In an era when the keepers of secrets find themselves increasingly vulnerable to those who traffic in exposure, the FBI's employment portal has been taken offline following a breach by ShinyHunters — a group claiming to hold two to three terabytes of sensitive personnel and operational data. The incident is not merely a technical failure but a confrontation between institutional authority and those who seek to redefine the terms of their own reputation, as the hackers demand the bureau publicly retract its characterization of them as threat actors. For thousands of current and former FBI emplo
FBI Probes Alleged Theft of Employee Data in Jobs Portal Breach
Thousands of FBI employees now have their operational details exposed
So ShinyHunters is saying they have two to three terabytes of FBI employee data. How much is that, really?
It's a massive amount—enough to hold detailed records on thousands of people, including their job assignments and what operations they work on. Reuters saw samples and confirmed the data is real and sensitive.
But we should note: ShinyHunters is claiming the size. The FBI hasn't independently verified that number yet. We know the breach happened; we know some data was stolen. The exact volume is still the hackers' claim.
And they're demanding the FBI take back something it said in May?
Yes. The FBI called them threat actors who bluff about having information they don't actually possess. ShinyHunters wants that statement rescinded.
Which is interesting because it suggests they're worried about their credibility. If they really have what they say they have, why does the FBI's characterization matter?
Fair point. So what's the actual damage here—to the employees, I mean?
Thousands of current and former FBI employees now have their personal information and operational details exposed. If you work counterintelligence against China or Russia, your assignment is now potentially known to hostile actors.
We should be careful here too. We know the data was stolen. We know it includes job assignments and operational references. But we don't yet know how much of it has actually circulated beyond the hackers and the journalists who saw samples.
The FBI said the breach point is still undetermined—could be their system or a vendor's?
Right. They're investigating both possibilities. That's actually a significant unknown because it changes how to fix this.
And it matters for future prevention. If it's a vendor, other agencies might be vulnerable too.
Le Pouls
- ShinyHunters claims to have seized 2–3 terabytes of FBI personnel data — including operational details about investigations into Chinese and Russian intelligence services and drug trafficking networks — from the fbijobs.gov portal.
- The FBI took its jobs portal offline Wednesday and confirmed the breach in a terse statement, while the full origin of the vulnerability — whether internal or through a third-party vendor — remains unresolved.
- The hackers have attached an unusual political condition to their silence: the FBI must publicly rescind a May statement branding ShinyHunters as extortionists prone to harassment, raising the stakes beyond data theft into a battle over institutional narrative.
- News outlets including Reuters reviewed samples of the stolen data and confirmed it contains genuinely sensitive operational detail, lending credibility to the hackers' claims and deepening the severity of the exposure.
- This breach follows a troubling pattern: a March compromise of an internal FBI surveillance system and a pro-Iranian group's claimed hack of Director Kash Patel's personal account signal that the bureau is facing sustained, multi-front digital pressure.
In an era when the keepers of secrets find themselves increasingly vulnerable to those who traffic in exposure, the FBI's employment portal has been taken offline following a breach by ShinyHunters — a group claiming to hold two to three terabytes of sensitive personnel and operational data. The incident is not merely a technical failure but a confrontation between institutional authority and those who seek to redefine the terms of their own reputation, as the hackers demand the bureau publicly retract its characterization of them as threat actors. For thousands of current and former FBI employees, the abstract risks of the digital age have become suddenly, personally concrete.
The FBI's jobs portal went dark Wednesday after the agency confirmed a breach by ShinyHunters, a hacking group claiming to have stolen between two and three terabytes of sensitive data on thousands of current and former employees. The stolen material reportedly includes personnel assignments and operational details tied to investigations of Chinese and Russian intelligence services, drug trafficking organizations, and other sensitive targets.
The FBI acknowledged the compromise in measured language, saying it was actively investigating while working with the third-party vendors who support the site. Whether the vulnerability originated inside the bureau or with an external provider remains an open question — one with significant implications for how the damage is ultimately understood and contained.
ShinyHunters announced the theft on Tuesday and immediately issued a demand: the FBI must retract a statement it published in May characterizing the group as threat actors who routinely bluff, harass, and extort. By Wednesday, the hackers were also claiming to be working to prevent the stolen data from spreading further — a posture that blends leverage with an odd performance of restraint.
Reporters at Reuters reviewed samples of the data and confirmed its sensitivity, lending weight to the hackers' claims. The breach arrives against a backdrop of mounting pressure on the bureau: in March, the FBI disclosed suspicious activity on an internal system tied to surveillance operations, and a pro-Iranian group claimed to have accessed FBI Director Kash Patel's personal account, releasing old photographs and personal documents. The jobs portal remained offline Wednesday with no restoration timeline announced.
The FBI's jobs portal went dark on Wednesday afternoon, taken offline in response to what the agency now confirms was a breach by ShinyHunters, a hacking group claiming to have stolen sensitive data on thousands of current and former employees. The stolen material—somewhere between two and three terabytes, according to the hackers—includes granular details about FBI personnel assignments, operational work against Chinese intelligence services, Russian spy agencies, drug trafficking organizations, and other targets the bureau considers sensitive.
The FBI acknowledged the compromise in a terse statement, saying it was "aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information." The agency added that it was "actively and aggressively investigating" the breach while working with third-party vendors who support the jobs site. What remains unclear is whether the vulnerability originated within the FBI's own systems or with one of those external providers.
ShinyHunters announced the theft on Tuesday and immediately attached a condition to its silence: the FBI must rescind a statement the bureau issued in May that characterized the group as threat actors prone to harassment and extortion. In that earlier statement, the FBI described ShinyHunters' typical playbook—claiming access to sensitive information, threatening to release embarrassing photographs or videos, often bluffing about material that does not actually exist. The group's demand suggests it wants the FBI to publicly walk back that characterization, though by Wednesday the hackers were also saying they were working to prevent the stolen personnel information from spreading more widely across the internet.
News outlets including Reuters obtained samples of the data and confirmed it contained the kind of operational detail that would be genuinely damaging if exposed: job titles, assignments, and references to sensitive investigative work. The scope of the breach—affecting thousands of employees—makes this one of the more serious compromises the FBI has suffered in recent memory.
This breach arrives amid a pattern of successful attacks on the bureau. In March, the FBI disclosed it was investigating suspicious activity on an internal system holding sensitive information about surveillance operations and ongoing investigations. That same month, a pro-Iranian hacking group claimed to have compromised an account belonging to FBI Director Kash Patel, posting what appeared to be years-old photographs of him along with his resume and personal documents spanning more than a decade. The jobs portal remained offline as of Wednesday afternoon, with no timeline announced for restoration.
Citations marquantes
The FBI is aware of a cybercriminal enterprise group claiming a compromise of the fbijobs.gov portal and alleged impact to FBI employee personally identifiable information.— FBI statement
ShinyHunters may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.— FBI May 2026 statement on ShinyHunters