Hackers Say They Stole Data on Nearly Every FBI Agent, and the Bureau Is Investigating
ShinyHunters says it broke in through the FBI's jobs portal and took 2 to 3 terabytes of files, including agents' home addresses and spouses' names. A former agent confirmed a sample was real.

The FBI said Wednesday it is investigating claims by the extortion gang ShinyHunters that it broke into the bureau's systems and stole personal information on "almost ALL FBI Agents" and on people who applied to work there.
"The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information," the bureau said in a statement. "While the point of breach is still undetermined — whether a third-party or the FBI's enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk." Both the FBI jobs site and its special agent applicant portal were offline this week.
A representative of the group told NBC News that ShinyHunters got into the jobs portal on Monday, moved from there into other agency programs, and took between 2 and 3 terabytes of files. According to 404 Media, which first reported the breach, the hackers got in through an Oracle PeopleSoft server of the kind human resources departments use to store applicant records. From there, they said, they reached an Amazon-hosted government cloud holding agent and applicant data. The sample the group released included agents' names, home addresses, phone numbers and the names of their spouses. A former FBI agent confirmed to NBC News that one sample document was authentic. Reuters ran names, addresses and Social Security numbers from the sample against credit bureau records and found matches in at least nine cases, though it could not confirm the data came from FBI systems.
The group says money is not the motive. It says the attack was revenge for an FBI alert in May that described ShinyHunters' methods and told victims not to pay. In a post on its site, the group called that alert "disinformation" and said it would publish the stolen data in a week unless the FBI withdraws it. "We have been working on this since the release of the FBI FLASH report they made on us in May. This was well planned and coordinated," a spokesperson told NBC News.
Security experts say the danger goes beyond embarrassment. FBI agents often sign their names to court filings against dangerous criminals, and foreign intelligence services could use home addresses and family details to pressure or recruit them. "This type of information could be used by criminals to target or physically harm FBI agents, personnel and their families," said Cynthia Kaiser, a former deputy director of the FBI's cyber division who now works at the security firm Halcyon. She said extortion crews usually mix "truth and lies" and tend to exaggerate, but she did not think the group was inventing its access. Picking a fight with the FBI is also risky for the hackers, she said: "That's normally a recipe for a takedown."
ShinyHunters is a loose network with members around the world. It has been tied to a May break-in at the education platform Canvas that disrupted schools across the United States and to a claimed theft of business records from Rockstar Games, the maker of "Grand Theft Auto." Earlier this month, the AI company Anthropic said it had repeatedly disrupted ShinyHunters affiliates trying to use its tools in their hacking.
It is the second known breach of an FBI system this year. Earlier, unidentified hackers got into an agency system used to manage real-time wiretaps and foreign intelligence warrants. Separately, an Iran-backed group called Handala hacked and leaked FBI Director Kash Patel's personal email.




