FBI hunts ShinyHunters after FBIJobs.gov breach of employee data
The FBI's cyber division publicly vowed to hunt down ShinyHunters after the group defaced FBIJobs.gov and claimed to steal sensitive employment records. Security teams should watch how the bureau determines whether a third-party vendor or internal system was the initial access point.
Beat this week
Last 7 days · Data Breaches
Impact 7.2/10 (-0.8 vs prior). Counts are stories in our record, not a market forecast.
Open the change reportCoverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 89 percentage points.
This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.
Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.
Cybersecurity briefing
Key takeaways
- The FBI's cyber division publicly vowed to hunt down ShinyHunters after the group defaced FBIJobs.gov and claimed to steal sensitive employment records.
- Security teams should watch how the bureau determines whether a third-party vendor or internal system was the initial access point.
- kacu.org
- iowapublicradio.org
In this briefing
Mentioned
Key Intelligence
Key Facts
- 1FBI Cyber Division Assistant Director Brett Leatherman publicly warned ShinyHunters in a video posted September 29, 2026: "You know how to find us, and we know how to find you."
- 2The breach involves FBIJobs.gov, which was defaced with a ShinyHunters message and temporarily taken offline late last week.
- 3FBI employees estimate the stolen data tranche could contain several terabytes of text files, including job applications, promotion details, sensitive postings, family details and medical records.
- 4Media organizations and threat intelligence researchers have already verified the authenticity of some of the stolen materials.
- 5The FBI is investigating whether hackers compromised third-party software or penetrated the bureau's own internal systems.
- 6Many current and former FBI employees first learned about the breach from media reports rather than from the bureau.
You know how to find us, and we know how to find you.
In a social media video posted September 29, 2026, warning ShinyHunters
Analysis
A breach at the FBI's own hiring portal raises one urgent question for security practitioners: did ShinyHunters exploit a third-party software dependency or compromise internal FBI infrastructure? If the data tranche really spans several terabytes of job applications, promotion records and medical details, it would represent a case study in how even high-security federal environments suffer from supply chain and data-exposure risks that defenders usually attribute to private-sector victims.
The FBI has publicly confirmed an aggressive investigation after cybercriminal group ShinyHunters claimed to have stolen sensitive data from FBIJobs.gov, the bureau's employment portal, and defaced the site. In a social media video posted Tuesday, September 29, 2026, FBI Cyber Division Assistant Director Brett Leatherman addressed the group directly, saying: "You know how to find us, and we know how to find you." His warning marked an unusual public escalation: a federal law enforcement agency openly vowing to hunt a specific cybercrime collective. The breach, which surfaced late last week after ShinyHunters posted a defacement message on FBIJobs.gov, has already forced the jobs website offline temporarily and created a national security concern because the exposed data potentially includes family details, medical information, promotion records and sensitive job postings for current and former FBI employees.
The FBI has publicly confirmed an aggressive investigation after cybercriminal group ShinyHunters claimed to have stolen sensitive data from FBIJobs.gov, the bureau's employment portal, and defaced the site.
Current and former FBI employees who spoke to NPR on condition of anonymity said many people first learned about the breach from media reports rather than from the bureau. They estimate the stolen tranche could contain as many as several terabytes of text files, including FBI job applications, details on promotions, information on sensitive job postings, family details and medical records. Media organizations and threat intelligence researchers have already verified the authenticity of some of the stolen materials, meaning this is not merely a hollow extortion claim. The scale and sensitivity of the data, if the employee estimates are accurate, would make this one of the most damaging known intrusions into a U.S. federal law enforcement systems in recent years.
The FBI is investigating how the hackers obtained the information, including whether they compromised third-party software or penetrated the FBI's own internal systems. A bureau spokesperson said the FBI is working "around the clock to investigate the cyber incident involving FBIJobs.gov and is in regular communication with anyone who may be impacted." That distinction matters: if the breach came through a third-party vendor or software supply chain, it would reflect a familiar and increasingly common attack path that federal agencies have struggled to secure. If attackers breached FBI internal systems directly, it would be far more serious and suggest a systemic failure inside the bureau's own security perimeter.
What to Watch
ShinyHunters is a prolific, loosely organized group of data extortionists known for breaching corporate and cloud systems, stealing databases and selling or leaking them. The FBI has pursued ShinyHunters operatives before, but the group's willingness to target the bureau itself is a high-profile escalation. Leatherman's public challenge, inviting group members to come forward while "the choice is still yours," is both a psychological pressure tactic and a signal that the FBI intends to prioritize identification and prosecution. His language also reflects the reality that attackers operating across international borders are difficult to arrest, but U.S. law enforcement has shown it can pursue cybercriminals over years with indictments, sanctions and coordinated international arrests.
The implications extend beyond the FBI. Current and former employees whose family details and medical information may be exposed now face heightened risks of identity theft, social engineering and potentially physical harassment. If the stolen files include identities of personnel assigned to sensitive postings, the breach could compromise operational security and counterintelligence efforts. The incident will likely accelerate federal scrutiny of third-party software used by law enforcement, increase funding demands for zero-trust architecture and prompt reviews of how agencies notify personnel after a breach. For the cybersecurity community, the case is a stark reminder that even the nation's top investigative agency cannot assume its own hiring infrastructure is immune from the same supply chain and extortion threats it warns the private sector about.
Timeline
Timeline
ShinyHunters defaces FBIJobs.gov
Late last week, ShinyHunters posts a defacement message on FBIJobs.gov claiming responsibility for stealing sensitive FBI employee data; the site is temporarily taken down.
FBI cyber chief issues public warning
Assistant Director Brett Leatherman posts a video directly addressing ShinyHunters, vowing to find group members and urging them to come forward while the choice remains theirs.
FBI confirms aggressive investigation
An FBI spokesperson tells NPR the bureau is working around the clock to investigate the FBIJobs.gov cyber incident and is in regular communication with potentially impacted individuals.
Source cluster
Primary reporting
- iowapublicradio.orgFBI hunting the hackers who stole its employee sensitive data
Cite This Page
"FBI hunts ShinyHunters after FBIJobs.gov breach of employee data." Cyber Intelligence Brief, September 30, 2026. https://getcyberbrief.com/story/fbi-shinyhunters-fbijobs-breach-employee-data
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |