The FBI confirmed on Tuesday it is investigating unauthorized activity affecting its jobs portal, FBIjobs.gov, which remained offline the following day. The disruption follows a claim by the hacking group ShinyHunters that it breached the site and stole data on almost all FBI agents and job applicants, including names, home addresses, Social Security numbers, and in some cases, details about family members.
ShinyHunters cited a May 2026 FBI public service announcement as motivation for the attack, stating the bureau’s warning against paying ransom demands prompted their action. The group shared a screenshot of a defaced FBI jobs website and a sample of allegedly stolen data with Reuters, though the authenticity of the sample could not be independently verified. Reuters partially verified some details in the sample by cross-referencing names, addresses, and Social Security numbers against credit bureau records and previously breached data, finding matches in at least nine cases.
The FBI stated in a release: "The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating." The bureau did not provide further details about the scope or nature of the breach. The FBI Special Agent Applicant Portal also displayed an "unavailable" notice alongside FBIjobs.gov.
Hacking Group Background and Tactics
ShinyHunters, active since at least 2019, has been linked to multiple high-profile breaches, including alleged thefts from Rockstar Games, Canvas learning platform, and Anthropic’s AI tools. The group typically engages in extortion, threatening to leak stolen data unless ransom demands are met. In this instance, however, ShinyHunters framed its actions as retaliatory, stating it targeted the FBI in response to the bureau’s public warning against paying extortion demands.
Cybersecurity experts noted that the group often exaggerates or falsifies claims of access to sensitive data to pressure victims. The FBI’s May announcement described ShinyHunters as a cybercriminal group specializing in large-scale data breaches, warning that the group may use threats, harassment, or false emergency reports to coerce payments. The bureau also cautioned that victims should not respond to extortion demands.
Scope and Verification Challenges
ShinyHunters claimed to have stolen 2 terabytes of data, including information from FBI criminal justice, human resources, and other systems. The group alleged the breach involved a zero-day vulnerability in Oracle’s PeopleSoft platform, though this claim has not been independently confirmed. Cybersecurity researchers told Axios that while the attack itself appeared legitimate, the full extent and authenticity of the stolen data remain unverified.
A sample of 5,000 records provided by the group contained purported addresses, phone numbers, dates of birth, and in some cases, details about spouses. Some phone numbers matched individuals in open-source intelligence databases, including those linked to Justice Department personnel, according to checks by 404 Media. However, Reuters could not establish the origin of the data or confirm whether it was obtained from FBI systems as claimed.
Potential Risks and Long-Term Implications
Cybersecurity analysts warned that if the data is legitimate, its exposure could pose long-term risks to FBI employees and their families. Allan Liska, a threat intelligence analyst at Recorded Future, noted that the data is likely to be repeatedly downloaded and shared among criminal groups if circulated on the dark web. The FBI has faced past data breaches that compromised the privacy of its staff, raising concerns about the bureau’s vulnerability to cyber threats.
ShinyHunters has not specified its next steps but has historically followed a pattern of leaking data incrementally to increase pressure on victims. The group’s dark-web communications and public statements suggest a strategy of maximizing visibility and disruption, though the FBI has not indicated whether it intends to engage with the hackers.
Official Responses and Ongoing Investigation
The FBI’s statement did not address whether any ransom demands had been made or whether the bureau had identified the method used to breach FBIjobs.gov. The bureau has not responded to repeated requests for comment from multiple outlets. Cybersecurity experts emphasized the importance of a thorough investigation to determine the full impact of the breach and to identify potential vulnerabilities in the FBI’s systems.
As of Wednesday morning, FBIjobs.gov remained inaccessible, with no timeline provided for its restoration. The investigation is ongoing, and further updates are expected as authorities assess the validity and scope of the hacking group’s claims.