The FBI is investigating a claimed compromise of FBIJobs.gov after a cybercriminal group alleged that employee personally identifiable information (PII) was exposed, but the Bureau still does not know whether the point of breach was its own enterprise or a third-party provider.
- The FBI investigates whether the reported FBIJobs portal compromise originated within federal infrastructure or through third-party recruitment contractors.
- Independent analysis verifies authentic Justice Department employee data across a 5,000-record sample leaked by hacking group ShinyHunters.
- Unconfirmed claims of zero-day exploits in Oracle PeopleSoft cloud environments threaten federal supply chain security across government agencies.
In a statement Wednesday, September 23, the FBI said it was aware of claims that the FBIJobs.gov portal had been compromised and that employee PII had been affected. The Bureau said the point of breach remained undetermined and that it was working with third-party providers supporting the portal to mitigate the risk.
The group using the ShinyHunters name has alleged that it obtained data on almost all FBI employees and applicants, including home addresses, phone numbers and information about family members. It has also claimed access to other FBI systems and said it obtained between 2 terabytes and 3 terabytes of data. Those claims remain unverified.
FBIJobs.gov Went Offline After Claimed Defacement
FBIJobs.gov and the Special Agent Applicant Portal went offline Tuesday, September 22, as the claims emerged. A seizure-style message claiming the site had been taken by ShinyHunters was reported on the recruiting portal before the pages became unavailable, which does not establish that the FBI’s wider enterprise was breached.
The group provided 404 Media with a sample of about 5,000 alleged records containing names, addresses, phone numbers and other personal information. Reuters and 404 Media found that portions of the sample appeared to correspond to real FBI or Justice Department personnel. Reuters also reported matching information against credit-bureau records and previously exposed data. Some records contained details that could reveal aspects of employees’ roles.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseThose matches indicate that at least some of the information appears to relate to real people. They do not establish where the records were obtained or whether they were taken from FBI systems during the alleged intrusion.
PeopleSoft And GovCloud Claims Remain Unverified
The group has claimed that it exploited a previously unknown vulnerability in Oracle PeopleSoft, an enterprise software platform used for functions including human resources, before reaching an FBI environment hosted through Amazon Web Services GovCloud. It has further claimed access to FBI human resources, criminal justice systems and MedLink, as well as the alleged 2 to 3 terabytes of data.
Reporting has established that FBI recruiting operations use PeopleSoft and AWS GovCloud. That does not establish that the alleged vulnerability existed, that those systems were exploited or that the claimed attack path was used in this incident.
The FBI’s latest statement specifically says it is working with third-party providers that support FBIJobs.gov. A compromise of a company supporting a government recruiting portal would not, by itself, demonstrate access to the Bureau’s broader investigative or operational networks.
Hackers Demand Retraction Of May FBI Warning
According to Nextgov/FCW, the group has demanded that the FBI retract or correct a May 15, 2026 warning about its tactics and gave the Bureau a one-week deadline. The warning, issued after attacks associated with ShinyHunters, described tactics including harassment, threatening messages and swatting.
The group has characterized its claimed FBI operation as retaliation for the warning rather than a financially motivated attack. The FBI has not indicated that it will comply with the demand.
For now, the confirmed picture is narrower: FBIJobs.gov and its applicant portal were disrupted, reporters examined a sample of about 5,000 alleged records and found information appearing to correspond to real people, and the FBI is investigating the source and scope of the claimed exposure.
The Bureau still has not said whether the alleged compromise occurred at a third-party provider supporting FBIJobs.gov or within the FBI’s own enterprise.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





