FBI Investigates Claimed Breach of Jobs Portal and Employee Data

The FBI said on September 23, 2026, it is investigating a claimed compromise of its fbijobs.gov portal involving FBI employee personally identifiable information. Its press-releases page listed an item titled "FBI Statement on Compromise of fbijobs.gov Portal and Alleged Impact to FBI Employee PII." The portal stayed offline. Al Jazeera
Personally identifiable information, or PII, means details that can identify a person. The claim originated with ShinyHunters. The group said on September 22, 2026, that it had breached the Federal Bureau of Investigation and stolen data. ShinyHunters claimed to have accessed records of agents and applicants through the FBI jobs website. The group is described as a digital extortion collective and claimed to have stolen "very sensitive" data on FBI personnel. Reuters The Washington Post
According to the September 23 reporting, ShinyHunters claims to have obtained detailed data on thousands of current and former FBI employees. The claimed trove is described as between two and three terabytes, a very large store of files. It is said to include detailed information about job assignments of scores of FBI officials involving work against Chinese spies, Russian intelligence, and drug cartels. That account of sensitive intelligence roles was reported as a Reuters exclusive bylined by Raphael Satter and AJ Vicens.
As of September 23, the FBI said the point of breach was still undetermined, whether a third party or the FBI's enterprise. The jobs portal was still offline on the afternoon of September 23. The vector, or method of entry, is unknown.
ShinyHunters said it is holding the stolen FBI data hostage until the FBI rescinds a statement about the group issued in May 2026. In May 2026, the FBI characterized ShinyHunters as "threat actors who harass or threaten victims and use real or exaggerated claims of access to sensitive information to prompt payment." ShinyHunters has said its claimed FBI breach was not financially motivated.
The FBI states it is the lead federal agency for investigating cyberattacks and intrusions. In 2026 the FBI listed a public service announcement titled "ShinyHunters: Cyber Criminal Group Attacks Learning Management System" about potential future impacts related to a cyberattack that affected an online learning system. Separately, after Raoult and his co-conspirators hacked companies, a user going by the name ShinyHunters posted hacked data from many of those companies. FBI
The broader context here is the particular sensitivity of a hiring and personnel system inside an intelligence and law enforcement service. Applicant files and assignment histories can expose identities, career paths, and areas of operational focus, much like an internal roster. When that type of material is alleged to include counterintelligence portfolios, the personnel-security questions extend beyond fraud or identity theft to possible targeting, recruitment pressure, and chilling effects on recruitment itself. Verification will determine whether the 2-3 terabyte figure and the assignment-level detail hold.
Looking at what this means for investigators and Bureau leadership, three uncertainties will shape the next phase. The first is provenance, or where the breach started. A third-party compromise implies supply-chain and contractor review. An enterprise compromise implies internal architecture and access-control review. The second is leverage. A demand to retract a May assessment asks the Bureau to trade analytic judgment for data containment, a precedent with institutional costs either way. The third is disclosure. Current and former personnel will require validated findings on what was taken, from where, and what mitigations apply.


