FBI Jobs Breach Exposes Hacking Unit Details, FBI Confirms Investigation

The FBI is investigating a breach of its jobs website after the hacking group ShinyHunters claimed to have stolen sensitive data on nearly all agents and applicants. The group, which previously targeted Rockstar Games and Canvas, alleges it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating two to three terabytes of data. The FBI jobs portal was defaced and taken offline. ShinyHunters demanded the removal of a May 2026 FBI advisory that labeled them a cyber-criminal group, rather than demanding ransom. The FBI confirmed it is investigating the unauthorized activity but declined to verify the extent of the data theft.
Key points
- FBI confirmed it is investigating unauthorized activity affecting FBIjobs.gov, which remained offline Wednesday morning.
- ShinyHunters claimed responsibility, stating they compromised 'very sensitive data' on almost all FBI agents and job applicants.
- The group alleged it exploited a zero-day vulnerability in Oracle PeopleSoft to access AWS GovCloud servers, exfiltrating two to three terabytes of data.
- ShinyHunters demanded the FBI remove a May 2026 public service announcement that characterized them as a 'cyber criminal group' specializing in extortion.
- 404 Media verified parts of a 5,000-record list shared by ShinyHunters, finding data on members of the FBI's Remote Operations Unit (ROU), including addresses, phone numbers, and spouse details.
- The FBI stated the point of breach is undetermined, whether a third-party or the FBI's enterprise, and is working with third-party providers to mitigate risks.
Background
This incident follows a pattern of high-profile intrusions by ShinyHunters, including breaches of Rockstar Games and the education platform Canvas. In March 2026, the FBI disclosed investigating 'suspicious activities' on an internal system containing sensitive surveillance data. Also in March, a pro-Iranian hacking group claimed to have hacked FBI Director Kash Patel's account, posting years-old photographs and personal documents. In September 2026, the FBI also investigated a breach at an ID-verification company that exposed digital copies of up to 160 million licenses and IDs.
How outlets are covering it
The Guardian reported that the FBI is aware of claims regarding unauthorized activity and is investigating, but declined to comment further on the specifics of the data theft. 404 Media provided deeper analysis, verifying parts of the stolen data and highlighting that the breach includes members of the FBI's secretive Remote Operations Unit (ROU), potentially revealing who is in that hacking team. 404 Media noted that the stolen data includes job titles related to investigating China or Russia, as well as 'remote operations units.' The FBI's statement emphasized that the point of breach is undetermined and that they are working with third-party providers to mitigate risks, while ShinyHunters framed the breach as a retaliatory response to the FBI's May 2026 advisory.
Why it matters
The breach exposes sensitive personal data on FBI agents, including members of the Remote Operations Unit, which could compromise ongoing investigations and national security operations. The incident highlights vulnerabilities in government systems and the potential for hackers to exploit zero-day vulnerabilities in critical infrastructure. The FBI's investigation and the group's demand for the removal of a prior advisory underscore the ongoing tension between law enforcement and cyber-criminal groups.
What to watch
The FBI is actively investigating the breach and working with third-party providers to mitigate risks. ShinyHunters has given the FBI one week to correct or remove the May 2026 advisory. The FBI has not confirmed the extent of the data theft, and verification of the stolen data remains ongoing. The incident may lead to further scrutiny of the FBI's cybersecurity measures and the Remote Operations Unit's operations.
- FBI investigates breach of jobs website as hackers claim ‘very sensitive data’ stolen The Guardian
- Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records The New York Times
- FBI Hack Exposed FBI’s Own Hacking Unit 404 Media
- EXCLUSIVE: Hacked FBI data has sensitive information about employees’ intelligence roles reuters.com
- FBI investigating possible cyber breach of its job application website: Sources ABC News - Breaking News, Latest News and Videos
Want the full story? Read the original reporting
Read on The Guardian