Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations

    September 23, 2026

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations
    • No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands
    • The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial
    • Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms
    • Adobe Patches Critical Flaws in Connect, AEM Forms
    • Stablecoins hold nearly $200 billion in US debt, but money funds bought the surge
    • NASA’s Hubble Seeks Lensed Supernova, Marks 200,000 Orbits
    • Millions of heads of lettuce ruined by aphid outbreak
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Business

    Hackers Say They Stole Thousands of Sensitive F.B.I. Personnel Records

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Business No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A prolific criminal hacking group said Tuesday that it had stolen a large tranche of sensitive personnel information belonging to thousands of F.B.I. officials in what would amount to a stunning breach of private data for the nation’s top law enforcement agency.

    The hackers, who call themselves ShinyHunters, said the records were stolen from an online jobs portal for the bureau and included names of current and former agents as well as applicants and corresponding home addresses, phone numbers, names of spouses, certain medical information and other data. The group does not appear to have yet leaked any of the data publicly.

    “We have compromised the FBI,” the group said in a message posted online that was addressed to the F.B.I. director, Kash Patel, and Brett Leatherman, who oversees the bureau’s cybersecurity division. “We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job.”

    In its message, ShinyHunters said it had targeted the F.B.I. as retribution for a public advisory the bureau issued in the spring warning about the group’s tactics. The group demanded the F.B.I. “correct or simply REMOVE” the advisory, which said ShinyHunters was known to harass victims and family members with threatening or coercive maneuvers, and do so within a week or risk further consequences.

    An F.B.I. spokeswoman acknowledged the breach, saying that the bureau was aware of the claims and that it was investigating. She declined to comment further on the matter. The jobs website remained inaccessible Wednesday morning after its homepage a day earlier featured a banner that read, “THIS SITE HAS BEEN SEIZED BY SHINYHUNTERS.”

    In an exchange with The New York Times, ShinyHunters described the personnel records it had, suggesting they concerned the private information of tens of thousands of people. News of the apparent hacking was reported earlier by 404 Media, an online cybersecurity and technology news publication.

    Former F.B.I. officials and cybersecurity experts who track criminal groups said that the breach appeared authentic and that it amounted to a potentially devastating security lapse and counterintelligence danger for the bureau. Among other concerns, the personnel information of F.B.I. officials, if posted on the dark web, could be acquired by foreign intelligence agencies in China, Russia or elsewhere and weaponized for espionage operations.

    “If true, this data breach is a reminder that no one is immune from cyberthreats and, unfortunately, it raises serious public safety and counterintelligence risks,” said Sumon Dantiki, a partner at the law firm Baker McKenzie and former senior F.B.I. and Justice Department official who worked on cybersecurity issues.

    A more tangible concern is that the data could also be a road map for violent criminals to seek retribution against the F.B.I. agents who put them behind bars, said Cynthia Kaiser, a former senior F.B.I. official who oversaw major cyberinvestigations. F.B.I. agents sign their names to court paperwork submitted against criminal suspects but are generally trained to avoid letting sensitive personal information, such as home addresses or familial ties, easily surface online.

    “What worries me most is how any criminal with a grudge could use this data to target and physically harm not only the F.B.I. agents who investigated them, but also those agents’ families,” Ms. Kaiser said.

    ShinyHunters is a well-known hacking collective that has been active for years and has claimed a string of major headline-grabbing breaches, though security researchers say the group has at times exaggerated or misrepresented its actions. It credibly takes responsibility for several notable hacks, however.

    In May, it said it had compromised an online learning system called Canvas that is used by thousands of schools and universities around the world, which led to the spring F.B.I. advisory. The group also said it was behind attacks against Ticketmaster in 2024, which the hackers said had compromised the user information of more than 500 million customers.

    The apparent F.B.I. breach called to mind the vast theft more than a decade ago of about 20 million government employee and contractor records from the Office of Personnel Management. That heist, which the Obama administration blamed on the Chinese government, is still considered one of the worst cybersecurity failures on record in the United States. As a result, government agencies strove to better protect and disaggregate sensitive data in an attempt to avoid future thefts of such richly detailed databases.

    Given the O.P.M. debacle, former F.B.I. officials said they were stunned to learn that such valuable — and voluminous — private information about bureau personnel appeared to be held in an online database tied to a jobs portal.

    The ShinyHunters breach would be just the latest in a recent string of cybersecurity lapses for the F.B.I. Earlier this year, the bureau identified what it believed were Chinese hackers inside a database it maintains on its domestic surveillance orders. That discovery was especially alarming because Beijing appeared to be building on a catastrophic infiltration of the F.B.I.’s internal network used to process and maintain domestic wiretaps on criminal suspects, which was part of a far-reaching espionage campaign that officials first disclosed in 2024 that infiltrated U.S. telecommunications infrastructure.

    Mr. Patel, too, had his personal emails hacked and leaked in March by a pro-Iranian hacktivist group associated with the country’s Ministry of Intelligence and Security.

    In the most recent episode, ShinyHunters said it had weaponized a zero-day, or previously undiscovered, computer bug within the Oracle PeopleSoft software, an application that companies use for human resources and financial management. The group declined to answer specific questions about the apparent flaw, saying in an email that “we intend to utilise the zero-day for our businesses’ normal operations.” Oracle did not respond to a request for comment.

    It was not clear what ShinyHunters, which said it had made off with two to three terabytes of data in total, intended to do should the F.B.I. not retract its advisory about the group. Flashpoint, a cybersecurity company in the United States, said it expected the hackers would likely follow their playbook against corporate victims and soon leak the stolen data online.

    “We cannot comment on what we will do if the F.B.I. does not comply with our request,” ShinyHunters said in its email to The Times. “We reiterate we are not extorting the F.B.I. and this is NOT financially motivated.”

    The hackers added: “Our intention, goal and motive is solely to set the record straight.”

    Tawnell D. Hobbs contributed reporting.

    F.B.I hackers personnel records sensitive stole Thousands
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    Six arrested after anti-migrant protest at Gosport marina | Police

    UK to join EU ocean science scheme to better predict extreme weather events | Climate crisis

    UK to launch military squadron to protect satellites in space | Defence policy

    Bitcoin Breaks Out as Nasdaq Hits Records and Oil Slides on Iran Hopes

    UK to review Chagos Islands deal after Trump called it ‘terrible’

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations

    September 23, 2026

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    September 23, 2026

    Zoox grounds Atlanta test fleet after workers report toxic gas exposure symptoms

    September 23, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Iran’s president says his country’s people have been ‘victims of terrorism’ by the United States – live | United Nations

    September 23, 2026

    No signs Chagos deal can be adapted to suit Trump, say UK officials | Chagos Islands

    September 23, 2026

    The Guardian view on Russian disinformation: a foreign threat that relies on UK complicity | Editorial

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.