A hacking group calling itself ShinyHunters claims it breached the FBI and stole data on a huge number of current and former bureau employees, raising fresh alarm about the security of federal law enforcement systems. The group said it obtained records “on almost ALL FBI Agents, and individuals who filed an application with the FBI for a job,” according to the hacking group.
The FBI has not confirmed the scope of the breach but acknowledged something happened. An FBI spokesperson said the bureau is “aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” That statement leaves open how much data, if any, was actually taken, but the claims themselves have already sent ripples through the cybersecurity world given the sensitivity of the target.
What the Stolen Data Allegedly Contains
A sample of the allegedly stolen data included information on roughly 5,000 alleged agents, according to reporting based on a data sample obtained by a technology news outlet. The sample appeared to include names, addresses, phone numbers, dates of birth, Social Security numbers, and in some cases details on employees’ spouses, according to the hacking group and independent verification by a news wire service.
A news wire service’s independent verification effort was able to partially confirm the authenticity of some of the allegedly stolen personnel information by cross-checking it against credit bureau records and previously breached data. In at least nine to ten instances, details in the sample data appeared to match real records, including in the case of FBI Director Kash Patel, according to a news wire service’s data verification effort. That level of matching suggests at least some of the material is genuine, even if the full extent of the breach remains unverified.
ShinyHunters claimed the following FBI services were compromised, according to the hacking group’s statement posted on its dark-web site:
- Criminal Justice (CJ)
- HR
- Medlink
- and more
If accurate, that list points to a breach touching not just recruitment records but internal human resources and health-related systems as well, a far broader footprint than a single jobs portal glitch.
How the Breach Allegedly Happened
ShinyHunters said it exploited a new zero-day vulnerability in Oracle’s PeopleSoft platform to gain remote code execution and deface the FBI’s jobs site, according to a spokesperson for the hacking group. PeopleSoft is widely used across government and corporate human resources systems, so a previously unknown flaw in it would carry implications well beyond the FBI alone.
A message posted on the affected FBI website said both the jobs site and the FBI “Special Agent Applicant Portal” were “currently unavailable.” The outage notice offers the clearest public sign that something disrupted the bureau’s recruitment infrastructure, even as officials stop short of confirming a breach outright.
The timing of the attack, according to the hacking group, was not random. ShinyHunters said it targeted the FBI in response to a May 2026 agency announcement detailing the group’s methods and advising targets not to pay, according to the hacking group. In other words, the hackers frame this as retaliation against the bureau for publicly exposing their tactics and urging victims to refuse ransom demands, turning a law enforcement advisory into what the group is portraying as a provocation worth answering.
Arrests and Unanswered Questions
The episode has already collided with law enforcement action overseas. The Dutch National Police arrested a member of the group that claimed responsibility for the FBI hack, and he was already in custody days before the hack was announced, according to law enforcement reporting. That detail complicates the narrative, raising questions about how a decentralized hacking collective operates and claims credit for attacks even as individual members face prosecution.
Despite the scale of what it claims to have taken, ShinyHunters has signaled it does not intend to release the material publicly. A representative of the hacking group told one outlet it had never intended to publish the stolen FBI data and had decided from the beginning it would not do so. That claim, if true, would mark a departure from the more common extortion playbook of threatening to leak data unless a ransom is paid, though it does nothing to resolve the underlying question of whether the data was stolen at all, or how much of it is real.
For now, the FBI’s formal position remains limited to confirming an investigation into unauthorized activity on FBIjobs.gov. No agency has issued a comprehensive accounting of how many employees, applicants, or family members might be affected, nor has there been a public timeline for resolving the matter. Given the partial verification already reported, including the apparent match involving Director Patel, pressure is likely to mount on the bureau to clarify what happened, how the intrusion occurred, and what steps are being taken to protect the personal information of thousands of current and former employees whose data may now be circulating outside government control.



