
The FBI has reportedly told employees that a cyberattack on its job application portal exposed personal information belonging to agents and support staff, marking the bureau’s first internal acknowledgement that employee data was taken in the incident. The revelation follows days of uncertainty over what, exactly, hackers managed to steal from the FBIJobs.gov system, which has remained offline while the bureau responds.
FBI declares a cyber security incident
According to reporting from MS NOW’s Ken Dilanian, the FBI sent an internal notification over the weekend saying it had declared a “cyber security incident” related to the breach. The notice reportedly informed staff that names, addresses, job titles and Social Security numbers were exposed.
The FBI had not publicly confirmed a breach before that internal acknowledgement. Last week, the bureau said it was aware that a hacking group had claimed responsibility for a cyberattack, but added that the theft of data was “still undetermined.” The new notification suggests the bureau has now concluded at least some employee information was compromised.
Several media outlets have since reported that the stolen material also included medical information, among it records related to blood and urine samples and psychiatric reports. Those details, if confirmed, would widen the scope of the incident beyond standard personnel records and into highly sensitive personal data.
What hackers say they stole from FBIJobs.gov
The hacking group ShinyHunters has claimed responsibility for the breach. In comments previously provided to TechCrunch, the group said it had “data on mostly all of FBI” and a “substantial” amount of information on applicants who applied through the FBIJobs.gov portal.
ShinyHunters said the intrusion involved exploiting a vulnerability in an Oracle PeopleSoft server that hosted human resources information for agents and current or former employees who used the application portal. That detail matters because PeopleSoft systems often store large volumes of sensitive personnel data, including identifying information, employment records and application materials.
Importantly, the hackers told TechCrunch they were not demanding a financial ransom. Instead, they said they wanted the FBI to correct an earlier report they believe misrepresents their activities. That unusual demand sets this case apart from many other major intrusions, where criminals typically seek payment in exchange for not leaking or selling stolen data.
Why the exposure matters
Even a limited leak of employee records can create lasting security risks for a federal law enforcement agency. Justin Sherman, a national security expert, described the breach as a “counterintelligence disaster” for the U.S. government in a blog post for Lawfare.
He warned that stolen information could “expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more.” That concern is especially significant when the records involve names, addresses, job titles and Social Security numbers, all of which can be used to target individuals with identity theft, impersonation or social engineering attacks.
If the medical data reports are accurate, the potential harm could extend further. Sensitive health information can be used to embarrass, pressure or manipulate victims, and in some cases can help attackers build more convincing phishing lures or assess vulnerabilities within a target organization.
What may be at risk
- Personal identifiers such as names and Social Security numbers
- Contact information, including home addresses
- Employment details, such as job titles
- Possible medical and psychiatric records
- Broader intelligence value for profiling or targeted recruitment
Congress may need to be notified
The internal staff notification does not yet answer a separate question: whether the FBI has told lawmakers with oversight responsibility for the bureau. Under federal law, agencies are required to notify Congress when an intrusion rises to the level of a “major incident,” including cases where a breach involves personally identifiable information that is “likely to result in demonstrable harm” to U.S. national security.
That threshold could become important here if the FBI determines the stolen data meets the statutory standard. The bureau’s lawyers are likely assessing that issue now, according to the reporting. If a formal congressional disclosure is required, this would be the FBI’s second known notification to lawmakers this year about a breach.
Earlier this year, hackers suspected to be Chinese broke into a surveillance system and exposed targets of FBI surveillance and investigations, according to the source material. That earlier incident added to concerns about the bureau’s cybersecurity defenses and the sensitivity of the systems it uses to manage investigations and personnel information.
The FBIJobs.gov portal remains down
ABC News reported that the FBI’s job site has served as the primary way to apply for positions with the bureau since 2017. The portal remained offline at the time of publication, which suggests the FBI is still working to contain the breach, assess the damage and restore services safely.
The outage is not just a technical inconvenience. For a major federal agency, a recruitment portal can be a gateway to large collections of applicant and employee records, making it a valuable target for hackers. Shutting it down may help limit further exposure while investigators determine how the attacker entered the system and what data was accessed.
Questions still unanswered
Several important details remain unresolved. The FBI has not publicly provided a full account of the breach, and it has not commented on whether the internal notification amounts to a formal acknowledgement of the scope of the incident. A spokesperson for the bureau did not respond to TechCrunch’s request for comment on Monday.
A White House spokesperson also did not respond to an email asking whether the FBI had declared a major incident. Representatives for several lawmakers with FBI oversight responsibilities likewise did not have immediate answers, according to the source material. That leaves the public record incomplete even as employees are apparently being warned about personal exposure.
For now, the breach appears to be another reminder that government personnel systems can contain some of the most attractive data for attackers. Once stolen, records involving employment history, identities and medical details can be used long after the initial intrusion is discovered.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: September 28, 2026 at 10:32 pm
0 views
