The FBI has reportedly told employees that their personal information was stolen in the recent cyberattack targeting FBIJobs.gov, marking the strongest acknowledgment yet that the ShinyHunters intrusion resulted in the compromise of sensitive bureau personnel data.
The internal notification represents a significant development in the incident first reported by BreachNews after ShinyHunters claimed it breached FBIJobs.gov through Oracle PeopleSoft and obtained extensive employee and applicant information.
According to reporting from TechCrunch, the FBI declared a “cyber security incident” in an internal notification sent to agents and support staff. Employees were reportedly told that exposed information includes names, home addresses, job titles and Social Security numbers.
The notification appears to be the FBI’s first acknowledgment to its workforce that employee information was actually compromised. The bureau’s previous public statement said it was investigating ShinyHunters’ claimed compromise of FBIJobs.gov and an alleged impact to employee personally identifiable information, but said the extent of any data theft remained undetermined.
FBI employees told Social Security numbers were exposed
The information reportedly identified in the FBI’s internal notification significantly increases the potential impact of the breach.
Exposed information reportedly includes employee names, home addresses, job titles and Social Security numbers. Previous reporting has also independently corroborated portions of a sample containing approximately 5,000 purported FBI employee records supplied by ShinyHunters.
Some of those records identify personnel associated with sensitive intelligence and counterintelligence roles, including work involving China, Russia and Iran, human intelligence operations and electronic surveillance.
Additional reporting has examined purported medical and psychiatric records allegedly obtained during the intrusion. Portions of those records have been independently authenticated, adding further evidence that the compromised information extends beyond basic employee contact details.
The FBI has not publicly disclosed how many current or former employees are affected.
ShinyHunters says it will not publish FBI data
As the FBI continues investigating the incident, ShinyHunters has changed its public messaging surrounding the stolen information.
In a statement provided to Nextgov/FCW on September 28, the group said it does not intend to publicly release the FBI data and described its confrontation with the bureau as a “marketing campaign.”
ShinyHunters said it had decided from the beginning that it would not publish the information and claimed the operation was intended to defend the group’s reputation following an FBI warning about its tactics.
The group previously demanded that the FBI correct or remove information it described as inaccurate and gave the bureau approximately one week to comply.
ShinyHunters now says it never expected the FBI to comply and intentionally did not specify what would happen if the bureau ignored the demand.
The group’s statement does not indicate that the stolen information has been deleted. Samples have already been distributed to journalists and examined by multiple news organizations.
Full scope of FBI breach remains unclear
Despite growing confirmation that FBI employee information was compromised, the complete scope of the incident remains unresolved.
ShinyHunters claims it obtained between 2TB and 3TB of information covering current and former FBI employees, applicants and internal records. The group has also claimed access to FBI-managed AWS GovCloud infrastructure and systems associated with human resources and medical functions.
The full 2TB to 3TB figure has not been independently verified, and the FBI has not publicly confirmed the broader scope claimed by ShinyHunters.
The FBI previously said investigators had not determined whether the initial point of compromise was within the bureau’s own enterprise or a third-party provider supporting FBIJobs.gov.
PeopleSoft attack method remains under investigation
ShinyHunters has attributed the FBIJobs.gov compromise to vulnerabilities affecting Oracle PeopleSoft, the enterprise software used by the FBI’s recruitment infrastructure.
Google Threat Intelligence Group and Mandiant recently confirmed that ShinyHunters, tracked as UNC6240, has resumed mass exploitation of Oracle PeopleSoft systems using CVE-2026-35273, a critical vulnerability the group previously exploited as a zero-day earlier in 2026.
Researchers found that ShinyHunters modified its exploitation technique to bypass some web application firewall mitigations by encoding portions of requests targeting the vulnerable PeopleSoft Environment Management Hub endpoint.
ShinyHunters has claimed that the FBIJobs.gov attack involved PeopleSoft exploitation and has separately alleged the existence of another previously unknown vulnerability affecting the same PSEMHUB component.
The additional vulnerability remains unverified. Oracle, the FBI and CISA have not publicly confirmed a second PeopleSoft zero-day or assigned a CVE to the alleged flaw.
FBI breach raises counterintelligence concerns
The exposure carries potential consequences beyond conventional identity theft because some of the compromised records reportedly identify personnel involved in sensitive intelligence and surveillance work.
Information linking FBI personnel to specific roles, home addresses, relatives or other personal details could potentially be used for targeted phishing, surveillance, harassment or foreign intelligence operations.
The combination of Social Security numbers, home addresses, employment information and potentially medical records also creates longer-term risks for affected personnel even if ShinyHunters follows through on its statement that it will not publicly release the dataset.
ShinyHunters’ decision not to publish the information would not necessarily prevent copies already shared with third parties from being retained or redistributed.
FBI investigation continues
The FBI has not yet issued a public statement matching the level of detail reportedly provided to employees in the internal notification.
The bureau’s latest public acknowledgment said investigators were examining the claimed FBIJobs.gov compromise and potential impact to employee personally identifiable information.
The reported internal notification significantly advances that picture by indicating that the FBI has identified specific categories of employee information exposed during the incident, including Social Security numbers and home addresses.
Important questions remain unresolved, including the total number of affected employees and applicants, the complete volume of information stolen and whether ShinyHunters’ claimed additional PeopleSoft vulnerability played a role in the initial compromise.
BreachNews will continue monitoring the FBI investigation, Oracle and CISA disclosures, developments involving the alleged PeopleSoft vulnerability and additional information concerning the scope of the stolen data.










