Story summary
ShinyHunters, a notorious hacking group, claimed on September 22 that they breached the FBIjobs.gov website and stole personal data from thousands of current and former FBI employees. The hackers obtained sensitive information such as names, home addresses, phone numbers, email addresses, and dates of birth for many agents and job applicants. ShinyHunters defaced the FBI's jobs portal with a mocking message that included President Trump’s signature phrase "Thank you for your attention to this matter," implying retaliation against his administration.
The FBI acknowledged unauthorized activity affecting their job application site but did not confirm the theft of data. Reuters partially verified some stolen information by cross-referencing it with credit bureau records and previous breaches, finding matches in at least nine cases. The hackers threatened further action if the FBI does not address what they see as false allegations against them.
The breach potentially impacted a significant number of individuals who applied for or held positions within the FBI since 2017 when the site became the primary application platform for agent and support roles. The full extent of data compromised remains unclear, but ShinyHunters shared what they claim is a small sample dataset involving approximately 5,000 individuals.
Written for “FBI Data Breach” on 2026-10-05,
grounded in this article and the 22 other(s) covering the same event.
FBI hunting the hackers who stole its employees' sensitive data
In a video posted on social media, the assistant director of the FBI's cyber division, Brett Leatherman, vowed yesterday to hunt down the members of a cybercriminal group going by the name of ShinyHunters, the same group that last week claimed to steal reams of sensitive data from the FBI itself.
asserted
that → hunt → FBI
"You know how to find us, and we know how to find you," Leatherman said in the video, encouraging the prolific group of loosely connected data extortionists to come forward and share information or face the consequences.
asserted
Leatherman → know → consequences
"I suggest you reach out first while the choice is still yours."
asserted
choice → suggest → ?
The FBI says it is "aggressively" investigating the breach and how hackers got ahold of sensitive FBI employment information, including whether the hackers got into third party software or the FBI's own internal systems.
asserted
hackers → say → software
In a statement emailed to NPR, a FBI spokesperson said the bureau is working "around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted."
uncertain
who → email → anyone
It's still unclear how much information was stolen, though media organizations and threat intelligence researchers have already verified the authenticity of some of the stolen materials.
uncertain
organizations → steal → materials
Meanwhile, a defacement message was posted on the FBI's jobs website late last week where ShinyHunters took credit for the attack, and the site was temporarily taken down.
asserted
site → post → attack
Current and former FBI employees familiar with the matter, who spoke to NPR on condition of anonymity because they feared reprisal for speaking about an ongoing investigation, said many employees first found out about the breach from media reports.
asserted
employees → speak → reports
They suggested there could be as many as several terabytes of text files in the data tranche, including FBI job applications, details on promotions, information on sensitive job postings, family details, medical data, and more.
uncertain
They → suggest → postings
Those same employees, particularly those who have retired, say there's growing frustration with FBI leadership including FBI Director Kash Patel about the lack of communication about the breach, exactly who is impacted, and how the FBI plans to protect its current and former employees.
asserted
FBI → retire → employees
Some retired employees who worked undercover might need protection services like relocation assistance or even name changes if their data is exposed publicly.
uncertain
data → retire → assistance
The FBI told NPR it sent multiple "bureau wide communications within 24 hours of public reporting" of the breach" and that "the FBI treats the security of its own information and the safety of its workforce as top priorities."
asserted
FBI → tell → priorities
One former senior FBI official told NPR the breach could be on par with the 2015 compromise of tens of millions of sensitive government employee records from the Office of Personnel Management.
uncertain
breach → tell → Management
The U.S. government attributed that breach to the Chinese government and described it as a widespread espionage operation designed to identify potential targets for intelligence gathering.
However, unlike the OPM breach, there is more concern in this instance that the stolen materials will fall into the wrong hands or be otherwise weaponized, either by ShinyHunters or any number of criminal, terrorist, or nation state organizations seeking to pilfer the stolen files.
asserted
materials → attribute → files
ShinyHunters has come out and said it never intended to leak the files, despite giving a deadline of Sept. 30 for the FBI to amend previously published press releases about the group that it argued were inaccurate, but that doesn't necessarily prevent further theft or exploitation of the data.
asserted
that → come → data
The bureau and its former employees are "bracing for impact" and assume that the stolen materials may be irretrievably compromised, according to the former senior FBI official.
uncertain
materials → brace → official
But experts argue that the ShinyHunters members, which many threat intelligence researchers have previously identified as a loose collective of young hackers around the world, should also brace themselves for the FBI's response.
asserted
researchers → argue → response
Cynthia Kaiser, the former FBI deputy director of the cyber division who currently leads ransomware research at cybersecurity company Halcyon, described the hackers as "reckless" for targeting the FBI, particularly knowing the FBI has a clear policy of not paying a ransom or negotiating with criminal actors.
asserted
FBI → lead → actors
"When any threat actor targets the FBI directly, they should expect that the FBI is going to marshall additional resources to bring them quickly to justice," she wrote in a social media post.
asserted
she → target → post
While the FBI has promised to seek the information to make arrests against ShinyHunters hackers in the wake of this breach, it's unclear how imminent those actions might be.
uncertain
actions → promise → breach
The FBI's video posted on social media also featured a recently announced arrest of one alleged member of ShinyHunters in Amsterdam by the Dutch National Police, an operation the FBI thanked their Dutch partners for leading.
asserted
FBI → post → partners
However, that arrest preceded the ShinyHunters theft of FBI personnel data, according to the former senior FBI official familiar with the matter.
uncertain
arrest → precede → matter
It's unclear if that arrest served as motivation for the breach of FBI data, and whether there was concern about potential retaliation following that arrest.
uncertain
arrest → serve → arrest
While the FBI has not shared any technical details about how the hackers got into their systems, Google's Mandiant published new research revealing that ShinyHunters are currently targeting a vulnerability in a human resources software tool called PeopleSoft, which is owned by tech giant Oracle.
asserted
which → share → Oracle
PeopleSoft is a tool used by the FBI, among other major clients in IT services, corporations, government, academia, and beyond.
asserted
PeopleSoft → use → services
Google originally disclosed information about the vulnerability and its exploitation in June and revealed that while the company released a patch, some customers instead implemented protections like a firewall to attempt to prevent bad actors from exploiting it.
asserted
customers → disclose → it
Ultimately, ShinyHunters have managed to easily bypass those controls.
asserted
ShinyHunters → manage → controls