ShinyHunters Claims Breach of FBI Jobs Portal

ShinyHunters says it broke into FBIjobs.gov and stole sensitive data on FBI agents and job applicants.
The FBI says it knows about claims of unauthorized activity affecting FBIjobs.gov and is investigating, according to reporting published September 23, 2026 The Guardian. The site was still offline on Wednesday morning, September 23, 2026.
FBIjobs.gov is the main portal where prospective employees learn about the FBI and start an application. So the claimed break-in touched the hiring pipeline, not the systems that hold case files or support operations.
The claim appeared in a message shared online and addressed to FBI Director Kash Patel and the assistant director in charge of the FBI's cyber division. In that message, ShinyHunters claimed it had taken very sensitive data on almost all FBI agents and people who filed a job application with the FBI The Guardian. TechCrunch reported the same claim on September 22, 2026 TechCrunch.
The group gave the FBI one week to correct or remove allegations from a May FBI public service announcement about the group. That May notice described ShinyHunters as a cyber criminal group specializing in large-scale data theft and extortion. The demand, as reported September 23, was to withdraw the May warning that said the gang uses exaggerated or false claims to pressure victims PCMag.
FBIjobs.gov was briefly defaced, meaning its public pages were altered without permission, as part of the claimed attack CyberScoop. On September 23, 2026, the FBI listed a press release titled "FBI Statement on Compromise of fbijobs.gov Portal and Alleged Impact to FBI Employee PII" on its press releases page. PII means personally identifiable information, such as names or contact details. The full scope of the claimed breach was still unclear in September 2026 reporting Nextgov.
Earlier in September 2026, Anthropic said it had caught hackers linked to ShinyHunters trying to use its AI tools CNBC.
The broader context here is a credibility fight built into extortion. The FBI's May warning said the group inflates or invents leverage. A defaced public site can be seen and checked. A claim to hold personnel data cannot, until samples, forensic findings, or misuse appear.
Looking at what this means for officials and close observers, the next signals are narrow. They include whether the FBI confirms data was taken or describes the event only as defacement and unauthorized access, whether applicant data is involved in addition to employee information, and whether the one-week deadline brings further disclosures. Personnel data carries counterintelligence and personal-safety concerns that differ from ordinary breach fallout, which explains why even an unproven claim about agents drew quick attention in Washington and among liaison partners.


