FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The FBI has privately told its employees that a recent cyberattack on its job application portal exposed personally identifiable information, including Social Security numbers, according to reporting by TechCrunch and other outlets. The bureau has not publicly confirmed the full scope of the breach beyond saying it was aware of a hacking group's claim and that data theft was still being investigated.

Why It Matters
If confirmed, the exposure of FBI personnel records would pose significant security and privacy risks for agents and staff and could trigger legal requirements for Congressional notification if the incident is deemed a "major incident." The incident also highlights vulnerabilities in widely used enterprise systems.
Key Facts
- Internal notice: FBI told employees it declared a "cyber security incident" related to the job application portal.
- Data exposed: Names, addresses, job titles and Social Security numbers; some reports say medical records and psychiatric reports were also included.
- Portal targeted: Hackers accessed data via the FBIJobs.gov portal, which has been the bureau's primary job application site since 2017 and remains down.
- Claimed attacker: A hacking group known as ShinyHunters told TechCrunch they have "data on mostly all of FBI" and substantial application data.
- Exploitation method: Attackers exploited a vulnerability in an Oracle PeopleSoft server that hosts human-resources information.
The Federal Bureau of Investigation has informed its agents and support staff that personally identifiable information was taken in a recent intrusion of its job-application portal, according to reporting by TechCrunch and an internal notification referenced by MS Now reporter Ken Dilanian. The bureau has not issued a full public confirmation of the breach beyond a prior statement that acknowledged a hacking group's claim and said the extent of data theft remained "still undetermined."
Tech reporting says the FBI's internal notice described the incident as a "cyber security incident" and warned that names, home addresses, job titles and Social Security numbers were exposed. Several outlets have also reported that some of the stolen records included medical material such as blood and urine test results and psychiatric reports. The FBIJobs.gov portal, the primary application site since 2017, remained offline at the time of reporting.
The group ShinyHunters told TechCrunch it holds a large trove of bureau-related data and said it obtained access by exploiting a vulnerability in an Oracle PeopleSoft server that stores human-resources information. The hackers said they are not seeking a ransom payment; instead they have demanded correction of an earlier FBI report they allege mischaracterized their activity.
Security experts and former officials warned of serious consequences if the reports are accurate. Justin Sherman, writing for Lawfare, described the theft as a "counterintelligence disaster" that could leave FBI personnel vulnerable to profiling, phishing and foreign-intelligence approaches. Separately, questions remain about whether the FBI has informed Congressional oversight bodies; federal law requires agencies to notify lawmakers when an intrusion meets the threshold of a "major incident," such as when personally identifiable information is taken that could result in demonstrable harm. The White House declined to comment directly and deferred to the FBI, which did not respond to TechCrunch's request for comment in the article's reporting.
Keep Reading

Modulate raises $25M for its voice models and analysis suite

After a deepfake voice fooled her grandfather, this founder sprang into action

Physical AI chip developer SiMa AI hits $1.45B valuation
