FBI Investigates Claims of Mass Data Breach Targeting Employee Records
-
Post By
Emmie
- September 24, 2026
The US Federal Bureau of Investigation is investigating claims by cybercrime collective ShinyHunters that it breached agency systems and accessed sensitive personal data belonging to current and former personnel.
The hacking group asserts it obtained between two and three terabytes of records covering almost all bureau staff, which is estimated at around 38,000 individuals, as well as job applicants. According to the hackers, the compromised files contain agent names, roles, badge numbers, Social Security numbers, home addresses, phone numbers, family details, and medical records.
Sample data reviewed by news organizations included granular details regarding officials' specific job assignments, including sensitive work targeting drug cartels, Russian intelligence, and Chinese espionage operations. Attempts to access `fbijobs.gov` showed the portal offline following reports of the disruption.
Unlike typical digital extortion attempts involving ransom demands, ShinyHunters claims it is holding the records hostage to force the FBI to retract a public service announcement issued in May 2026.
The agency characterized ShinyHunters as "threat actors" who use "their real or exaggerated claims of access to sensitive or personal information to prompt payment from victims". The group expressed offense at the characterization, giving the bureau one week to remove or correct the statement before publishing the stolen databases in full.
In a statement published on X, the FBI confirmed it was looking into claims regarding fbijobs.gov and evaluating whether the breach occurred on internal servers or through external vendors:
"While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support fbijobs.gov to mitigate any and all risk."
Cybersecurity experts warned that exposing personnel details creates long-term hazards for law enforcement operations and safety.
Cynthia Kaiser, a former FBI official now serving as senior vice president at cybersecurity firm Halcyon, emphasized the lasting threat posed by leaked agent rosters:
"Once that information is stolen, it is used forever."
She noted that legacy breaches from years prior continue to be leveraged by bad actors seeking to harass or pressure active investigators.
ShinyHunters has previously been linked to high-profile network intrusions, including a breach at video game developer Rockstar Games, an attack on educational platform Canvas, and recent unauthorized activity targeting AI developer Anthropic. The group claims it utilized vulnerabilities within cloud storage systems supporting the bureau's recruitment and administrative portals to carry out the attack.
The FBI has not confirmed whether any internal databases beyond the job portal were affected, and federal cyber authorities continue to assess the scope of the incident.