The Plain Record

Neutral daily news — clear headlines, complete facts.

National

FBI Investigates Data Breach of Personnel Records Following Website Defacement

The FBI is investigating a data breach by the group ShinyHunters involving reams of sensitive personnel and applicant information from its jobs website.

Published September 30, 2026 at 10:43 AM EDT

The short answer

The FBI is investigating a data breach by the group ShinyHunters involving reams of sensitive personnel and applicant information from its jobs website. The FBI announced on Tuesday, Sept. 29, 2026, that it is investigating a cyber incident involving the theft of sensitive personnel data from the FBIJobs.gov website.

FBI Investigates Data Breach of Personnel Records Following Website Defacement

The Facts

Who
FBI Assistant Director Brett Leatherman, the hacking collective ShinyHunters, FBI Director Kash Patel, and Oracle (PeopleSoft)
What
The FBI is investigating a cyber incident where the group ShinyHunters claimed to steal sensitive personnel data, including medical and family information, from the FBIJobs.gov portal.
When
Tuesday, September 29, 2026 (statement) and late September 2026 (breach)
Where
Washington, D.C. and the FBIJobs.gov website
Why
The breach exposes sensitive personal information of federal agents and applicants, potentially requiring undercover officers to seek relocation or name changes for safety.

The FBI announced on Tuesday, Sept. 29, 2026, that it is investigating a cyber incident involving the theft of sensitive personnel data from the FBIJobs.gov website. Brett Leatherman, the assistant director of the FBI’s cyber division, released a video addressed to the hacking group ShinyHunters, which claimed responsibility for the breach. The group had previously posted a defacement message on the bureau’s employment site, leading to its temporary removal and replacement with an error page.

Current and former FBI employees said many workers first learned of the compromise through media reports. According to these sources, the stolen data may include several terabytes of text files containing job applications, promotion details, family information, medical data, and sensitive job postings. While ShinyHunters stated the attack was not financially motivated, the FBI said it is working "around the clock" to investigate the incident.

The breach appears linked to a vulnerability in PeopleSoft, a human resources software tool owned by Oracle and used by the FBI. According to research from Google's Mandiant, ShinyHunters has targeted this specific vulnerability, which was originally disclosed in June. Although a patch was released, Mandiant reported that some customers relied on firewalls that the hackers were able to bypass. A former senior FBI official stated that the incident could be comparable in scale to the 2015 Office of Personnel Management breach, which exposed records of tens of millions of government employees.

Federal employees and job applicants will likely notice the FBIJobs.gov site remains affected. While ShinyHunters claimed their actions were intended to force the FBI to amend press releases the group found inaccurate, the presence of this data in a compromised state creates a risk of exploitation by other criminal or nation-state organizations. Former employees expressed frustration with FBI Director Kash Patel over a lack of communication regarding which specific individuals were compromised and what protections will be provided to them.

The FBI has not yet reported a specific date for when the jobs website will be fully restored. The bureau stated it sent communications to its workforce within 24 hours of the initial public reports. ShinyHunters had previously set a deadline of Sept. 30, 2026, for the FBI to address its demands regarding press releases. Further legal actions following the recent detention of an alleged member in Amsterdam by Dutch National Police have not been announced.

Timeline of what happened

Key dates and decisions, in the order they occurred.

  1. June 2026

    Vulnerability in Oracle's PeopleSoft software is disclosed by Google

  2. September 23, 2026

    NBC News reports FBI investigation into claims of stolen agent data

  3. September 26, 2026

    J. Edgar Hoover FBI Building photographed amid reports of site defacement

  4. September 29, 2026

    FBI Cyber Division Assistant Director Brett Leatherman releases video statement

  5. September 30, 2026

    Deadline set by ShinyHunters for FBI to amend press releases

Summaries are written by The Plain Record to state the facts of a story plainly and without political slant. Drafted with AI assistance and checked against the source record before publication. See how we report, or report a correction.

← Back to the front page

Questions readers ask

What happened: FBI Investigates Data Breach of Personnel Records Following Website Defacement?

The FBI is investigating a cyber incident where the group ShinyHunters claimed to steal sensitive personnel data, including medical and family information, from the FBIJobs.gov portal.

Who is involved?

FBI Assistant Director Brett Leatherman, the hacking collective ShinyHunters, FBI Director Kash Patel, and Oracle (PeopleSoft)

When did this happen?

Tuesday, September 29, 2026 (statement) and late September 2026 (breach)

Where did this happen?

Washington, D.C. and the FBIJobs.gov website

Why does this matter?

The breach exposes sensitive personal information of federal agents and applicants, potentially requiring undercover officers to seek relocation or name changes for safety.