FBI hunting the hackers who stole its employees' sensitive data

Read the original at NPR ↗
NPR · collected 2026-09-30 · by Jenna McLaughlin

Quick Summary

The FBI is investigating a data breach by hackers known as ShinyHunters who stole sensitive information from the FBI’s employment website, FBIJobs.gov. Assistant Director Brett Leatherman urged the cybercriminals to cooperate voluntarily before facing legal consequences. The extent of the stolen data remains unclear but may include job applications, promotion details, medical records, and other personal information amounting to several terabytes of text files. Current and former FBI employees are expressing frustration over a perceived lack of communication from leadership regarding the breach's impact and protective measures for affected individuals.
Written locally by qwen2.5:14b on 2026-09-30, using this article's own text rather than the other coverage of the same event (that is the story summary below).

AI analysis runs on qwen2.5:14b, locally

Story summary

ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.

The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.

The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.

Written for “FBI Data Breach” on 2026-10-05, grounded in this article and the 22 other(s) covering the same event.

Signals How these are calculated →

Claims extracted
27
claim-shaped sentences
Uncertain
33%
9 of 27 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
59.6
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
23
Crime & Law
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-30 · how these are computed

Story

📰 FBI Data Breach
Crime & Law · 23 article(s) covering the same event. See how they differ ↓

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 33% of its claims. Each row says how that neighbour differs.
Fox News · 0.90 cosine similarity
⚖️ leaning not scored 🔴 26% hedged 36 of 141 📰 publisher trust 69
“Both articles discuss the same cyberattack by ShinyHunters on the FBI, involving the theft of sensitive data from FBIJobs.gov, and mention the FBI's response to the incident.”
BBC News
⚖️ leaning not scored 🔴 35% hedged 9 of 26 📰 publisher trust 78
“Article A reports on the initial theft of sensitive medical data, while Article B describes the FBI's response to find and address those responsible for the hack.”
Fox News
⚖️ leaning not scored 🔴 8% hedged 2 of 24 📰 publisher trust 69
“The articles discuss different topics related to the FBI: one about cybercriminals stealing data and the other about defending the FBI's fugitive apprehension statistics.”
Times of India
⚖️ leaning not scored 🔴 12% hedged 2 of 17 📰 publisher trust 59
“The articles discuss different topics related to the FBI: one focuses on the theft of employee data by hackers (ShinyHunters), while the other is about an internal report examining past failures and accountability.”
BBC News
⚖️ leaning not scored 🔴 24% hedged 10 of 41 📰 publisher trust 78
“Article A describes the initial reaction and aftermath of a data breach, while Article B reports on an FBI response to find the hackers who conducted the breach.”
ABC News (US)
⚖️ leaning not scored 🔴 67% hedged 8 of 12 📰 publisher trust 59
“While both articles discuss a hack involving FBI personnel data, Article A describes the initial hacking incident and stolen records, while Article B reports on the FBI's response to find and address those responsible for the hack.”
404 Media
⚖️ leaning not scored 🔴 11% hedged 5 of 45 📰 publisher trust 95
“While both articles discuss the same hacking incident involving ShinyHunters stealing FBI employee data, ARTICLE A reports on the hackers' statement about not publishing the stolen data, while ARTICLE B focuses on the FBI's response and pursuit of the hackers.”
The Straits Times
⚖️ leaning not scored 🔴 44% hedged 4 of 9 📰 publisher trust 59
“Article A reports on the FBI's vow to hunt down ShinyHunters after they stole sensitive data, while Article B describes a separate incident where a member of ShinyHunters was detained in Jordan and is cooperating with the FBI.”
The Straits Times
⚖️ leaning not scored 🔴 26% hedged 5 of 19 📰 publisher trust 59
“Article A discusses the FBI's response to the data theft and their pursuit of ShinyHunters, while Article B reports on a specific arrest in Jordan and cooperation with the FBI.”
Times of India
⚖️ leaning not scored 🔴 25% hedged 2 of 8 📰 publisher trust 59
“Article A reports on the FBI's response and warning to ShinyHunters, while Article B covers a separate incident of an alleged member being detained in Jordan.”

Publisher

NPR · 532 article(s) · 2 correction(s) detected
Running correction rate · 2 correction(s)
2026-10-01
COMIC: How the census gives your state power (and what Trump wants to change)
2026-08-31
Hit shows from Edinburgh's Fringe festival are coming to America. Here are our top picks

Who wrote this

Jenna McLaughlin
2 article(s) here · 1 carrying a prediction
🔮 In a statement emailed to NPR, a FBI spokesperson said the bureau is working "around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted."
🔮 Adrian Fontes, who, as the secretary of state of Arizona is one of the local officials who would be impacted by losing funding for election security, gave a blunt assessment to NPR.
Also by Jenna McLaughlin
Nothing else under this byline is closely related to this article, so these are simply their most recent.

Topics

FBI FBIJobs.gov NPR ShinyHunters the Office of Personnel Management

Subjects

FBI ORG · 20× ShinyHunters ORG · 5× NPR ORG · 4× Brett Leatherman PERSON · 1× Chinese NORP · 1× FBIJobs.gov ORG · 1× Kash Patel PERSON · 1× Leatherman PERSON · 1× U.S. GPE · 1× the Office of Personnel Management ORG · 1×

Narrative

The U.S. government attributed that breach to the Chinese government and described it as a widespread espionage operation designed to identify potential targets for intelligence gathering. However, unlike the OPM breach, there is more concern in this instance that the stolen materials will fall into the wrong hands or be otherwise weaponized, either by ShinyHunters or any number of criminal, terrorist, or nation state organizations seeking to pilfer the stolen files.
framing: mixed · carried by 1 article(s) · first seen 2026-09-30
🔮 In a statement emailed to NPR, a FBI spokesperson said the bureau is working "around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted."

Claims (27 extracted, 9 hedged)

FBI hunting the hackers who stole its employees' sensitive data In a video posted on social media, the assistant director of the FBI's cyber division, Brett Leatherman, vowed yesterday to hunt down the members of a cybercriminal group going by the name of ShinyHunters, the same group that last week claimed to steal reams of sensitive data from the FBI itself. asserted
that → hunt → FBI
"You know how to find us, and we know how to find you," Leatherman said in the video, encouraging the prolific group of loosely connected data extortionists to come forward and share information or face the consequences. asserted
Leatherman → know → consequences
"I suggest you reach out first while the choice is still yours." asserted
choice → suggest → ?
The FBI says it is "aggressively" investigating the breach and how hackers got ahold of sensitive FBI employment information, including whether the hackers got into third party software or the FBI's own internal systems. asserted
hackers → say → software
In a statement emailed to NPR, a FBI spokesperson said the bureau is working "around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted." uncertain
who → email → anyone
It's still unclear how much information was stolen, though media organizations and threat intelligence researchers have already verified the authenticity of some of the stolen materials. uncertain
organizations → steal → materials
Meanwhile, a defacement message was posted on the FBI's jobs website late last week where ShinyHunters took credit for the attack, and the site was temporarily taken down. asserted
site → post → attack
Current and former FBI employees familiar with the matter, who spoke to NPR on condition of anonymity because they feared reprisal for speaking about an ongoing investigation, said many employees first found out about the breach from media reports. asserted
employees → speak → reports
They suggested there could be as many as several terabytes of text files in the data tranche, including FBI job applications, details on promotions, information on sensitive job postings, family details, medical data, and more. uncertain
They → suggest → postings
Those same employees, particularly those who have retired, say there's growing frustration with FBI leadership including FBI Director Kash Patel about the lack of communication about the breach, exactly who is impacted, and how the FBI plans to protect its current and former employees. asserted
FBI → retire → employees
Some retired employees who worked undercover might need protection services like relocation assistance or even name changes if their data is exposed publicly. uncertain
data → retire → assistance
The FBI told NPR it sent multiple "bureau wide communications within 24 hours of public reporting" of the breach" and that "the FBI treats the security of its own information and the safety of its workforce as top priorities." asserted
FBI → tell → priorities
One former senior FBI official told NPR the breach could be on par with the 2015 compromise of tens of millions of sensitive government employee records from the Office of Personnel Management. uncertain
breach → tell → Management
The U.S. government attributed that breach to the Chinese government and described it as a widespread espionage operation designed to identify potential targets for intelligence gathering. However, unlike the OPM breach, there is more concern in this instance that the stolen materials will fall into the wrong hands or be otherwise weaponized, either by ShinyHunters or any number of criminal, terrorist, or nation state organizations seeking to pilfer the stolen files. asserted
materials → attribute → files
ShinyHunters has come out and said it never intended to leak the files, despite giving a deadline of Sept. 30 for the FBI to amend previously published press releases about the group that it argued were inaccurate, but that doesn't necessarily prevent further theft or exploitation of the data. asserted
that → come → data
The bureau and its former employees are "bracing for impact" and assume that the stolen materials may be irretrievably compromised, according to the former senior FBI official. uncertain
materials → brace → official
But experts argue that the ShinyHunters members, which many threat intelligence researchers have previously identified as a loose collective of young hackers around the world, should also brace themselves for the FBI's response. asserted
researchers → argue → response
Cynthia Kaiser, the former FBI deputy director of the cyber division who currently leads ransomware research at cybersecurity company Halcyon, described the hackers as "reckless" for targeting the FBI, particularly knowing the FBI has a clear policy of not paying a ransom or negotiating with criminal actors. asserted
FBI → lead → actors
"When any threat actor targets the FBI directly, they should expect that the FBI is going to marshall additional resources to bring them quickly to justice," she wrote in a social media post. asserted
she → target → post
While the FBI has promised to seek the information to make arrests against ShinyHunters hackers in the wake of this breach, it's unclear how imminent those actions might be. uncertain
actions → promise → breach
The FBI's video posted on social media also featured a recently announced arrest of one alleged member of ShinyHunters in Amsterdam by the Dutch National Police, an operation the FBI thanked their Dutch partners for leading. asserted
FBI → post → partners
However, that arrest preceded the ShinyHunters theft of FBI personnel data, according to the former senior FBI official familiar with the matter. uncertain
arrest → precede → matter
It's unclear if that arrest served as motivation for the breach of FBI data, and whether there was concern about potential retaliation following that arrest. uncertain
arrest → serve → arrest
While the FBI has not shared any technical details about how the hackers got into their systems, Google's Mandiant published new research revealing that ShinyHunters are currently targeting a vulnerability in a human resources software tool called PeopleSoft, which is owned by tech giant Oracle. asserted
which → share → Oracle
PeopleSoft is a tool used by the FBI, among other major clients in IT services, corporations, government, academia, and beyond. asserted
PeopleSoft → use → services
Google originally disclosed information about the vulnerability and its exploitation in June and revealed that while the company released a patch, some customers instead implemented protections like a firewall to attempt to prevent bad actors from exploiting it. asserted
customers → disclose → it
Ultimately, ShinyHunters have managed to easily bypass those controls. asserted
ShinyHunters → manage → controls
💬Give feedback
🕘History 🎫Support