Skip to main content
developing↑ EscalatingCyber

FBI Personnel Data Breach via Job Portal: ShinyHunters Claims Responsibility

The FBI is investigating a confirmed data breach affecting its job portal, with the cybercrime group ShinyHunters claiming responsibility for exfiltrating sensitive personnel data.

Impact
5.3
Confidence
Medium
Evidence
11 sig · 11 src
Trajectory
↑ Escalating
Geo
US
First seen Sep 23·Updated Sep 23·Synthesized Sep 23
Export brief

Assessment

Medium confidence: 3/11 signals corroborated across 11 independent sources

The FBI is investigating a confirmed data breach affecting its job portal, with the cybercrime group ShinyHunters claiming responsibility for exfiltrating sensitive personnel data. While the full scope and authenticity of the claimed 2TB data theft, including intelligence roles and PII, remain unverified, samples of agent data have been published. This incident represents a significant counterintelligence and force-protection risk, compromising operational security and personnel identities.

Why it matters: This breach poses a severe national security risk due to potential exposure of intelligence roles, operational details, and personal information of FBI agents, enabling identity theft, espionage, and undermining agency credibility.

Established

  • ·Confirmed: FBI systems experienced a data breach exposing employee data, including intelligence roles and operations. The FBI is investigating a breach of its job website, which was temporarily defaced and taken offline.
  • ·Claimed: ShinyHunters claims to have breached the FBI's job portal, exfiltrating over 2TB of sensitive personnel data on 'almost all' FBI agents and applicants, including names, addresses, phone numbers, spouse details, Social Security Numbers, and job titles. ShinyHunters claims to have exploited an Oracle PeopleSoft zero-day and published samples of 5,000 agents' data on the dark web. The group also claims the attack was in response to unspecified actions and is demanding retraction of a threat report.
  • ·Unclear: The full scope and authenticity of the data exfiltrated, the exact method of the breach (beyond ShinyHunters' PeopleSoft zero-day claim), and the specific motivations behind the attack (beyond general cybercrime or retaliation) remain unconfirmed.

Indicators to watch

  • FBI official confirmation on the scope and nature of the compromised data
  • Further data leaks or sales by ShinyHunters on dark web markets
  • Identification of the specific vulnerability exploited in the breach

Evidence

Confirmed · 11 independent sources · 11 signals · 11 independent sources

Central claim ShinyHunters Claims Theft of FBI Employee Data; Breach Unverified82% on claim

Corroborated2 · 2 src · best low 35%
Single-source1 · 1 src · best low 23%
Emerging5 · 5 src · best low 49%
Unclassified1 · 1 src · best low 26%
Context2 · 2 src · best low 55%
Prior · historical1 · 1 src · best high 94%

Topics fbi · data-breach · intelligence · counterintelligence · cyberattack · personnel-security · data breach · shinyhunters · law enforcement · cybersecurity · personnel data · investigation

Discussion

Sign in to add a note, contribute a source, or challenge the assessment.