The FBI is investigating claims by the cybercriminal group ShinyHunters that it breached the bureau’s recruitment website and stole highly sensitive information about agents, employees and people who have applied for jobs.
The group said it had obtained data relating to “almost all” FBI agents and applicants, including information held by several employment and personnel systems. The claims have not been fully verified, and the FBI has not confirmed that its wider internal network was compromised.
FBIJobs.gov and the Special Agent Applicant Portal remained unavailable on Thursday, with visitors told that the services were temporarily offline. The FBI said it was working with outside providers supporting the recruitment platform to assess and contain any risk.
FBI investigates ShinyHunters data breach claims
In a statement, the bureau said it was aware of “a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information”.
It added that the “point of breach” had not yet been established, including whether the suspected intrusion involved a third-party supplier or the FBI’s own systems.
ShinyHunters addressed its message to FBI director Kash Patel and Brett Leatherman, the assistant director responsible for the bureau’s cyber division. The group claimed that criminal justice, human resources and medical-related services had been affected.
Reports from US cybersecurity outlets said the hackers had provided samples of thousands of alleged FBI records, including names, contact details and information relating to spouses. Some of the records were reported to have been checked against publicly available information, although that does not establish the full scale or source of the alleged breach.
The group has also claimed to have stolen between two and three terabytes of data and suggested that the intrusion involved an Oracle PeopleSoft human resources system. The FBI has not publicly confirmed either claim.
Hackers demand removal of FBI advisory
ShinyHunters said the alleged attack was carried out in response to an FBI advisory issued in May, which described the group as threat actors that sometimes exaggerate claims of access to sensitive information to pressure victims into paying.
The advisory also accused the group of harassment and threats, including claims involving relatives and alleged compromising material. ShinyHunters said it was offended by those descriptions and demanded that the FBI remove or correct the document within a week.
“This is not a ransom, coercion, or extortion,” the group said in its message. “This PSA is NOT financially motivated.”
The hackers did not specify what action they would take if the FBI failed to meet their demand.
Cybersecurity lawyer Miriam Wugmeister said the alleged exposure could create risks beyond the agents themselves, particularly if personal information about their families were circulated. Such data could potentially be used for intimidation, extortion or false emergency calls directed at agents’ homes.
The FBI has previously investigated suspicious activity involving systems containing sensitive information about surveillance operations and criminal investigations. In a separate incident earlier this year, a pro-Iranian hacking group claimed to have accessed one of Mr Patel’s accounts and published old personal photographs and documents.
