS News.
uncertain
claims → verify → News
In the group's post, which was saved by RansomLook, ShinyHunters complained about an FBI FLASH report issued during the second quarter of 2026 and disputed the bureau's characterization of the group and its tactics.
asserted
ShinyHunters → save → group
The group said the FBI had suggested that ShinyHunters sometimes exaggerates access, harasses victims or relatives, participates in swatting and falsely claims to possess compromising material.
uncertain
ShinyHunters → say → material
The group also took issue with the FBI's description of ShinyHunters, denying that its demands are financially motivated and rejecting descriptions of their actions as ransom, coercion or extortion.
asserted
demands → take → ransom
In May 2026, the FBI issued two warnings related to ShinyHunters-linked activity.
uncertain
FBI → issue → activity
A May 8 FLASH bulletin described what it called the group's ecosystem — warning of stolen credentials, abuse of trusted vendor and cloud relationships, plus data theft and extortion sometimes involving harassment.
uncertain
it → describe → harassment
A week later, an Internet Crime Complaint Center (IC3) advisory cautioned that actors using the ShinyHunters name may make real or exaggerated claims of access, threaten victims and relatives, engage in swatting and falsely allege they hold compromising material in order to pressure targets.
uncertain
they → caution → targets
In both warnings, the FBI advised organizations not to pay or engage with their demands.
asserted
FBI → advise → demands
The group gave the FBI a deadline of one week to "correct or remove" portions of the earlier FLASH report.
asserted
group → give → report
Earlier this year, from May 25 through June 9, Google also documented ShinyHunters exploiting a different Oracle PeopleSoft zero-day vulnerability.
uncertain
ShinyHunters → document → vulnerability
CBS News has reached out to Oracle for comment.
asserted
News → reach → comment
While it is widely known for executing large-scale data and cloud theft, security researchers treat it not as one single, fixed entity, but rather as a shifting ecosystem of threat actors.
asserted
researchers → know → actors
This is at least the third potentially major cyber incident to impact the FBI or its employees so far this year.
asserted
This → impact → FBI
In March, the FBI revealed it had
activity targeting one of its systems.
asserted
it → reveal → systems
That system stores unclassified and law enforcement sensitive information, such as pen registers — which are surveillance tools that record phone numbers, IP addresses, signaling and other information, in real time — and trap-and-trace surveillance returns, as well as personally identifiable information related to subjects of FBI criminal probes.
asserted
that → store → probes