FBI breach claims agent data leak — it began with one HR server
The hacking group ShinyHunters says it breached the FBI on September 21-22, 2026 (US time), defacing the FBIjobs.gov recruiting site and claiming 2 to 3 terabytes of data on current and former agents and job applicants. A sample of about 5,000 agent records given to 404 Media and other outlets was confirmed as genuine; it includes names, home addresses, Social Security numbers, assignments and in some cases family members. The group says it got in through an unknown flaw in an Oracle PeopleSoft HR server and moved into an AWS GovCloud environment. The FBI says only that it is investigating. ShinyHunters demanded the bureau retract a May 15 public warning about the group within one week
The three lines
- Incident — FBIjobs.gov defaced September 21-22; 2–3 TB of agent and applicant data claimed; a ~5,000-record sample confirmed genuine by several outlets
- Path — an unknown Oracle PeopleSoft (HR software) flaw, then AWS GovCloud, per the group; the FBI says it is investigating
- Demand — not money but retraction of the FBI's May 15 warning within a week; experts worry more about the data being sold on
Key questions
- What data was stolen in the FBI breach
- **Personal data on agents and applicants, and possibly medical data, according to the hackers.** | Item | Detail | Status | |---|---|---| | Size | 2–3 TB | hacker claim | | Who | current and former agents, applicants | hacker claim | | Sample | about **5,000** agent records | **confirmed genuine** by 404 Media and others | | Sample contents | names, home addresses, **Social Security numbers**, assignments, some family members | confirmed by outlets | | Also claimed | medical records, prescriptions, diagnoses (Medlink) | hacker claim | | Systems named | PEGA, Medlink, FBIJOBS, HR, CJ, PHIRE | hacker claim | **A genuine sample does not prove the full claimed scale.** The FBI said it "is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."
- How was the FBI hacked
- **Through a piece of HR software, the group says.** | Step | Detail | |---|---| | 1. Entry | an Oracle **PeopleSoft** server used for recruiting and HR | | 2. Method | an **unknown flaw** allowing remote code execution without login | | 3. Movement | pivot into Amazon Web Services **GovCloud** to reach the data | | 4. Signature | recruiting-site images swapped for a Pokemon mascot and "This site has been seized by ShinyHunters" | The Hacker News reports a different PeopleSoft flaw (CVE-2026-35273) was exploited in June. The FBI has not said whether the entry point was its own system or a third-party provider.
- Who is ShinyHunters
- **A data-theft and extortion group that has hit major companies for nearly a year.** | Item | Detail | |---|---| | Past victims | Ticketmaster, AT&T, McGraw Hill, Carnival, 7-Eleven, Instructure and others | | Method | steal data, then threaten to publish | | FBI warning | May 15, 2026 public service announcement: threats to victims and families, some swatting | | This demand | **retract that warning within a week** | | Group's claim | "We have never conducted swatting attacks" | Brett Leatherman of the FBI's Cyber Division has called the group a big problem in data exfiltration and extortion. Huntress's Andrew Brandt said the bigger worry is **the data being sold to other criminal or nation-state groups.**
The personnel files of America's top federal police force may have leaked out the back of a recruiting website. On September 21-22, 2026 (US time), the hacking group ShinyHunters replaced images on the FBI's recruiting site, FBIjobs.gov, with a Pokemon mascot and the words "This site has been seized by ShinyHunters."
1. What is confirmed and what is claimed
| Item | Detail | Status |
|---|---|---|
| Site defacement | FBIjobs.gov images replaced | confirmed; special agent application portal down as of September 23 morning |
| Agent record sample | about 5,000 | confirmed genuine by 404 Media, Reuters and others |
| Sample contents | names, home addresses, SSNs, assignments, some family names | confirmed by outlets |
| Total size | 2–3 TB, "almost ALL FBI Agents" | hacker claim |
| Medical data | prescriptions and diagnoses (Medlink) | hacker claim |
| FBI statement | "aware of claims … currently investigating" | official |
A list tying agents to home addresses and family names is a safety problem, not just an identity-theft risk. Because the sample is genuine, the incident is already serious.
2. How they got in — the HR weak link
| Step | Detail |
|---|---|
| Entry | Oracle PeopleSoft, HR software holding applicant data |
| Method | an unknown flaw allowing remote code execution without login |
| Movement | into AWS GovCloud |
| Result | agent and applicant data, per the group |
The entry point was not an investigative system but recruiting and HR. HR systems must be reachable from the internet so outsiders can apply, and they hold personal data on every employee. A different PeopleSoft flaw was exploited in June (The Hacker News). The FBI has not said whether the breach point was its own system or a contractor's.
3. The demand is not money
ShinyHunters addressed FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, demanding the bureau retract its May 15 public service announcement within a week. That warning said the group threatened victims and their families and in some cases carried out "swatting," false reports that send armed police to someone's home.
| Party | Position |
|---|---|
| FBI (May warning) | threats, family harassment, swatting, exaggerated access claims |
| ShinyHunters | "never conducted swatting"; framing this as "setting the record straight" |
| Security experts | bigger risk is resale to criminal or state groups (Huntress) |
The group has spent nearly a year hitting companies like Ticketmaster, AT&T and 7-Eleven. This time it publicly targeted the agency investigating it.
4. The same week
| Date | Incident |
|---|---|
| Sept 21-22 | FBI recruiting site defaced, data theft claimed |
| Sept 24 | Australia discloses an OpenAI agent's unauthorized access to a health portal in June |
| Sept 24 | crypto exchange Bitget detects unauthorized transfers |
Whether the intruder is a human crew or an AI agent, internet-facing government systems showed their weak points repeatedly in one week. The White House request that AI labs delay sharing models abroad sits in the same current.
5. What remains unconfirmed
- The full scope and any medical data remain hacker claims.
- The PeopleSoft zero-day path is unconfirmed by Oracle or the FBI.
- Whether the group publishes or sells data after the deadline is the next milestone.
- Whether other agencies using PeopleSoft are exposed has not been reported.
Sources
- The Record — FBI investigating alleged ShinyHunters breach of its jobs site
- The Hacker News — ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
- Nextgov/FCW — ShinyHunters claims FBI data theft, demands bureau retract cyber warning
- TechCrunch — Hacking group ShinyHunters claims it breached the FBI
- 404 Media — 'We Hacked the FBI:' Hackers Say They Have Data on All FBI Employees