The FBI confirmed Wednesday that it is looking into claims by a criminal hacking outfit that it accessed highly sensitive personnel records and compromised the bureau's online recruitment portal. The group, known as ShinyHunters, said it obtained personal details on thousands of current agents and job applicants, and that it broke into FBIJobs.gov, the primary site for prospective hires.

In a statement, the FBI acknowledged the alleged intrusion, saying it was aware of a cybercriminal enterprise claiming a compromise of the portal and potential exposure of personally identifiable information. The bureau noted that the exact entry point had not yet been confirmed, but emphasized that investigators are working aggressively with third-party vendors that support the site to assess and reduce risks. As of Wednesday afternoon, the recruitment website remained offline.

Read also
Defense
Ecuador's cartel crackdown makes it a prime candidate for major non-NATO ally status
Ecuador has emerged as a key U.S. partner in counter-narcotics, prompting calls to designate it a major non-NATO ally. The move would deepen military cooperation and reward Quito's alignment.

ShinyHunters, in a message circulated online, claimed responsibility and addressed FBI Director Kash Patel and Brett Leatherman, the assistant director in charge of the bureau's cyber division. The group asserted that it holds "very sensitive data" on nearly all FBI agents and individuals who have applied for positions. The authenticity of the claims could not be independently verified, and an email to an address associated with the group went unanswered.

The hackers said their actions were in retaliation for an FBI advisory issued in May that labeled ShinyHunters a "cyber criminal group specializing in large-scale data breaches and extortion." That advisory described the group as threat actors who often use real or exaggerated claims of access to sensitive information to pressure victims into paying, and who may resort to harassment or false claims. ShinyHunters demanded the FBI retract those characterizations within a week, though it did not specify consequences if the bureau failed to comply. The group insisted its actions were not financially motivated, stating, "This is not a ransom, coercion, or extortion."

Cybersecurity experts say the breach, if confirmed, could have serious national security implications. Miriam Wugmeister, a lawyer specializing in data privacy and cybercrime, noted that ShinyHunters has a track record of following through on such claims, making it likely that the group did compromise the site and obtain data. She highlighted the risk of exposing agents and their families to extortion, swatting, and other harassment, particularly because the stolen information reportedly includes spouses' details. "Even if the agents and the analysts and the employees are sophisticated, you worry about their families too," she said.

ShinyHunters has a reputation for causing disruption, as seen in its involvement in a spring breach of Canvas, a widely used online learning system. That incident caused chaos for students and prompted the FBI advisory that the group now objects to. The current hack was first reported by 404 Media, which said a ShinyHunters representative shared a sample of data on 5,000 FBI employees, including addresses, phone numbers, and some spouse information. The group indicated it exploited a vulnerability in Oracle PeopleSoft software, commonly used by government agencies for human resources and data processing.

The FBI has not determined whether the breach originated with a third-party vendor or its own enterprise systems. This incident is the latest in a series of cyberattacks targeting the bureau. In March, the FBI disclosed it was investigating suspicious activity on an internal system containing sensitive surveillance and investigative data. Also that month, a pro-Iranian hacking group claimed to have accessed an account of Director Patel, posting old photographs, a resume, and personal documents. The FBI described that compromise as involving historical information with no government data.

Given the sensitive nature of the data allegedly stolen, the investigation is a top priority. The bureau is coordinating with its technology partners and federal cyber authorities to contain any fallout and determine the full scope of the breach. For now, the recruitment site remains down, and prospective applicants are advised to monitor official channels for updates. This incident also raises broader questions about the security of federal hiring systems and the increasing boldness of cybercriminal groups targeting government infrastructure.