Cybercriminals Steal Sensitive Data from FBI Job Applications
If you have ever filled out a job application, handed over your Social Security number for a background check, or trusted an organization with details about your family, pay attention to what happened at the FBI. The cybercriminal group ShinyHunters claims it compromised FBIJobs.gov and stole highly sensitive information connected to current and former FBI personnel and people who applied for jobs at the Bureau. This haul reaches far beyond basic contact information.
On Sept. 23, the FBI acknowledged the group's claims and said it was "actively and aggressively investigating" the incident. The Bureau stated investigators had not yet determined whether the point of breach involved an FBI system or a third-party provider supporting FBIJobs.gov. That uncertainty is important. At the same time, samples provided to journalists contain enough real-world information to make the situation difficult to dismiss. For anyone whose details may be included, the potential fallout goes well beyond having an email address leaked.
Since that statement, the FBI has struck back by announcing the arrest of an alleged ShinyHunters leader in the Netherlands following a joint operation with Dutch authorities. Dutch police said a 24-year-old Amsterdam man was arrested Sept. 15.
The FBI's Special Agent Applicant Portal also became unavailable as the incident unfolded. A notice posted on Sept. 22 said FBIJobs.gov and the Special Agent Applicant Portal were unavailable. The applicant portal supports people who have progressed through portions of the special-agent hiring process, making the type of information potentially involved especially sensitive.
In its Sept. 23 statement, the FBI addressed both the alleged compromise and the uncertainty surrounding where the attackers may have gained access. "The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal," the Bureau said. It added that the point of breach remained undetermined and said it was "actively and aggressively investigating this matter." The FBI also said investigators were working closely with third-party providers that support FBIJobs.gov to reduce potential risk. The FBI confirmed the investigation and the unresolved question about where the breach occurred. It did not verify ShinyHunters' full account of what the group says it stole.
CyberGuy reached out to the FBI for an update on the incident, including whether employee or applicant data was accessed and whether affected individuals are being notified or offered identity protection. We did not hear back before our deadline.

ShinyHunters provided journalists with a spreadsheet containing about 5,000 alleged FBI personnel records. Reuters reported that the spreadsheet included names, home addresses, phone numbers, dates of birth, Social Security numbers and emergency contact information. It also included information about field-office assignments and, in some cases, sensitive intelligence or counterespionage work. Reuters said it could not authenticate the entire spreadsheet.
Reporters checked details for over 22 individuals by cross-referencing credit records and older leaked files. Reuters matched career paths or job titles for eight people against court documents, news stories, public profiles, and online posts. This verification does not prove where every record originated since real data can sit in multiple databases or past breaches. Yet these matches lend credibility to at least parts of the sample. 404 Media separately noted that this 5,000-person list included names, home addresses, phone numbers, and details involving spouses of FBI employees.
Sensitive FBI assignments reportedly surfaced within the leaked data. The personal information alone creates obvious privacy concerns while reported job details raise another level of risk. Reuters found records identifying people connected to China-related investigations, Russian intelligence work, human intelligence operations, and electronic surveillance. Other entries referenced covert access, clandestine technical operations, and telecommunications interception. Reuters stated it could not verify that every assignment was authentic or up to date.
404 Media also reported on Sept. 23 that the data appeared to expose members of the FBI's Remote Operations Unit. The outlet describes the ROU as a secretive team involved in developing and using hacking tools to gain access to target devices. Think about what that combination of information could provide to someone with bad intentions. A name may lead directly to a home address. An emergency contact could identify a spouse or child. Job information might reveal the kind of investigations someone works on. For an FBI employee working in a sensitive position, that creates risks far beyond ordinary financial fraud.
IS YOUR SOCIAL SECURITY NUMBER ON THE DARK WEB?

ShinyHunters claims it breached the FBI and stole between 2 and 3 terabytes of information connected to FBI personnel and job applicants. The group has also claimed that Justice Department worker data was obtained. The hackers claim they exploited a previously unknown vulnerability involving Oracle PeopleSoft, software used for human resources and other enterprise functions. FBI documents reportedly show its recruiting operation uses PeopleSoft and AWS GovCloud. However, that does not prove the hackers' claimed method of attack.
The alleged PeopleSoft vulnerability, the claimed 2-to-3-terabyte haul, and a broader compromise of FBI systems had not been independently verified. Reuters also reported that ShinyHunters claimed to possess files involving employee and applicant vetting, contracted background investigations, and sensitive medical information. Reuters said it could not verify what additional information the hackers actually possessed. That caveat is critical because ShinyHunters has an obvious interest in making its access sound as extensive as possible. For now, there are signs that portions of the information supplied by the hackers correspond to real people. Major questions about the source, scope, and attack path remain unresolved in the FBI's public statement.
ShinyHunters says retaliation rather than a demand for money motivated the attack. The group points to warnings the FBI issued about ShinyHunters-related cyber activity earlier in 2026. On May 15, the FBI's Internet Crime Complaint Center published an advisory describing ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. The advisory warned that actors using the name may use real or exaggerated claims about stolen information to pressure victims. It also described threatening communications, harassment of family members, and swatting among tactics associated with ShinyHunters actors. ShinyHunters disputes portions of the FBI's description of its activities.
Reuters reports that the group claimed it targeted the FBI following a warning issued in May. They say they are currently holding what is alleged to be stolen data while demanding the Bureau rescind its statement.
Why this matters even if you never worked for the agency You might read a headline about FBI staff and think this has nothing to do with you. Yet anyone who has handed personal information to an employer, bank, health provider, insurance company, or government agency should feel that this could happen to them. Organizations often collect far more than your name and email address. They may hold your home address, Social Security number, birth date, employment history, and emergency contacts. Job applications can contain years of background information.
You may have done everything right and still have that information exposed because the organization holding it, or one of its technology providers, was attacked. That third-party piece deserves attention here. In its Sept. 23 statement, the FBI specifically said investigators had not determined whether the breach point involved its own enterprise or a third party.

The same setup exists throughout everyday life. Your employer might use an outside payroll provider. Your doctor's office may rely on billing software from another company. Retailers routinely send information through outside payment systems. Once you hand over your personal data, you often have little visibility into how many systems eventually store or process it.
Stolen personal details make scams much harder to spot Suppose someone emails you and knows your full name, employer and home address. Then the person mentions your spouse or a job application you actually submitted. That message feels very different from a generic scam email. This is why personal data can be so useful to attackers. They can combine stolen records with information already available from data brokers, social media, or previous breaches. The result can be a phishing message tailored closely enough to make you hesitate before questioning it.
Cybercriminals could pose as an FBI recruiter or someone from an employer's human resources department. They could even claim they are contacting you to help protect information exposed in the breach. The FBI's May advisory warned that stolen personal information can help attackers create targeted campaigns and pressure victims.
What FBI applicants, employees and families should do now Even while investigators work to establish the full scope, anyone who believes their information may be involved can take precautions.
Verify every unexpected FBI-related message If you applied for an FBI job, be suspicious of calls, texts or emails claiming you need to re-enter information because of the portal incident. Do not use a link or phone number contained in an unexpected message. Contact your existing Applicant Coordinator or reach the FBI through a channel you already know. The FBI's own ShinyHunters guidance recommends verifying unusual requests through another method before responding.
Warn family members and emergency contacts This step becomes particularly important because the reported sample included spouses and emergency contacts. Tell people listed on employment or application records to be cautious if someone suddenly knows their connection to you. Criminals may target a relative because they expect that person to have fewer security safeguards. If someone claims there is an urgent problem involving you, an employer, or law enforcement, verify the story independently before sharing information or sending money.

Freeze your credit if your Social Security number may be exposed A credit freeze can make it harder for someone to open a new credit account in your name. You need to place the freeze separately with Equifax, Experian and TransUnion. The FTC says credit freezes are free and remain in place until you lift them. A freeze will not prevent every form of identity theft.
Keep a close eye on every account you already own. If your Social Security number might have been exposed, consider getting an IRS Identity Protection PIN to shield yourself from tax identity theft. This six-digit code stops others from filing a federal return using your SSN or Individual Taxpayer Identification Number. Any eligible person can request one after verifying their identity, so keep that number strictly private. The IRS will never call, email, or text you asking for this specific pin.
Watch your financial, tax, and medical activity carefully. Spot new accounts you do not recognize, unfamiliar charges, or sudden changes to existing ones. Unexpected IRS notices, rejected filings, and strange medical bills also signal trouble. These red flags point to identity theft types a credit freeze alone may miss. If you find proof of theft, report it through IdentityTheft.gov and stick to the recovery plan for compromised data.
Strengthen your online accounts before phishing attacks begin. Neither Reuters nor the FBI statement from Sept. 23 mentioned passwords in the leaked 5,000 records. Still, exposed personal details make password-stealing attempts far more convincing. Use a unique password for every important account and let a password manager track them all. Turn on two-factor authentication or passkeys wherever possible. Be wary of unexpected requests to reset your password.
Keep strong antivirus software running on your devices at all times. A personalized phishing message can still hide a malicious link or infected attachment inside it. Good security tools detect known phishing sites, bad downloads, and malware before they compromise your machine. This layer helps if a scam email looks unusually believable. Software cannot replace careful clicking, but it catches threats that look too real to ignore. Visit CyberGuy.com for my picks of the best 2026 antivirus winners for Windows, Mac, Android, and iOS.

Reduce how much personal information strangers can find online. If your home address, phone number, and relatives appear on people-search sites, leaked records give criminals even more material to work with. Search for yourself and review what is publicly visible right now. You can request removal from many data brokers or use a service to handle recurring opt-out requests. Less public info means fewer pieces for a criminal to combine with breach data. Check out my top picks for data removal services at CyberGuy.com to get a free scan of your online footprint.
Use dark web monitoring as an early warning system. These tools alert you when information tied to your email, phone, or SSN shows up in known breach collections. Some identity theft companies offer this service to find exposed data and notify you immediately. Treat every alert as a warning rather than proof that someone stole your identity yet. Monitoring cannot stop info from circulating once criminals get it, but it gives you time to secure accounts and act sooner. See my tips on the best identity theft protection at CyberGuy.com.
Do not pay anyone who claims to have your data. The FBI guidance regarding ShinyHunters recommends against paying or engaging with threat actors making demands. Save threatening communications instead of deleting them. Preserve screenshots, email addresses, phone numbers, and other identifying details for later use. You can report cybercrime through the Internet Crime Complaint Center at IC3.gov without delay.
If someone appears to face an immediate physical threat, contact emergency services right away. Kurt's key takeaways highlight a troubling reality: major questions remain unanswered regarding the FBIJobs.gov incident. The statement released by the FBI on Sept. 23 left the exact point of breach unresolved. Furthermore, the Bureau had not publicly validated ShinyHunters' claim that it stole between 2 and 3 terabytes of data. Still, those data samples deserve serious attention. Reuters verified details belonging to more than 22 people and reported that the spreadsheet contained Social Security numbers, home addresses, dates of birth, emergency contacts and information about sensitive assignments.
What concerns me most is how useful those pieces become when they are connected. A criminal who knows where you work, where you live and who your spouse is has a much easier time building a scam that feels authentic. For FBI personnel tied to intelligence or covert technical work, the exposure could create security concerns that reach well beyond financial fraud. The takeaway for the rest of us is practical. You cannot control the security of every employer, government agency or company holding your information. You can control how much information about you remains publicly available, how strongly your accounts are protected and how quickly you respond when something suspicious appears.
If information this sensitive can potentially be exposed through a system connected to the FBI, how confident are you about the employers, companies and government agencies holding your personal data? Let us know by writing to us at CyberGuy.com. Sign up for my FREE CyberGuy Report to get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily. Plus, you'll get instant access to my Ultimate Scam Survival Guide free when you join. CLICK HERE TO DOWNLOAD THE FOX NEWS APP. Copyright 2026 CyberGuy.com. All rights reserved.
Photos