FBI Tells Its Employees to Assume Hackers Have Their Personal Data
An internal FBI memo instructed employees to assume their personal information was stolen after the jobs site FBIjobs.gov was reportedly breached by the hacker group ShinyHunters. The group says it exfiltrated 2 to 3 terabytes of records covering agents, job applicants and some spouses; the FBI says it is investigating and has not verified the claimed scale or method.

Why It Matters
If the breach is real at the scale ShinyHunters claims, it could expose sensitive personal details on current and prospective FBI staff, raising safety and identity-theft risks for employees and their families. The incident also highlights risks tied to widely used HR software and recurring pressure tactics by organized cybercriminal groups.
Key Facts
- Internal memo: FBI told employees to assume their personal data was stolen
- Claimed haul: ShinyHunters says it holds 2 to 3 terabytes of data
- Affected groups: Almost all FBI agents, FBI job applicants, and some spouses (per ShinyHunters)
- Site hit: FBIjobs.gov banner showed 'seized by ShinyHunters' after intrusion began Monday night; visible by Sept. 22
- Alleged vulnerability: Group claims initial access via a zero-day in Oracle PeopleSoft; FBI has not confirmed
An internal FBI memo advised staff to operate on the assumption that their personal data may have been stolen following an apparent breach of the bureaus recruitment site, FBIjobs.gov. The memo reportedly directs employees to expect virtual briefings and to be alert for suspicious calls or texts, while the bureau continues an active investigation and has not confirmed the full scope of the incident.
The hacker collective ShinyHunters has claimed responsibility, saying it obtained two to three terabytes of information that include names, phone numbers, home addresses and, in some instances, spouse details. The group says its haul covers nearly all FBI agents and anyone who applied for a job with the agency. If accurate, the release could extend the impact beyond employees to applicants and family members.
ShinyHunters stated the intrusion began on a Monday night and by Sept. 22 visitors to the jobs site saw a banner asserting the site had been seized. The group attributes the break-in to an unknown vulnerability in Oracles PeopleSoft, a human-resources platform used by many organizations; security professionals classify such undisclosed bugs as zero-day flaws. The FBI has not confirmed the exploitation method.
Tensions between the bureau and ShinyHunters intensified after an FBI Cyber Division chief, Brett Leatherman, posted a video on Sept. 29 referencing a Sept. 15 arrest in the Netherlands and warning the group that the bureau can locate them. ShinyHunters later characterized the warning as a marketing ploy and said it did not intend to publish the stolen data. The group also pushed the FBI to retract a May 15 advisory that accused it of harassment tactics including threats and swatting; ShinyHunters denied those accusations. The FBI continues to investigate and has asked employees to take protective steps while the situation develops.
Keep Reading

Gemini 4 Is Here, and Google’s Flagship Tops All Other AI Models on Cybersecurity

OpenAI, Google and Meta pledge independent AI safety audits under voluntary White House deal
Google shows it’s not out of the AI race just yet
