Thursday, September 24, 2026·Focal News

Focal News

Independent local reporting across America

Politics

FBI investigates alleged breach of job portal after hackers claim agents’ data was stolen

The FBI is investigating claims that the cybercrime group ShinyHunters accessed its online recruiting system and obtained personal information tied to thousands of agents and applicants. The alleged exposure could put law-enforcement personnel and their families at risk of harassment, intimidation or targeting by hostile intelligence services.

FBI investigates alleged breach of job portal after hackers claim agents’ data was stolen
The FBI said Tuesday it was investigating suspected unauthorized activity involving FBIjobs.gov after the cybercrime group ShinyHunters claimed it had stolen sensitive information about bureau employees and job applicants. The group said online that it obtained data on “almost all” FBI agents. A sample reportedly provided to security researchers included records for about 5,000 people, with names, home addresses, phone numbers and information about spouses. The FBI has not confirmed how much information was accessed or whether the group’s broader claims are accurate. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” the bureau’s National Press Office said. The FBI’s recruiting website displayed a “system unavailable” notice Tuesday afternoon. Investigators have not publicly identified the systems involved, the period covered by the records or the method used to gain access. Two people familiar with the investigation said authorities viewed the claims as credible and considered the incident a serious counterintelligence concern. Personal information about even a small number of active agents could be used to threaten or harass them and their relatives, while also providing useful leads to foreign intelligence services and violent criminal organizations. One person familiar with the matter said investigators believe the hackers may have exploited Oracle PeopleSoft, a human-resources platform used by many organizations. A representative of ShinyHunters claimed the group used a previously unknown software flaw, known as a zero-day vulnerability, but investigators had not determined whether that was the entry point. ShinyHunters used a previously unknown PeopleSoft vulnerability in a campaign against education-sector organizations in June, according to cybersecurity researchers. Oracle subsequently issued a fix. Investigators are examining whether the FBI system lacked that patch, whether the group reused the same exploit or whether a different weakness was involved. The alleged intrusion follows another major FBI cybersecurity incident this year. In April, hackers linked to China broke into an FBI wiretap system in what officials considered one of the most serious compromises of the bureau’s internal systems in years. ShinyHunters has become increasingly active. The FBI issued a public warning about the group in May after attacks on the Canvas learning platform temporarily disrupted services at thousands of schools and universities. The group has also been linked to the publication of customer data from Madison Square Garden and a breach involving European Commission cloud infrastructure. Cynthia Kaiser, a former deputy assistant director of the FBI’s Cyber Division, described the alleged attack as an unusual form of retaliation rather than a typical ransomware operation. She said the incident underscored how unpredictable the group could be and noted that cybercriminals have repeatedly targeted law-enforcement agencies to gather information about investigations and the people conducting them. The Justice Department and the Cybersecurity and Infrastructure Security Agency did not provide additional comment. The FBI investigation is expected to determine what data, if any, was taken and whether current employees, former employees, applicants and their families need to be notified or protected.

More from Focal News