Skip to content
Data breachOngoing

FBI declares cyber incident after breach of its FBIJobs.gov hiring portal (2026)

The FBI declared a cyber security incident and warned staff their personal data may have been exposed after the ShinyHunters group claimed it breached the bureau's FBIJobs.gov hiring portal.

Victim
Federal Bureau of Investigation (FBI)

In late September 2026, the U.S. Federal Bureau of Investigation (FBI) declared a "cyber security incident" and notified employees, agents, and job applicants that their personal information may have been exposed in a breach of its recruitment website, FBIJobs.gov. The hacking group ShinyHunters claimed responsibility, saying it had accessed records tied to the portal. FBI spokesperson Benjamin Williamson said the bureau's first agency-wide email went out on 22 September, "less than 12 hours after public reporting surfaced."

What happened

The FBI told staff that exposed data could include names, addresses, job titles, and Social Security numbers. According to samples reviewed by reporters, some of the material the attackers claimed to hold went further โ€” reportedly including home addresses, assignments, names of family members in some cases, and sensitive records such as medical test results and psychiatric reports associated with the hiring and vetting process. The FBI has not confirmed the full scope of what was taken.

Investigators suspect the intruders gained access by exploiting an unpatched vulnerability in an Oracle system, the same class of software ShinyHunters targeted in an extortion campaign earlier in 2026. As of the latest reporting, the FBI said it had not yet determined whether the breach originated within the bureau's own environment or through a third-party provider that operates the jobs platform.

Why it matters

A compromise of a law-enforcement hiring portal is unusually sensitive: the records it holds can identify agents, reveal their assignments and home addresses, and expose the vetting details of applicants โ€” information that could put individuals at physical risk or aid hostile intelligence services. The incident also fits a broader 2026 pattern in which ShinyHunters and allied groups have chained exploitation of enterprise software against high-value government and corporate targets, turning a routine recruitment system into a national-security exposure.

Timeline

  1. The FBI sends its first agency-wide email about the incident, less than 12 hours after public reporting of the alleged breach surfaces.

  2. Further reporting details the scope of data the hackers claim to have taken; the FBI says the source of the breach is still under investigation.

Sources

  1. techcrunch.comhttps://techcrunch.com/2026/09/28/fbi-reportedly-declares-cyber-security-incident-after-hackers-steal-agents-personal-data/
  2. foxnews.comhttps://www.foxnews.com/politics/fbi-source-jobs-portal-breach-still-unknown-hackers-allege-employee-data-compromised
  3. yahoo.comhttps://www.yahoo.com/news/us/articles/social-security-numbers-birth-dates-035746706.html

Related incidents

Data breachContained

Florida DMV confirms breach of DAVID driver database via compromised law-enforcement account

Florida's Department of Highway Safety and Motor Vehicles confirmed that attackers used a compromised law-enforcement account to breach its DAVID driver database, as the ShinyHunters extortion group claimed to have stolen more than 200,000 driver records.

Victim
Florida Department of Highway Safety and Motor Vehicles
Records
200.0K