The FBI is investigating unauthorized activity affecting its jobs website as the cybercrime group makes broader claims about stolen employee and applicant records.
WASHINGTON, DC — The FBI is investigating apparent unauthorized activity involving its online jobs portal after the cybercrime group ShinyHunters claimed it breached bureau systems and obtained sensitive information about current and former employees and people who applied for FBI jobs.
The bureau has confirmed that it is investigating activity affecting FBIjobs.gov but has not publicly confirmed the full scope of ShinyHunters’ claims or specified what information may have been accessed. The jobs website, which prospective employees use to learn about FBI careers and begin the application process, remained unavailable Wednesday morning. The incident raises concerns because personnel and applicant records can contain information that could expose government employees and their families to fraud, harassment or other targeting.
ShinyHunters claimed it obtained information covering nearly all FBI agents as well as people who had applied for jobs with the bureau. The group also alleged that additional FBI services involving criminal justice, human resources and medical-related functions were compromised. Those broader claims have not been confirmed by the FBI, and the bureau has not disclosed whether systems beyond its jobs website were affected.
The group provided journalists with a sample said to contain records involving about 5,000 FBI personnel. 404 Media reported that the material included names, home addresses, telephone numbers and information about employees’ spouses. The publication said it verified portions of the sample. The existence of apparently legitimate records does not independently establish the group’s broader claim that it obtained information covering nearly all FBI personnel or applicants.
ShinyHunters also claimed responsibility for altering the FBI jobs website. Recorded Future News reported that agency images on the site were replaced with an image associated with the group. By Wednesday morning, the site displayed a notice indicating that the special agent application portal was unavailable. The FBI has not publicly provided a technical explanation for the disruption or said when normal service will resume.
The hacking group portrayed the incident as a response to an FBI public service announcement issued May 15 about ShinyHunters. In that advisory, the FBI described ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. The bureau said actors using the ShinyHunters name have used real or exaggerated claims about stolen information to pressure victims and have employed harassment tactics in some incidents.
ShinyHunters disputed portions of that characterization and demanded that the FBI remove or correct the advisory. The group said its latest action was not financially motivated. Its explanation for the alleged breach remains the group’s own account and has not been independently established as the motive behind the intrusion.
Questions also remain about how the intrusion occurred. ShinyHunters has claimed that a previously unknown vulnerability involving Oracle PeopleSoft software was used in the attack, according to cybersecurity reports. The FBI has not confirmed that account, and no public technical findings from the bureau have established the entry point. Until investigators release additional evidence, claims about the specific vulnerability or systems used to gain access remain unverified.
The incident could carry consequences beyond disruption of an employment website if the personnel information described by the hackers was taken. Detailed records about law enforcement employees could potentially be used for impersonation, targeted phishing, harassment or efforts to identify employees and their relatives. The extent of that risk depends on what information was actually obtained and whether it is distributed further.
The FBI has previously warned organizations about ShinyHunters and the risks created when attackers obtain sensitive personal or enterprise information. Its May advisory said stolen information can be reused in targeted phishing campaigns or transferred to other cybercriminals. The agency’s description of the group and ShinyHunters’ own account of its activities differ on several points.
The FBI has not announced how many employees or applicants may be affected, what categories of information were accessed or whether the alleged intrusion extended beyond FBIjobs.gov. The investigation remained underway Wednesday, leaving the scale of the incident and the group’s broader claims unresolved.
Author note: Last updated September 23, 2026.