ShinyHunters breach FBI jobs portal, agents' data stolen
The FBI confirmed a cyber security incident after ShinyHunters exploited an Oracle PeopleSoft flaw behind FBIJobs.gov, exposing employee Social Security numbers.
By Mira Castell · Published · Updated · 7 min read

The FBI has told its agents and support staff that their personal information was stolen in an attack on FBIJobs.gov, the bureau's job application portal — one of the most embarrassing breaches of a US law enforcement agency in years.
What happened
The extortion group ShinyHunters claimed the attack last week and defaced the jobs site, which was briefly taken offline. The group told TechCrunch it broke in through a vulnerability in an Oracle PeopleSoft server that holds human resources data on employees and applicants.
In an internal notice, the FBI declared a "cyber security incident" and said names, home addresses, job titles and Social Security numbers were exposed. Several outlets have confirmed that some stolen files include medical records, such as drug test results and psychiatric reports — data collected during the bureau's vetting process for applicants and staff.
The portal is used by thousands of people who apply for jobs at the bureau each year, meaning the stolen data likely covers not just serving agents but applicants who were never hired, along with support and administrative staff.
The FBI's response
The assistant director of the FBI's cyber division, Brett Leatherman, posted a video warning the group: "You know how to find us, and we know how to find you," NPR reported. The bureau says it is still working out whether attackers got in through third-party software or its own systems, and has not said how many people are affected.
The defacement of a federal recruitment site, combined with the theft of agent data, makes this a rare double humiliation for the bureau — and an unusually public one, since ShinyHunters announced the breach itself rather than negotiating quietly.
Who is ShinyHunters?
ShinyHunters is a loose, English-speaking extortion network that has been active since 2020 and is linked to some of the largest data thefts on record. Security researchers have connected the name to breaches at Ticketmaster, AT&T, Santander and PowerSchool, among many others. More recently, overlapping groups have been tied to the wave of Salesforce data thefts that hit dozens of major companies through compromised third-party integrations.
The group's method is consistent: find a way into a system holding large volumes of personal data, steal it quietly, then demand payment under threat of publication. Members are typically young, financially motivated and spread across several countries, which makes prosecution slow even when suspects are identified. Dutch police arrested a suspected member earlier this year, but the network has continued operating.
The PeopleSoft problem
Oracle PeopleSoft is a human resources platform widely used by governments and large employers. It is also exactly the kind of system attackers love: old, heavily customized, often reachable from the internet, and packed with the most sensitive records an organization holds — identity documents, background checks, medical files and payroll data.
HR systems tend to lag behind on patching because they are business-critical and awkward to take offline. That combination of sensitive data and slow maintenance has made them a repeat target, from the 2015 US Office of Personnel Management breach — which exposed more than 20 million federal records — to this incident.
Why it matters
Leaked details about federal law enforcement staff create real safety risks. Doxxing, swatting and targeted phishing against agents and their families are all realistic follow-ons, and the exposure of medical and vetting records adds a blackmail dimension that ordinary breaches do not carry.
For everyone else, the lesson is simpler: if the FBI's recruitment portal can be raided through an unpatched HR system, so can your employer's. The breach is a reminder that the weakest point in many organizations is not the perimeter but the aging business software just inside it.
What affected applicants and staff should do
- Watch for phishing emails or calls referencing an FBI application — criminals routinely follow up breaches with targeted scams.
- Place a fraud alert or credit freeze with the major credit bureaus if your Social Security number was exposed.
- Be skeptical of any message claiming to be the FBI asking for more personal information; the bureau will not do that by email.
Lessons for organizations
- Patch internet-facing business software such as PeopleSoft quickly and remove versions that are no longer supported.
- Keep HR and applicant data separate from other systems and encrypt it at rest.
- Monitor for large, unusual data exports from HR platforms.
- Assume applicant data is as sensitive as employee data — it usually contains the same identity documents with none of the same protections.



