IT-PUB NEWS

FBI says hackers stole agents’ personal data

29.09.2026 12:03 • Author: IT-PUB
FBI says hackers stole agents’ personal data

An internal FBI notice said a breach of its jobs portal exposed names, addresses, Social Security numbers, and in some cases medical records.

The FBI has reportedly told employees that hackers stole personal information from its job application portal, the bureau’s first known internal acknowledgement that agents’ data was taken in the incident. The breach has drawn attention not just because it hit one of the most sensitive U.S. law enforcement agencies, but because the stolen material appears to include deeply personal details.

The bureau has not publicly confirmed the full scale of the breach. Last week, it said only that it was aware of a hacking group’s claim and that whether data had been stolen was still undetermined. But, according to reporting by MS NOW’s Ken Dilanian, the FBI has now declared a “cyber security incident” in a notice to staff.

FBI staff were told their data was exposed

In the internal notification, the FBI said employees’ names, addresses, job titles, and Social Security numbers were exposed. That alone makes the incident serious, since those details can be used for identity theft, targeted scams, or other kinds of abuse.

Several media outlets have also confirmed that some of the stolen data included medical information. According to IT-PUB News, that reportedly covered records related to blood and urine samples, as well as psychiatric reports. The source text does not say how many people were affected, but the presence of this kind of material makes the breach more sensitive than an ordinary personnel-data leak.

The hackers say they used an Oracle PeopleSoft flaw

The group calling itself ShinyHunters previously told TechCrunch that it had data on “mostly all of FBI” and a “substantial” amount of information on applicants who used the FBIJobs.gov portal. The hackers said they got in by exploiting a vulnerability in an Oracle PeopleSoft server that stores large amounts of human resources information.

That helps explain why the incident matters beyond the bureau itself. A job portal can hold data on current staff, applicants, and others tied to hiring processes, meaning a single breach can expose a wide range of personal records in one place.

The hackers also said they are not seeking a financial ransom. Instead, they want the FBI to correct an earlier report that they claim misrepresented their activities. The source does not say whether the bureau has responded to that demand.

A breach with national security implications

The leak has raised concern because of who was affected. Justin Sherman, a national security expert, called it a “counterintelligence disaster” in a Lawfare blog post. He said the stolen information could expose thousands of FBI personnel to profiling, phishing, and foreign intelligence approaches.

That points to a risk beyond privacy. When personal and employment data tied to law enforcement staff is exposed, it can create openings for social engineering, pressure campaigns, or attempts to map who works where.

The FBI has not said publicly whether it has determined the incident to be a “major incident” under federal law. That designation matters because it can trigger a requirement to alert Congress when an intrusion involves personally identifiable information likely to cause demonstrable harm to U.S. national security.

Questions remain over congressional disclosure

It is still unclear whether lawmakers have been told about the breach. The source says that if the incident meets the legal threshold, the FBI would have to notify Congress. If that happens, it would be the bureau’s second known notification to lawmakers this year about a data breach, after hackers suspected to be Chinese broke into a surveillance system and exposed targets of FBI surveillance and investigations earlier this year.

So far, the FBI has not commented publicly on the latest incident. A bureau spokesperson did not respond to TechCrunch’s request for comment on Monday, and a White House spokesperson also did not answer questions about whether the bureau had declared a major incident.

Representatives for several lawmakers with oversight responsibility for the FBI also did not have immediate answers, according to the source.

The bureau’s job site has been the main way to apply for a position with the FBI since 2017, according to ABC News. The portal remains down at the time of publication, suggesting the incident is still disrupting access to a system used for recruitment and hiring.

For employees and applicants, the immediate concern is what can be done with the exposed data. For the FBI, the bigger problem is how a portal meant to collect job applications became the route to a breach that now raises questions about personal safety, internal security, and possible national security fallout.


Improve SEO for a small/medium business website for $50