FBI Data Breach: Hackers Say They Hold Agents' and Job Applicants' Home Addresses

FBI Data Breach: Hackers Say They Hold Agents’ and Job Applicants’ Home Addresses

In 2024 a forensic accountant in Richmond applied for a job with the Bureau. She filled in the long application on apply.fbijobs.gov, uploaded her resume, and heard nothing back. Last week her phone rang. The caller knew her date of birth, her street address and her husband’s first name, and said her background check needed one more form. That call is the shape of the FBI data breach the Bureau is now investigating. She had typed all of it into a government hiring portal two years earlier.

Confirmation: 404 Media, TechCrunch and BleepingComputer all reported it on September 22, 2026. The FBI says it is investigating and has not confirmed any theft, so treat the scale as a claim rather than a finding. See the September 30 update below.

What happened in the FBI data breach

On Monday, September 21, 2026, the group put a banner on the FBI’s applicant page at apply.fbijobs.gov: “This site has been seized by ShinyHunters.” 404 Media broke the defacement the next day, and Gizmodo covered it hours later.

ShinyHunters is a theft-and-extortion crew, not a research group. It told 404 Media the way in was a previously unknown bug in Oracle’s PeopleSoft software, which many large employers run for HR and hiring. From there the group says it reached the Bureau’s Amazon GovCloud environment and pulled between 2 and 3 terabytes.

The Bureau’s statement is short. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” So far it has not said whether the group copied anything. Oracle had not commented when BleepingComputer published.

The numbers are disputed, so here are both. The group claims data on almost all FBI agents plus everyone who filed a job application. What reporters have actually seen is smaller: the group handed 404 Media a sample of roughly 5,000 purported employee records. Nextgov also reports the group demanding the Bureau retract a cyber warning, which tells you the motive is leverage.

Updates to the FBI data breach story

Update, September 30, 2026. Two things have changed since this post went up. First, the Bureau told its own staff. MS Now reporter Ken Dilanian reported on September 26 that the FBI sent employees an internal notification declaring a “cyber security incident.” It said the exposed information included names, addresses, job titles and Social Security numbers. Later reporting described medical and psychiatric records in the same set. Publicly, though, the Bureau has not gone that far. Its public line is still that the theft of data is undetermined. So treat the internal notice as the strongest signal so far, rather than as a public confirmation.

Second, there has been an arrest. Dutch police detained a 24-year-old Amsterdam man on September 15, and the FBI announced the arrest publicly on September 29. Prosecutors accuse him of participating in a criminal organization, and he is separately under investigation over an alleged plan to arrange two murders abroad. He is accused, not convicted. A ShinyHunters representative told TechCrunch that he has no association with the group.

Here is what that means for you. An arrest does not pull leaked data back. So if your Social Security number sat in a federal personnel file, step 2 below matters more this week than it did last week. You can change a password. You cannot change a Social Security number.

October 2026: a second detention, and an arrest confirmed

Update, October 4, 2026. There has been a second detention, and this one sits closer to the FBI data breach itself. Jordanian authorities took a suspected ShinyHunters member into custody on Tuesday, September 29. Reuters identified him as Saif al-Din Khader, who used the alias “Rey,” and BleepingComputer reported the detention on October 3. Two sources told Reuters that Khader is cooperating. They said he is walking investigators through his own devices and messages to help identify other members. Then, on October 4, Jordanian state media confirmed an arrest without naming the suspect, and said investigations are ongoing. So sources describe the cooperation, and no official has confirmed it on the record. The Bureau declined to discuss Khader. It said it continues to investigate and has already worked with partners to arrest multiple subjects.

Two smaller signals point the same way. The group’s leak site went offline on the day of the reported detention, and an affiliate who had been briefing reporters shut down their messaging account. But none of that undoes the exposure. A leak site can return, and copied files stay copied. So nothing below changes, and step 2 still carries the most weight for anyone whose Social Security number sat in that personnel file.

What the FBI data breach exposed, and what it buys an attacker

In the sample reporters reviewed, each record carried a name, a home address, a phone number and a date of birth. Some records also held details about the person’s spouse. Reporters did not list email addresses among those fields, so nobody should claim inbox addresses leaked.

Each item does a different job for someone building a con.

  • Home address. It makes a letter or a doorstep visit credible, and it is the field that turns a data problem into a physical one.
  • Date of birth. Support lines and banks still use it to confirm identity, so it opens phone channels.
  • Phone number. It is the delivery route for a text that quotes your real details.
  • Spouse name. Two connected people are far more persuasive than one, because a caller who names your husband sounds like they already have your file.

Why this matters even if you did not apply

Here is the part that reaches past the Bureau. ShinyHunters says the same PeopleSoft flaw is unpatched, and BleepingComputer reports the group is now aiming it at Fortune 500 companies. PeopleSoft sits behind a great many hiring portals and payroll systems, so the FBI data breach is a preview rather than an outlier.

So the lesson of this FBI data breach is not really about the FBI. Old job applications are live records. You filled in a form, you did not get the job, and the file stayed. You were told nothing, because you were not a customer and often not an employee either.

What to do now

Most of this has nothing to do with us.

1. Distrust any caller who recites your details. A birth date proves someone read a file. Hang up, then dial the number on the organization’s own website. 2. Freeze your credit at all three bureaus. It is free and takes about twenty minutes. A birth date plus an address covers most of a fraudulent application. 3. Add a passkey or an authenticator app to your email and your bank. Choose the strongest sign-in each account offers, because a texted code is the weakest one. 4. Expect a phish dressed as the Bureau. Messages will quote the incident and offer a “case portal” or identity protection. No agency asks for your Social Security number through an emailed link. 5. Check your old applications. If a former employer’s portal still holds your file, ask for deletion in writing.

How OptMsg changes this exposure

Let us be precise, because the honest version is narrower than the marketing version. The attackers took this data from someone else’s HR system. OptMsg would not have prevented that, and it does nothing about a phone call or a letter.

What it changes is the follow-up. Criminals resell breached records, and the second wave arrives as email dressed up as the breached brand. With OptMsg, mail from a sender you have not approved goes to Trash, not your Inbox, and it auto-deletes after 30 days. The message quoting your address lands somewhere you are not reading in a hurry. That is a smaller claim than “you are protected,” and it is the true one.

There is a second effect worth one line. Your OptMsg account has no password, so a password stolen from another site cannot open your inbox — and because your inbox is the reset route into most other accounts, that door staying shut matters more than it sounds.

What this does not cover: a compromised device, a live phishing page you sign into, or someone holding your unlocked phone. If you want the version of this argument aimed at personal data rather than accounts, read Private Always. If you would rather just try it, create an account and forward your existing mail to it for a fortnight.

Create Your Account

Your Inbox. Your Rules.

Frequently asked questions

Has the FBI confirmed the data breach? No. The Bureau says it is aware of claims about unauthorized activity affecting FBIjobs.gov and is investigating. It has not confirmed any theft, so every figure in circulation is the hackers’ claim.

Were email addresses exposed in the FBI data breach? Not in what reporters have seen. The sample of about 5,000 records described names, home addresses, phone numbers, dates of birth and some spouse details. Email exposure is unconfirmed either way.

I applied for an FBI job years ago. Am I affected? Possibly. The group specifically claims to hold applicant data, and the entry point was the jobs portal. Assume your application details could be in circulation and act on the steps above.

What is the Oracle PeopleSoft link? ShinyHunters says it exploited a previously unknown flaw in PeopleSoft, Oracle’s HR and hiring software. The group claims the same flaw still works elsewhere, which is why this matters beyond one agency.

Will OptMsg stop the scam calls? No. Calls and letters are outside email entirely. What OptMsg changes is where the follow-up email lands: mail from a sender you have not approved goes to Trash rather than your Inbox.

Sources

Scroll to Top