
The agency responsible for investigating cybercrime just became one of its most consequential victims. According to TechCrunch, the FBI has issued an internal notification to staff declaring a “cyber security incident” after hackers stole the personal information of agents and support staff from the bureau’s job application portal, FBIJobs.gov. We’re not talking about generic account credentials here. Names, home addresses, job titles, Social Security numbers, and medical records, including blood work, urine samples, and psychiatric reports, were taken. That’s the kind of data profile that lets a foreign intelligence service build a very detailed picture of exactly who works for the FBI and how to approach them.
The hacking group ShinyHunters previously told TechCrunch they have data on “mostly all of FBI” and a “substantial” amount of information on applicants who went through the FBIJobs.gov portal. The method was not sophisticated in any flattering way: the attackers exploited a vulnerability in an Oracle PeopleSoft server, a human resources platform that stored years of sensitive personnel records. ShinyHunters says they are not after money. Instead, they are demanding the FBI correct an earlier report they claim misrepresents their activities. That framing, whether genuine or performative, does not make the data any less exposed.
The FBI’s public posture last week was careful to the point of evasive. Its official statement acknowledged that a hacking group had claimed an attack but said the theft of data was “still undetermined.” That language aged poorly. The internal notification to staff, first reported by NBC News reporter Ken Dilanian, tells a very different story. Employees were told their data was taken. Full stop.
National security expert Justin Sherman described the breach as a “counterintelligence disaster,” warning it would expose thousands of FBI personnel to profiling, phishing, and foreign intelligence approaches. That assessment is hard to argue with. A list of FBI agents paired with their home addresses and psychiatric histories is not just an embarrassment. It is an operational threat to the people named in those files.
There is also a legal question hanging over this. Federal law requires the FBI to notify Congress when a breach qualifies as a “major incident,” which includes theft of personally identifiable information likely to cause demonstrable harm to national security. The bureau’s lawyers are almost certainly working through that determination right now. If they decide notification is required, it would be the FBI’s second congressional disclosure about a data breach this year. The first followed a separate intrusion, attributed to Chinese hackers, that compromised an FBI surveillance system.
The White House deferred comment to the FBI. The FBI did not respond to TechCrunch’s questions. Several congressional oversight offices had no immediate answers. FBIJobs.gov remained offline at the time of publication. The site has been the bureau’s primary hiring portal since 2017, meaning this breach potentially spans nearly a decade of applicant and employee data.
So the agency that tells companies to patch their systems, report breaches promptly, and cooperate with investigators is now on the other side of that conversation. The irony would be almost funny if the stakes were not this serious for the people whose data is now circulating outside the bureau’s control.