FBI Hackers Say They Won’t Publish Massive Trove of FBI Employee Data

Read the original at 404 Media ↗
404 Media · collected 2026-09-28 · by Joseph Cox

Quick Summary

Hackers from ShinyHunters revealed on Monday that they will not release the stolen personal information of FBI employees and applicants, including medical records and addresses, despite previously threatening to do so within a week unless certain demands were met. The hackers claimed they had accessed between two and three terabytes of data, which includes details about family members and job roles. Although ShinyHunters initially framed their actions as an extortion attempt to combat disinformation about their activities, they now assert that publishing the data was never part of their plan, reducing immediate concerns over potential misuse by criminals targeting FBI personnel.
Written locally by qwen2.5:14b on 2026-09-28, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.

The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.

The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.

Written for “FBI Data Breach” on 2026-10-05, grounded in this article and the 22 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
45
claim-shaped sentences
Uncertain
11%
5 of 45 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
95.0
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
23
Crime & Law
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-28 · how these are computed

Story

📰 FBI Data Breach
Crime & Law · 23 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 11% of its claims. Each row says how that neighbour differs.
CBS News
⚖️ leaning not scored 🔴 33% hedged 10 of 30 📰 publisher trust 66
“Both articles discuss the same cyber attack by ShinyHunters on the FBI and mention the stolen data including personnel and applicant information, indicating they are reporting on the same specific incident.”
CBC News
⚖️ leaning not scored 🔴 13% hedged 4 of 30 📰 publisher trust 77
“Both articles describe ShinyHunters announcing they will not publish stolen FBI data, referencing the same breach and timeframe.”
The Sydney Morning Herald · 0.86 cosine similarity
⚖️ leaning not scored 🔴 28% hedged 8 of 29 📰 publisher trust 61
“Both articles discuss the same hacking incident by ShinyHunters involving stolen data from FBI employees and applicants.”
Fox News
⚖️ leaning not scored 🔴 33% hedged 6 of 18 📰 publisher trust 69
“Both articles refer to a single cyber-attack on the FBI's jobs portal and mention hackers claiming to have compromised employee data.”
BBC News
⚖️ leaning not scored 🔴 35% hedged 9 of 26 📰 publisher trust 78
“Both articles describe a single hacking incident involving the theft of sensitive medical and personal data from FBI special agents.”
The Straits Times
⚖️ leaning not scored 🔴 17% hedged 2 of 12 📰 publisher trust 59
“Both articles discuss the same hackers (ShinyHunters) stealing sensitive data including medical records from FBI staff.”
ABC News (US)
⚖️ leaning not scored 🔴 67% hedged 8 of 12 📰 publisher trust 59
“Both articles discuss an alleged hack of FBI personnel data by ShinyHunters, involving medical records and personal information.”
BBC News
⚖️ leaning not scored 🔴 24% hedged 10 of 41 📰 publisher trust 78
“Both articles refer to a single data breach affecting all FBI employees and applicants, with similar details about stolen personal information and security concerns.”
The Straits Times
⚖️ leaning not scored 🔴 24% hedged 7 of 29 📰 publisher trust 59
“Both articles describe ShinyHunters hackers stealing FBI staff medical and personal records in the same breach incident.”
CBC News
⚖️ leaning not scored 🔴 21% hedged 7 of 34 📰 publisher trust 77
“Both articles discuss ShinyHunters claiming responsibility for hacking and stealing data from the FBI on the same date.”

Publisher

404 Media · 104 article(s) · 0 correction(s) detected
No corrections detected for this publisher. That may mean careful reporting, or simply that nothing has been checked.

Who wrote this

Joseph Cox
21 article(s) here · 1 carrying a prediction
🔮 Although any potential damage will be less if ShinyHunters doesn’t publish the data publicly, the theft happening at all still presents much of those same national security risks, with the data providing granular insight into how the FBI operates. “Since the very beginning we had made our decision that we would never publish this data.
🔮 What is different in this latest Copilot episode, and 404 Media’s reporting on contractors at other AI companies like OpenAI, is that the content humans are reviewing are prompts and uploads that chatbot users may assume are private, and that the contractors are not looking at this material to train the models to filter out offensive images or for some other safety concern.
🔮 And the ALPR Hostlist Management Audit report details changes made to alerts the agency may receive.
🔮 Georgia State University has rescinded a job offer given to a high profile activist who is currently fighting a case in which he allegedly wiped a security-focused Android phone before Customs and Border Protection (CBP) could search it.
🔮 The prompts these people review can include whole conversations between users and the chatbot, conversations that most of ChatGPT’s more than 900 million users probably don’t realize may be read by actual people.
🔮 Apparently over the cross of that source and interviewer relationship, Biden “asked if he could use our mailing list whenever he launched a new product,” according to a statement posted by Channel 5 to X on Monday.
🔮 Border Patrol is running secretive predictive policing units that analyze Americans’ financial activity and other data, then feed that intelligence to local police who pull people over who are not suspected of any specific crime, but which the government thinks may be worth searching, 404 Media has found.
🔮 The comments highlight how Axon is trying to take advantage of sustained opposition against Flock's license plate cameras, with one law enforcement customer suggesting a camera redesign would “help with the optics while we batten down the hatches” as the backlash spreads.
🔮 The baba lao was going to do a ritual designed to ensure a Nigerian scammer would make more money in his blackmailing or manipulation of an overseas victim, maybe back in the United States.
🔮 “I would rather your event flyer look like this than see more AI slop,” one flyer posted to Instagram, written in pencil on a page of lined paper, reads.
2026-08-28 · assertive framing · Businesses Go Viral for Making Signs Without AI
Also by Joseph Cox
Nothing else under this byline is closely related to this article, so these are simply their most recent.
All 21 articles by Joseph Cox →

Topics

404 Media Darkside FBI OSINT Industries ShinyHunters

Subjects

FBI ORG · 13× ShinyHunters ORG · 10× 404 Media ORG · 7× Bureau ORG · 1× China GPE · 1× District 4 ORG · 1× FBIJobs.gov ORG · 1× OSINT Industries ORG · 1× Reuters ORG · 1× Russia GPE · 1×

Narrative

Although any potential damage will be less if ShinyHunters doesn’t publish the data publicly, the theft happening at all still presents much of those same national security risks, with the data providing granular insight into how the FBI operates. “Since the very beginning we had made our decision that we would never publish this data.
framing: assertive · carried by 1 article(s) · first seen 2026-09-28
🔮 Although any potential damage will be less if ShinyHunters doesn’t publish the data publicly, the theft happening at all still presents much of those same national security risks, with the data providing granular insight into how the FBI operates. “Since the very beginning we had made our decision that we would never publish this data.

Claims (45 extracted, 5 hedged)

The hackers behind the massive FBI breach told 404 Media on Monday they do not intend to publish the data. asserted
they → tell → data
The breach, in which the hackers stole personal information on “all FBI employees and applicants” including physical addresses, job roles, names of spouses, and medical records, represents a significant national security and counterintelligence threat. asserted
hackers → steal → threat
Criminals in the same ecosystem as the hacking group, called ShinyHunters, have previously used hacked phone data to track and harass the FBI agents investigating them. asserted
Criminals → hack → them
When 404 Media first broke news of the breach, the group sent the personal data of an agent and their spouse who they said was investigating the group. asserted
they → break → group
Although any potential damage will be less if ShinyHunters doesn’t publish the data publicly, the theft happening at all still presents much of those same national security risks, with the data providing granular insight into how the FBI operates. “Since the very beginning we had made our decision that we would never publish this data. asserted
we → publish → data
We have never intended to nor have we ever planned to,” a representative of ShinyHunters told 404 Media on Monday. asserted
representative → intend → Monday
Last week, ShinyHunters provided 404 Media with a sample list of 5,000 FBI officials, in many cases including details on their spouses too. asserted
ShinyHunters → provide → spouses
404 Media verified this data by cross-referencing it with open source records available in the research tool OSINT Industries, and previously compromised data in Darkside, a tool made by cybersecurity company District 4. asserted
Media → verify → District
At the time of the breach, the ShinyHunters representative said the exfiltrated data totalled between two and three terabytes. asserted
data → say → terabytes
In a since-deleted announcement posted to their leak site, ShinyHunters wrote, “All FBI data was compromised including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. asserted
data → delete → employees
We have a lot more than we claim here.” uncertain
we → have → more
ShinyHunters said on its site that it was “allowing you [the FBI] a time of 1 week to correct” or remove a previously published FBI report. asserted
it → say → report
In that report, the FBI said that ShinyHunters exaggerates its claims of access to sensitive data to elicit payment, and that the group sends threatening text messages and phone calls to victims and their families. uncertain
group → say → victims
Typically, ShinyHunters extorts victims by threatening to publish their data online if the target organization doesn’t pay up. asserted
organization → extort → data
In the new statement on Monday, ShinyHunters told 404 Media “Since the very beginning of this event we have unequivocally and assiduously emphasised this is NOT extortion, this is NOT ransom, this is NOT financially motivated. asserted
this → tell → event
However, the public and media has misinterpreted this for an extortion and have assumed that if the victim entity does not comply within 1 week which we all know including ourselves that they would never comply, we would publish all the data.” asserted
we → misinterpret → data
“This was all a marketing campaign to protect our business and actively combat disinformation. asserted
This → protect → disinformation
If we made this statement normally then this much attention to our words and intentions would’ve never been this widespread. asserted
attention → make → words
We’d have been ignored and disregarded. asserted
We → ignore → ?
However, now everyone knows what the issue is and what we are doing. asserted
we → know → what
Everyone is reading about it. asserted
Everyone → read → it
We proved our points on several occasions. asserted
We → prove → occasions
We do not care what the public says and we are not affected by it nor do we cloud our judgement by external opinions and thoughts,” the statement added. asserted
statement → care → opinions
The FBI told 404 Media in a statement “The FBI is working around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted — including multiple Bureau wide communications within 24 hours of public reporting. uncertain
who → tell → reporting
The FBI treats the security of its information and the safety of its workforce as top priorities, and our investigation is ongoing. asserted
investigation → treat → priorities
Last week, Reuters reported some of the personnel in the 5,000 officials sample include those assigned to investigate China or Russia, presenting a serious national security threat. asserted
some → report → threat
404 Media found the hack also exposed the names and personal data of some members of the FBI’s secretive hacking team, called the Remote Operations Unit. asserted
hack → find → team
The BBC reported the breach included Special Agents’ blood and urine test results. asserted
breach → report → results
Reuters reported the hack also impacted mental health evaluations. asserted
hack → report → evaluations
“We again want to emphasise that this is not extortion, it was never one to begin with, not a threat, not a ransom, and not financially motivated. asserted
it → want → ?
Nothing will happen. asserted
Nothing → happen → ?
We are way past this situation in our business’s operations and we confidently believe we have been successful due to seeing a recent influx of success in our operations,” ShinyHunters told 404 Media on Monday. asserted
ShinyHunters → believe → Monday
The data of 5,000 FBI employees has spread, though. asserted
data → spread → employees
On its site ShinyHunters said it only provided the data to “a select group of prominent U.S. media organizations solely to verify our claims.” uncertain
it → say → claims
Soon after, the cybersecurity researcher and YouTuber John Hammond said they obtained a copy too. asserted
they → say → copy
Hammond declined to tell 404 Media how he obtained the data when asked last week. asserted
he → decline → data
This information, as well as the alleged two to three terabytes of overall stolen data, is likely of high interest to foreign intelligence agencies, potentially making anyone who has obtained it a target. asserted
who → allege → it
In a separate case that shows the potential danger of stolen data, a man linked to the hack of all AT&T customer metadata records communicated with an email address he believed belonged to a foreign country’s military intelligence service, and attempted to sell the data to that country, 404 Media previously reported. asserted
Media → show → country
Asked last week if ShinyHunters planned on selling the hacked FBI data to a foreign intelligence agency, the representative said, “No definitely not.” asserted
representative → ask → agency
On Monday, the New York Times reported the FBI sent a memo to staff saying it would offer virtual briefings and instructed employees to remain vigilant while at home and their place of work. asserted
it → report → work
…and 5 more, not listed.
💬Give feedback
🕘History 🎫Support