WASHINGTON, D.C. — The hacking group ShinyHunters claimed responsibility for breaching the FBI and stealing data on current and former employees on September 22, 2026. The Federal Bureau of Investigation stated it is aware of "a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information."
ShinyHunters said it compromised very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job. The group directed its message to FBI Director Kash Patel and Brett Leatherman, the assistant director in charge of the bureau’s cyber division.
A 5,000-line spreadsheet allegedly stolen by ShinyHunters includes names, addresses, telephone numbers, dates of birth, Social Security numbers, and emergency contact details for thousands of FBI employees. The alleged stolen data includes details of assignments to specific field offices and units engaged in intelligence, security, or counterespionage work against Chinese spies, Russian intelligence, and drug cartels. ShinyHunters said the 5,000-line spreadsheet represents only a small piece of a claimed two- to three-terabyte trove of stolen data.
Reuters verified the details of more than 22 people in the hacked data by cross-referencing with credit records and previous data leaks from District 4 Labs. The FBIJobs.gov website remained offline as of Wednesday morning. The FBI stated the cause of the breach was undetermined and that it was "actively and aggressively investigating the matter." The agency said it is working closely with third-party providers that support FBIJobs.gov to mitigate any and all risk.
Why It Matters
The breach involves personally identifiable information for thousands of current and former FBI employees, including those assigned to units engaged in counterespionage work against foreign intelligence services and drug cartels. The scale of the alleged theft, described as a two- to three-terabyte trove, raises concerns about the exposure of sensitive operational details and the safety of agents and their families. Verification of data for more than 22 individuals confirms the presence of real employee records in the leaked material.
This incident follows a pattern of cyber activity targeting federal law enforcement infrastructure. In March 2026, the FBI disclosed it was investigating suspicious activities on an internal system containing sensitive information related to surveillance operations and investigations. That same month, a pro-Iranian hacking group claimed to have hacked an account of Patel and posted years-old photographs, a work resume, and other personal documents online. The FBI described the information compromised in the March 2026 incident involving Patel as historical in nature and said it involved no government information. The ongoing investigation into the current breach remains focused on determining whether the entry point was a third-party provider or the FBI’s own enterprise systems.
Timeline
The May FBI public service announcement characterized ShinyHunters as threat actors who often "use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims." The May FBI public service announcement said ShinyHunters commonly harass or threaten victims and "may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist." ShinyHunters said it was offended by the FBI's May characterizations. ShinyHunters directed its message to FBI Director Patel and Brett Leatherman, the assistant director in charge of the bureau’s cyber division.
What's New
Additional details revealed that ShinyHunters said it was offended by the FBI's May characterizations. The group directed its message to FBI Director Patel and Brett Leatherman, the assistant director in charge of the bureau’s cyber division. Further context established that the May FBI public service announcement characterized ShinyHunters as threat actors who often use their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims. Background information clarified that the FBI described the information compromised in the March 2026 incident involving Patel as historical in nature and said it involved no government information. As of Wednesday morning, the FBIJobs.gov website remained offline. The FBI said the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — and is actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.
forum Comments (0)
No comments yet. Be the first to comment.