FBI reportedly declares ‘cyber security incident’ after hackers steal agents’ personal data
The Federal Bureau of Investigation has reportedly told its agents and support staff that their personal information was stolen in a recent cyberattack that targeted the bureau’s job application portal.
It’s the bureau’s first acknowledgement that the personal information of FBI agents was taken in the breach. The FBI has not publicly confirmed a breach beyond a statement last week, in which it said it was aware that a hacking group had claimed a cyberattack, but that the theft of data was “still undetermined.”
As reported by MS NOW reporter Ken Dilanian over the weekend, the FBI has since declared a “cyber security incident” in an internal notification to staff, telling employees that their names, addresses, job titles, and their Social Security numbers were exposed.
New: The FBI told employees in an internal notification that it has declared a “cyber security incident” related to the hack of the https://t.co/l4iJxC0jA2 portal. Personally identifiable information of FBI employees, including social security numbers, addresses and job titles,…
— Ken Dilanian (@KDilanianMSNOW) September 26, 2026
Several media outlets have since confirmed that some of the stolen data included medical information, such as records relating to blood and urine samples, as well as psychiatric reports.
The hacking group called ShinyHunters previously told TechCrunch that they “have data on mostly all of FBI,” and a “substantial” amount of information on applicants who applied through the FBIJobs.gov portal. The hackers broke in by exploiting a vulnerability in an Oracle PeopleSoft server, which hosts reams of human resources information on agents and now-employees who applied through the portal.
The hackers told TechCrunch that they are not seeking a financial ransom, but are demanding the correction of an earlier FBI-issued report, which they say misrepresents their activities.
Justin Sherman, a national security expert, called the data breach a “counterintelligence disaster” for the U.S. government in a blog post for Lawfare. He warned that the data theft would “expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more.”
While the bureau has notified employees, it’s less clear if the FBI has disclosed the incident to lawmakers in Congress who have oversight of the FBI. Under federal law, alerting Congress is required when an intrusion meets the bar of a “major incident” — such as if a data breach involves the theft of personally identifiable information that is “likely to result in demonstrable harm” to U.S. national security.
It’s likely that bureau lawyers are trying to figure that out right now. If a disclosure is required, it would be the FBI’s second known notification to lawmakers this year about a data breach, after hackers, suspected to be Chinese, broke into a surveillance system that exposed targets of FBI surveillance and investigations earlier this year.
A spokesperson for the FBI did not respond to TechCrunch’s request for comment on Monday, and a White House spokesperson also did not respond to an email asking if the bureau had declared a major incident.
Representatives for several lawmakers whose jurisdictions cover oversight of the FBI did not have any immediate answers.
ABC News reports that the FBI’s job site has been the primary way to apply for a job with the bureau since 2017. The portal remains down at the time of publication.
Do you work at the FBI and have received a notice about the data breach? We want to hear from you. You can contact this reporter securely on Signal at zackwhittaker.1337, or reach him by email at zack.whittaker@techcrunch.com.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.
Comments 0
Leave a Reply
Your email address will not be published. Required fields are marked *
Technology
Explore All
Can a chatbot fix the government maze? The White House is about to find out
America.gov is intended to simplify the process of navigating government bureaucracy, but language models are imperfect and remain prone to hallucinat...
Instinct founder said more than 50% of transactions on the platform are travel-related
2 hours ago
After losing his voice to cancer, this founder is building “glasses for voice”
2 hours ago
Oura shelves its $2.2B IPO citing ‘uncertainty’ in the market
2 hours agoWith Dazzle, Marissa Mayer bets your camera roll has more info on your life than your inbox
3 hours agoWhats New
View All
Berlanti Productions Promotes Liam Driscoll to Creative Executive (EXCLUSIVE)
Graham Norton Shoots Down ‘Conspiracy Theory’ That Taylor Swift’s ‘Opalite’ Video Was Shot Before She Came on His Show
Can a chatbot fix the government maze? The White House is about to find out
Beyond Fest Organizers on Improved Ticketing, Fans ‘As Unhinged as We Are’ and Their 7 Titles Not to Miss
‘Love Hypothesis’ Sequel in the Works at Amazon MGM and MRC, Based on Author Ali Hazelwood’s New Book ‘The Two-Body Problem’
Trump unveils America.gov as AI-powered hub for passports, Medicare enrollment and more
Disney Makes More Job Cuts, Laying Off a Few Hundred Employees
Man City guilty of all serious financial breach charges: Premier League
Drug cartel kingpin among targets in sweeping Trump crackdown on alleged Mexican corruption network