FBI Tells Employees to Assume Hackers Hold Their Personal Data After FBIjobs.gov Breach Claim
Key Takeaways
- •An internal FBI memo instructs bureau employees to assume the hacker group ShinyHunters stole their personal data in a claimed breach of the FBIjobs.gov site.
- •ShinyHunters claims to hold 2 to 3 terabytes of data covering nearly all FBI agents and everyone who has ever applied for an FBI job, including names, phone numbers, and home addresses.
- •The group says it entered through a previously unknown, or zero-day, flaw in Oracle's PeopleSoft HR software, a claim that, if confirmed, would raise concerns for organizations well beyond the FBI.
- •ShinyHunters says the breach was retaliation for a May 15 FBI advisory describing its harassment tactics, and it later called its ultimatum a marketing campaign and said it will not publish the data.
- •FBI Cyber Division Chief Brett Leatherman publicly warned the hackers on Sept. 29, citing a Dutch arrest, while the bureau said it is investigating and has not confirmed the scale or method of the claimed theft.

An internal FBI memo has told bureau employees to assume that the hacker group ShinyHunters stole their personal data, after a claimed breach of the bureau's jobs site, FBIjobs.gov. According to the memo, reported this week by Reuters and Axios, the FBI is working from the premise that data on every staffer may have been taken.
The group claiming credit says it holds data on almost all FBI agents and on everyone who has applied for an FBI job. It puts the haul at 2 to 3 terabytes, including names, phone numbers, home addresses and, in some cases, details on spouses. If the group's account is accurate, the damage would reach past serving agents: by its own description, anyone who has ever applied for an FBI job could be in the files. FBI says it is investigating and has not confirmed the scale of the breach.
to the group, the intrusion began on a Monday night, and by Tuesday, Sept. 22, visitors to the site were met with a banner saying it had been seized by ShinyHunters, as reported by Gizmodo. The group says it got in through a previously unknown flaw in Oracle's PeopleSoft, software many organizations use to run HR. Security researchers call such a bug a zero-day: a flaw the vendor does not know about and has not yet fixed. Because PeopleSoft runs HR systems at many organizations, the claim, if confirmed, would matter for employers well beyond the FBI. The FBI has not confirmed the method or the scale of the claimed theft.
The group says the trigger was an FBI advisory. In that May 15 notice, the bureau warned that ShinyHunters uses harassment, including threats against victims' family members and, in some cases, swatting — a fake emergency call that sends armed police to someone's door. The group denies that characterization. It gave the bureau one week to retract the warning.
ShinyHunters is not new. It surfaced in 2020 selling stolen databases on hacker forums and helped run one of the biggest of them, BreachForums. Last year it claimed about 1.5 billion records from customers of Salesforce, a widely used customer-data platform.
Then the FBI hit back. Cyber Division Chief Brett Leatherman posted a video on X on Sept. 29, as the one-week window the group had set for a retraction was ending. He pointed to a Dutch arrest from Sept. 15 and told the hackers "we know how to find you," urging them to reach out first. The group says the arrested man has no association with it.
FBI pitches ShinyHunters on cooperating: "You know how to find us, and we know how to find you. I suggest you reach out first while the choice is still yours. pic.twitter.com/LP90fjlsnO
— Ken Klippenstein (@kenklippenstein) September 29, 2026
https://x.com/kenklippenstein/status/2104963948848074979?ref_src=twsrc%5Etfw
ShinyHunters later said the ultimatum was a marketing campaign and that it does not plan to publish the data. The memo also tells staff to expect virtual briefings and to watch for suspicious texts or calls from unknown numbers — guidance in line with the bureau's May warning that the group harasses its targets.
Why would a home address matter that much? Because stolen data rarely stays on a screen. If the data is released and employees are doxxed, staff could be threatened or physically harmed, identity theft cases could surge, and relatives of doxxed FBI employees could also be at risk.
Crypto has already shown the pattern. Coinbase said bribed support agents leaked customer data last year, and the company then faced a $20 million extortion demand. As of April, France had recorded 135 crypto-related "wrench attacks" since 2023 and had charged 88 suspects. In one case, attackers who beat a couple outside their Nancy apartment reportedly obtained their details from a January leak at Waltio, a French crypto tax platform that exposed about 50,000 users.
The one-week window the hackers set has passed, and ShinyHunters says it will not publish the data. The memo, as reported, tells staff to work from a stark assumption: their data is already out.