The cybercriminal group ShinyHunters claims it breached the FBI’s recruitment systems and stole sensitive information belonging to agents and job applicants.
What happened
Reuters reported on September 22, 2026, that the cybercriminal group ShinyHunters claimed it had breached the U.S. Federal Bureau of Investigation (FBI) and stolen sensitive information belonging to current and former FBI employees and job applicants.
ShinyHunters released a sample of the allegedly stolen information that it said was related to about 5,000 FBI agents. The data reportedly included names, Social Security numbers, home addresses, work assignments, and family members' names. Reuters was able to partially verify some of the information through credit bureau records and other sources but could not independently establish that the data had originated from the FBI's systems.
The FBI said it was aware of claims involving unauthorized activity affecting FBIjobs.gov and was investigating. The agency's jobs website and Special Agent Applicant Portal were also unavailable at the time of the reported incident.
The alleged breach appears to have involved the FBI's recruitment infrastructure, although the FBI had not confirmed whether its own enterprise systems or a third-party provider supporting FBIjobs.gov had been compromised. This distinction remains important as the investigation continues.
Going deeper
The breach appears to have centered on the FBI's FBIJobs.gov recruitment infrastructure, which uses Oracle PeopleSoft and connects to the bureau's HR systems. ShinyHunters claimed it exploited a vulnerability in PeopleSoft to gain access to sensitive information, although some of the group's broader claims have not been independently verified.
The FBI later identified a third-party security failure as the source of the incident. Reuters reported that a contractor failed to apply a security patch for a critical PeopleSoft vulnerability, CVE-2026-35273, which Oracle had warned could be exploited remotely and without authentication. The contractor was subsequently removed from the project.
The compromised environment contained more than basic recruitment information. Leaked data reportedly included names, Social Security numbers, home addresses, job details, and other sensitive personal information. Reuters also reported that some exposed records contained information about FBI personnel working in sensitive roles, as well as medical and psychiatric information.
The full extent of the breach remains under investigation, and claims by ShinyHunters about the volume of data stolen and access to additional FBI systems have not all been confirmed.
What was said
According to Reuters, the FBI said it was aware of “claims regarding unauthorized activity affecting FBIjobs.gov” and was investigating the incident. The bureau did not initially confirm the extent of the alleged breach or whether sensitive FBI systems had been accessed.
ShinyHunters, meanwhile, claimed the breach exposed information on “almost ALL FBI Agents, and individuals who filed an application with the FBI for a job.” The group released a sample of about 5,000 records, which it said demonstrated the scale of the alleged compromise.
The potential consequences of the exposure were pointed out by former FBI officials. Cynthia Kaiser, a former FBI cyber official, described breaches involving employees' personal information as “incredibly harmful,” warning that “once that information is stolen, it is used forever.” Former FBI counterintelligence operative Eric O'Neill was even more direct about the intelligence implications, describing the allegedly exposed information as “a foreign intelligence service goldmine.” He warned that information identifying FBI personnel and their roles could be particularly valuable to foreign intelligence services.
In the know
A third-party data breach occurs when attackers compromise a vendor, contractor, or external service provider that handles data or systems on behalf of an organization. In the FBI incident, the suspected entry point was a third-party-managed Oracle PeopleSoft platform used in the bureau’s recruitment infrastructure. Reuters reported that a contractor failed to apply a security patch for a critical vulnerability, potentially allowing attackers to gain access to sensitive information.
Third-party breaches can be particularly difficult to detect and contain because an organization may have strong security controls around its own systems while relying on external providers to secure connected platforms and data.
The incident indicates why organizations need to assess both their own cybersecurity controls and also the security practices of vendors, contractors, and technology providers with access to sensitive information.
Why it matters
The potential impact is significant because recruitment and human-resources systems can contain much more than basic application information. They may hold personally identifiable information belonging to employees, former employees, and applicants.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
What is a software vulnerability?
A software vulnerability is a weakness or flaw in an application, operating system, or other technology that attackers can exploit to gain unauthorized access or perform malicious actions.
What is a security patch?
A security patch is an update released by a software provider to fix a known security vulnerability or other security weakness. Applying patches promptly can reduce the window of opportunity for attackers.
What should organizations do if a vendor suffers a breach?
They should work with the vendor to determine what systems and information were affected, contain any ongoing access, assess the potential impact, and follow applicable notification and incident-response requirements. They should also review whether additional controls are needed to prevent a similar incident.
