FBI confirms cyber security incident after agents’ data stolen

▼ Summary
– The FBI has confirmed a cyber security incident where personal information of agents and applicants was stolen from the job application portal.
– Stolen data includes names, addresses, Social Security numbers, medical records, and psychiatric reports exposed via an Oracle PeopleSoft vulnerability.
– The hacking group ShinyHunters claims responsibility but demands correction of an earlier report rather than financial ransom.
– Experts warn the breach poses significant counterintelligence risks, potentially exposing personnel to profiling and foreign intelligence approaches.
– It remains unclear if the FBI has notified Congress, which is legally required for major incidents likely to harm national security.
The Federal Bureau of Investigation has officially classified a recent breach as a cyber security incident, confirming that the personal data of its agents and support staff was compromised. This internal declaration marks the first time the bureau has explicitly acknowledged that the sensitive information of its workforce was stolen in an attack targeting the agency’s job application portal.
Previously, the FBI had only issued a vague statement last week, noting awareness of claims by a hacking group but maintaining that the extent of the data theft remained “still undetermined.” The shift to declaring a formal incident follows reports from MS NOW reporter Ken Dilanian, who highlighted an internal notification sent to employees. This communication detailed the exposure of names, addresses, job titles, and Social Security numbers.
> New: The FBI told employees in an internal notification that it has declared a “cyber security incident” related to the hack of the https://t.co/l4iJxC0jA2 portal. Personally identifiable information of FBI employees, including social security numbers, addresses and job titles,… , Ken Dilanian (@KDilanianMSNOW) September 26, 2026
Further details emerging from media outlets indicate that the stolen cache extends beyond basic identification. Some of the compromised records include medical information, such as results from blood and urine samples, alongside psychiatric reports. These highly sensitive health records significantly raise the stakes for the affected personnel.
The intrusion is attributed to the hacking collective known as ShinyHunters. In communications with TechCrunch, the group asserted that they possess data on “mostly all of FBI,” along with a “substantial” amount of information regarding applicants who used the FBIJobs.gov portal. The attackers gained access by exploiting a vulnerability within an Oracle PeopleSoft server, which stores extensive human resources data for both current agents and prospective hires.
Despite having access to this trove of information, the hackers stated they are not demanding a financial ransom. Instead, they are seeking the correction of a prior FBI-issued report that they claim misrepresents their activities.
Experts have reacted strongly to the severity of the breach. Justin Sherman, a national security expert writing for Lawfare, described the event as a “counterintelligence disaster” for the United States government. He warned that the theft would “expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more,” potentially compromising ongoing operations and agent safety.
While employee notifications have been issued, it remains unclear whether the FBI has informed Congress about the breach. Federal law mandates reporting to lawmakers if an intrusion qualifies as a “major incident,” defined as one involving personally identifiable information likely to cause demonstrable harm to national security. Bureau lawyers are reportedly assessing whether this threshold has been met. If required, this would be the second notification to Congress this year, following a separate breach earlier in the year involving a surveillance system that exposed targets of FBI investigations, which was suspected to be linked to Chinese actors.
Requests for comment from an FBI spokesperson and a White House representative went unanswered. Similarly, representatives for several lawmakers with oversight jurisdiction provided no immediate response. The FBI’s job application site, which has served as the primary entry point for candidates since 2017, remains offline at the time of reporting.
(Source: TechCrunch)

