A cybercriminal group known as ShinyHunters claimed on Tuesday, September 22, 2026, that it breached FBI systems and stole sensitive data belonging to personnel and job applicants. The group stated in dark-web posts and media exchanges that it obtained 2 to 3 terabytes of information, including records for nearly all FBI agents. The FBI confirmed on Tuesday that it was investigating claims of unauthorized activity affecting the FBIjobs.gov portal but did not verify the extent of the alleged breach.
The hackers claim they exploited a new vulnerability in Oracle PeopleSoft, a human resources management program used by the FBI's recruiting arm. On Tuesday, the FBI careers website displayed a "System Unavailable" message for its special agent applicant portal. By Wednesday, September 23, 2026, the agency issued a statement saying it was aggressively investigating the claims and working with third-party providers to determine if the breach occurred at a vendor or within the FBI's own enterprise.
According to data samples provided to media outlets, the stolen information allegedly includes names, agent statuses, emails, phone numbers, home addresses, and Social Security numbers for spouses. Two individuals with knowledge of the investigation told Politico that the claims appear credible, identifying it as a significant counterintelligence failure. The hackers stated their motive was not financial but was intended to force the FBI to retract a May 2026 advisory that characterized the group's tactics as involving harassment and "swatting"—the practice of making false police reports to draw a tactical response to a victim's home.
Individuals who have applied for positions through FBIjobs.gov or are currently employed by the bureau would notice the most immediate impact through the suspension of the applicant portal, which remained offline as of Tuesday afternoon. The scale of the theft, cited by the hackers as up to 3 terabytes, suggests a high volume of documents. Because cybersecurity researchers have noted that stolen data is often downloaded and distributed among other threat actors on the dark web shortly after a breach, the exposure of this information could persist indefinitely even if the original hackers do not sell it.
The incident sets a precedent for "retribution" style attacks where cybercriminals target law enforcement agencies specifically to dispute official government characterizations of their activities. It follows other recent security incidents involving the FBI, including the targeting of Director Kash Patel’s personal email in March 2026 and a reported breach of a wiretap system in April 2026. While the FBI continues its investigation alongside third-party providers, the hackers have set a deadline of one week from the initial breach for the agency to modify its earlier public reports about the group. The bureau has previously advised organizations not to pay or engage with the group's demands.