The Plain Record

Neutral daily news — clear headlines, complete facts.

Legal

Cybercrime group claims breach of FBI personnel data and applicant portal

The hacking group ShinyHunters claims it stole up to 3 terabytes of data, including personal records of agents and job applicants, to protest FBI reports on its tactics.

Published September 23, 2026 at 5:06 PM EDT

The short answer

The hacking group ShinyHunters claims it stole up to 3 terabytes of data, including personal records of agents and job applicants, to protest FBI reports on its tactics.

Cybercrime group claims breach of FBI personnel data and applicant portal

The Facts

Who
ShinyHunters (cybercriminal group) and the FBI
What
A cybercriminal group claimed to have stolen sensitive personal data of FBI agents and job applicants, citing a software vulnerability in a human resources program.
When
Tuesday, September 22, 2026
Where
Washington, D.C. / dark web
Why
The group claims it stole the data to force the FBI to retract public statements that characterized the hackers as engaging in harassment and extortion.

A cybercriminal group known as ShinyHunters claimed on Tuesday, September 22, 2026, that it breached FBI systems and stole sensitive data belonging to personnel and job applicants. The group stated in dark-web posts and media exchanges that it obtained 2 to 3 terabytes of information, including records for nearly all FBI agents. The FBI confirmed on Tuesday that it was investigating claims of unauthorized activity affecting the FBIjobs.gov portal but did not verify the extent of the alleged breach.

The hackers claim they exploited a new vulnerability in Oracle PeopleSoft, a human resources management program used by the FBI's recruiting arm. On Tuesday, the FBI careers website displayed a "System Unavailable" message for its special agent applicant portal. By Wednesday, September 23, 2026, the agency issued a statement saying it was aggressively investigating the claims and working with third-party providers to determine if the breach occurred at a vendor or within the FBI's own enterprise.

According to data samples provided to media outlets, the stolen information allegedly includes names, agent statuses, emails, phone numbers, home addresses, and Social Security numbers for spouses. Two individuals with knowledge of the investigation told Politico that the claims appear credible, identifying it as a significant counterintelligence failure. The hackers stated their motive was not financial but was intended to force the FBI to retract a May 2026 advisory that characterized the group's tactics as involving harassment and "swatting"—the practice of making false police reports to draw a tactical response to a victim's home.

Individuals who have applied for positions through FBIjobs.gov or are currently employed by the bureau would notice the most immediate impact through the suspension of the applicant portal, which remained offline as of Tuesday afternoon. The scale of the theft, cited by the hackers as up to 3 terabytes, suggests a high volume of documents. Because cybersecurity researchers have noted that stolen data is often downloaded and distributed among other threat actors on the dark web shortly after a breach, the exposure of this information could persist indefinitely even if the original hackers do not sell it.

The incident sets a precedent for "retribution" style attacks where cybercriminals target law enforcement agencies specifically to dispute official government characterizations of their activities. It follows other recent security incidents involving the FBI, including the targeting of Director Kash Patel’s personal email in March 2026 and a reported breach of a wiretap system in April 2026. While the FBI continues its investigation alongside third-party providers, the hackers have set a deadline of one week from the initial breach for the agency to modify its earlier public reports about the group. The bureau has previously advised organizations not to pay or engage with the group's demands.

Timeline of what happened

Key dates and decisions, in the order they occurred.

  1. March 1, 2026

    FBI detects suspicious activity on law enforcement sensitive systems

  2. April 1, 2026

    Reported breach of FBI wiretap system by hackers linked to China

  3. May 8, 2026

    FBI issues FLASH bulletin regarding ShinyHunters ecosystem and tactics

  4. May 15, 2026

    IC3 advisory warns against ShinyHunters harassment and swatting tactics

  5. May 25, 2026

    Google documents ShinyHunters exploiting Oracle PeopleSoft vulnerability

  6. September 21, 2026

    ShinyHunters claims to breach FBI systems and steal 2 to 3 terabytes of data

  7. September 22, 2026

    FBI confirms investigation into unauthorized activity at FBIjobs.gov

Summaries are written by The Plain Record to state the facts of a story plainly and without political slant. Drafted with AI assistance and checked against the source record before publication. See how we report, or report a correction.

← Back to the front page

Questions readers ask

What happened: Cybercrime group claims breach of FBI personnel data and applicant portal?

A cybercriminal group claimed to have stolen sensitive personal data of FBI agents and job applicants, citing a software vulnerability in a human resources program.

Who is involved?

ShinyHunters (cybercriminal group) and the FBI

When did this happen?

Tuesday, September 22, 2026

Where did this happen?

Washington, D.C. / dark web

Why does this matter?

The group claims it stole the data to force the FBI to retract public statements that characterized the hackers as engaging in harassment and extortion.