Hackers Claim FBI Data on 60,000 Staff, Set 5-Day Deadline

ShinyHunters claims to hold sensitive information on around 60,000 current and former FBI staff and says it will publish the full dataset in five days unless the FBI meets its demands. The group, described as a cyber-extortion outfit that steals data and threatens to release it to force action, says it breached FBI systems on Monday and posted details on its darknet site, a hidden part of the internet not reached by normal browsers. BBC
Samples reviewed so far contain names, addresses, phone numbers, badge numbers, job titles and information about spouses. The records appear to relate to thousands of agents, including senior officials such as deputy directors. Reporting on the samples also points to detailed job assignments for scores of officials, including sensitive information about employees' intelligence roles. BBC Reuters
The BBC reports that stolen FBI "fitness-for-work" medical examinations it reviewed are among the most sensitive files. Those files link blood and urine test results to agents' full names and addresses. The examinations include references to 'blood in the urine' and 'high cholesterol'.
ShinyHunters claims it exploited a vulnerability, a flaw in software, in an Oracle cloud storage system, an online storage service, used by the FBI. The group also said it hacked into the FBI's jobs portal, the public hiring site fbijobs.gov, and used that access to steal sensitive data. BBC NBC News
The FBI acknowledged the breach on Wednesday and said it was "aggressively investigating" how it happened. On September 23, 2026, the FBI listed a press release titled 'FBI Statement on Compromise of fbijobs.gov Portal and Alleged Impact to FBI Employee PII' on its press releases page.
The group says it wants a retraction of an FBI advisory published in May. It is not demanding money, according to the claims. Both the claim and the scope of the alleged theft are unverified.
Experts say the combination of identifiers, employment data and medical records could leave agents vulnerable to scams, blackmail and targeted attacks. They say the stolen data could help criminals impersonate law enforcement officers. BBC
The broader context here is counterintelligence risk. For police and intelligence staff, exposure of name, home address, badge number, assignment history, family links and health information opens several paths for coercion and fraud. Impersonation gets easier. Vetting gets harder. Even partial publication can have operational effects if outsiders can connect assignments to intelligence roles.
Looking at what this means for the next few days, three questions dominate. First is authentication. Investigators must establish what was taken from which system, and whether the Oracle flaw and the jobs portal describe the same break-in. Second is leverage. A five-day deadline tied to retraction of an advisory, rather than payment, centers pressure on credibility. Third is containment. If medical and spousal data are authentic at scale, notification, monitoring and protection for current and former staff will be complex. The deadline sets the tempo.


