The FBI Breach: What’s Confirmed and What’s Only Claimed

SPECIAL REPORT

This story is developing. Details are current as of Sept. 30, 2026.

On Tuesday, the head of the FBI’s Cyber Division recorded a message for the people who say they robbed his bureau. “You know how to find us, and we know how to find you,” Assistant Director Brett Leatherman said in a video addressed to members of ShinyHunters, according to Nextgov/FCW. He urged them to come forward “while the choice is still yours.”

A week earlier, ShinyHunters, an extortion group, had claimed it broke into FBIJobs.gov, the bureau’s hiring portal, and walked off with personnel files. What the FBI has not said, a week later, is how much was taken or whose files it was. That gap matters. The last time the government lost applicant files at this scale, in the 2015 breach at the Office of Personnel Management, the full reckoning took Congress more than a year.

What the FBI has confirmed

The bureau’s first statement, reported by Cybersecurity Dive on Sept. 23, said the FBI was aware of a criminal group claiming to have compromised FBIJobs.gov, with alleged impact to employees’ personal information. The FBI said the point of breach was still undetermined. It could be a vulnerability at a third-party provider or a weakness in the FBI’s own systems. The bureau has since said it is working “around the clock” on the investigation, and that it sent bureau-wide communications within 24 hours of the first public reports, NPR reported on Sept. 30.

Beyond that, the official record is thin. The FBI has not published a count of affected people, a list of compromised systems or a timeline for notifying them. Current and former employees told NPR that the stolen material includes job applications, promotion details, family information and medical data. That account comes from those employees, not from the bureau, and we have not been able to confirm it independently.

The strongest outside check so far comes from 404 Media. ShinyHunters gave journalists a sample of roughly 5,000 records, which included names, home addresses, phone numbers and family details, Nextgov/FCW reported. 404 Media verified parts of that sample, according to Cybersecurity Dive. That suggests the sample is at least partly genuine. It says nothing about the size of the rest.

What only ShinyHunters has claimed

Everything about the breach’s scale currently rests on the group’s own word. ShinyHunters says it took between 2 and 3 terabytes. It says the haul covers “almost ALL FBI Agents” and everyone who applied for an FBI job. It also says it reached human-resources, criminal-justice and “Medlink” medical systems, as reported by The Hacker News and Nextgov/FCW. None of those figures has been confirmed by the FBI or by any outlet that has examined the full dataset.

The group says it got in through a previously unknown flaw in Oracle’s PeopleSoft software. Oracle has not published an advisory for any such flaw and declined to comment to Cybersecurity Dive. In June, Oracle disclosed a separate PeopleSoft flaw, CVE-2026-35273, after ShinyHunters had already exploited it against other targets. Researchers at Vectra AI, drawing on a Sept. 25 Mandiant report and on 404 Media’s reporting, have written that the attackers used the June flaw and slipped past the firewall rules meant to block it with a one-character change to the web request. Neither the FBI nor Oracle has said which account is correct.

ShinyHunters has also offered a motive. It wants the FBI to retract a public service announcement the bureau issued on May 15. That notice, published on the FBI’s Internet Crime Complaint Center site, warned that the group’s members harass victims and their families with threatening calls and texts and have in some cases resorted to swatting. In a Sept. 23 statement on its leak site, reported by Malwarebytes, the group framed the breach as a response to that notice and insisted its “threats and claims are very real.” The FBI has not responded publicly to the demand.

An arrest in Amsterdam

Dutch police arrested a 24-year-old Amsterdam man on Sept. 15 and announced the arrest on Sept. 29, CBS News reported. He is suspected of membership in ShinyHunters and of attempting to incite two murders. A court has ordered him held for at least 90 days, according to the Associated Press. FBI Director Kash Patel described him as “one of the alleged leaders,” CBS reported. Dutch authorities have described him as a suspected member, and published reports do not say he is accused of carrying out the FBI breach himself. ShinyHunters told The Hacker News it has no connection to him.

The 2015 record Congress already wrote

The government has been here before, and it left a paper trail. In 2015, the Office of Personnel Management disclosed that intruders had taken background-investigation records on 21.5 million people, personnel records on 4.2 million, and fingerprints of 5.6 million. The House Oversight and Government Reform Committee spent a year investigating. Its staff report, released Sept. 7, 2016, concluded bluntly: “The OPM data breach was preventable.”

The committee found that OPM’s leadership had “failed to heed repeated recommendations from its Inspector General” and had misled the public about the extent of the damage. The report came more than a year after the first disclosure. It is the closest thing the public has to a model for what an accounting of the FBI breach should eventually contain. That means which systems were exposed, whose records were in them and whether the warnings came in time.

The two cases differ in important ways. The OPM records covered much of the federal workforce. The FBI data, on the group’s own telling, covers one agency and its applicants. But the kind of file at issue overlaps. Justin Sherman, writing for Lawfare on Sept. 25, argued that personal data on FBI personnel in a hacking group’s hands “would expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more.” That is an analyst’s assessment of the risk, not a finding about what has been taken.

For now, the public knows three things for certain. Someone got into the FBI’s hiring portal. A sample of real employee data is circulating. The bureau is hunting the people responsible. How much else left the building is, as of this writing, known only to the people who took it and, perhaps, to the FBI.


The FBI confirms a breach of its hiring portal but not its scale. What’s confirmed, what only ShinyHunters claims, and what the 2015 OPM breach taught.

Sources: Nextgov/FCW, Sept. 29, 2026; Nextgov/FCW, Sept. 2026; NPR, Sept. 30, 2026; Cybersecurity Dive, Sept. 23, 2026; The Hacker News, Sept. 2026; The Hacker News, Dutch arrest; Vectra AI, Sept. 28, 2026; Malwarebytes; CBS News, Sept. 29, 2026; Associated Press; FBI Internet Crime Complaint Center, PSA, May 15, 2026; Lawfare, Justin Sherman, Sept. 25, 2026; House Oversight and Government Reform Committee, OPM report release, Sept. 7, 2016; House Oversight staff report, “The OPM Data Breach” (PDF).

Filed under: Federal Bureau of Investigation

Leave a Reply