Updated
Updated · The New York Times · Sep 28
FBI Declares Cybersecurity Incident After Hack Threatens PII of All Employees
Updated
Updated · The New York Times · Sep 28

FBI Declares Cybersecurity Incident After Hack Threatens PII of All Employees

3 articles · Updated · The New York Times · Sep 28

Summary

  • Friday’s internal memo told FBI staff the bureau is treating the ShinyHunters intrusion as a cybersecurity incident and assumes the hackers may have exfiltrated personally identifiable information on all employees.
  • Nearly a week after the group breached the FBI’s jobs portal, investigators were still determining how the attack happened and how much data was taken as a leak deadline approached.
  • Tens of thousands of current and former employees may be affected; records reviewed by The New York Times indicated the haul included home addresses, Social Security numbers and sensitive job assignments.
  • The breach is already being compared with the Office of Personnel Management hack that exposed more than 20 million records, underscoring fears of long-term risks to bureau personnel.

Insights

Could the theft of terabytes of personnel files be the ultimate weapon for foreign spies to dismantle domestic counterintelligence?
How did a known software flaw allow hackers to expose the FBI's most secretive undercover agents to the world?
Will the FBI bow to criminal extortionists demanding the retraction of a cybersecurity warning to protect their exposed workforce?

The September 2026 FBIJobs.gov Breach: Anatomy, Impact, and National Security Fallout of the 2–3 TB ShinyHunters Data Theft

Overview

In September 2026, ShinyHunters launched a retaliatory cyberattack on the FBI's hiring portal, FBIJobs.gov, after disputing an earlier FBI warning about their extortion tactics. Exploiting a zero-day vulnerability in Oracle PeopleSoft, the group breached the portal, exfiltrated up to 3 terabytes of sensitive data—including personal and medical information of FBI agents and applicants—and shared a sample with journalists, who verified its authenticity. The FBI quickly took the portal offline, but the exposure created severe counterintelligence and safety risks for agents and their families. This high-profile breach is now driving urgent security reviews across federal agencies and intensifying efforts to track down ShinyHunters.

...