Wednesday, September 30, 2026·Focal News

Focal News

Independent local reporting across America

Politics

FBI probes theft of employee records as ShinyHunters claims responsibility

The FBI says it is investigating a breach of its jobs portal after ShinyHunters claimed it stole sensitive personnel information. The potential exposure includes employment, family and medical details, raising concerns about risks to current and former bureau employees.

FBI probes theft of employee records as ShinyHunters claims responsibility
The FBI is investigating the theft of sensitive information tied to its employment portal after the hacking group ShinyHunters claimed responsibility, and the bureau says it is working to identify those behind the breach. In a video posted Sept. 29, Brett Leatherman, assistant director of the FBI’s cyber division, addressed the group directly: “You know how to find us, and we know how to find you.” He urged members to contact the bureau, warning they could face consequences if they did not. The FBI said it is examining how hackers accessed information connected to FBIJobs.gov, including whether a third-party software provider or the bureau’s internal systems were compromised. The bureau has not disclosed how much data was taken or provided technical details about the intrusion. The jobs website was temporarily taken offline after a message claiming the attack appeared on it late last week. Current and former bureau employees familiar with the situation said the stolen files could amount to several terabytes and may include job applications, promotion records, details about sensitive positions, family information and medical data. The FBI has not confirmed that estimate or the full scope of the information involved. The uncertainty has caused particular concern among retired employees, including some who worked undercover. If identifying information is exposed, some could require protective measures such as relocation assistance or new names, according to a former senior FBI official familiar with the matter. The bureau said it sent communications to employees within a day of public reports about the breach and is in regular contact with people who may be affected. Some current and former employees, however, told reporters they first learned of the incident through media coverage and expressed frustration about the pace and detail of the FBI’s communication. ShinyHunters has said it did not intend to publish the stolen files, but that assurance does not eliminate the risk of further access or misuse. The group had set a Sept. 30 deadline for the FBI to revise previous public statements about it. A former senior FBI official said the bureau and former employees are preparing for the possibility that the data cannot be recovered or secured. The incident comes as security researchers have reported that ShinyHunters is targeting a vulnerability in PeopleSoft, an Oracle human-resources software product used by government agencies and other organizations. Google’s Mandiant cybersecurity team said some organizations had relied on protective measures such as firewalls after a patch was released, but that attackers had bypassed those safeguards. The FBI has not said whether a PeopleSoft vulnerability was involved in its breach. Leatherman’s video also referenced the recent arrest in Amsterdam of a person alleged to be a ShinyHunters member. A former senior FBI official said that arrest occurred before the theft of the bureau’s personnel data; whether it played any role in the breach is not known. Cynthia Kaiser, a former deputy director of the FBI’s cyber division who now researches ransomware at cybersecurity company Halcyon, called targeting the bureau “reckless.” She said perpetrators should expect additional resources to be devoted to identifying and arresting them. The FBI has not said when arrests related to this breach might occur.

More from Focal News