
The Federal Bureau of Investigation is investigating a cyberattack involving its recruitment portal, FBIJobs.gov, after the cybercriminal group ShinyHunters claimed it compromised the site and obtained personal information linked to FBI employees and job applicants.
In a statement issued on September 23, the FBI said it was aware of a cybercriminal enterprise group claiming a compromise of the FBIJobs.gov portal and an alleged impact to FBI employee personally identifiable information.
The bureau said the point of the breach had not yet been determined and that investigators were working with third-party providers supporting FBIJobs.gov to address the incident.
The FBIJobs.gov website was taken offline following the incident. The Record reported that ShinyHunters had defaced the recruitment website by replacing agency imagery with an image of a Pokémon character associated with the group.
ShinyHunters said it had breached the FBI and stolen data belonging to a large number of current and former employees. The group also said it was holding the information while demanding that the bureau withdraw a statement it issued about ShinyHunters in May.
A sample of the information was provided to journalists. Reuters reviewed a 5,000-line spreadsheet containing names, addresses, telephone numbers, dates of birth, Social Security numbers and emergency-contact information for people identified as FBI employees.
The spreadsheet also contained information about assignments to particular field offices and units associated with intelligence, security, counterespionage, surveillance and other sensitive work, according to Reuters.
Reuters reported that the material included 14 staffers identified with China-related assignments, including a China criminal enterprise unit, China technology-transfer analysis unit and China intelligence section.
Nine people were listed in Russia-related roles, including two in the Russia Operations Section and another working on Russia critical infrastructure and technology threats.
Three people were listed in Iran- or Hezbollah-focused intelligence roles.
The information also identified 18 people associated with data intercept or telecommunications intercept technologies, clandestine technical operations, covert access, and video, audio or electronic surveillance.
Another 11 FBI staffers were listed in human intelligence, or HUMINT, positions, including personnel identified as working in the Human Intelligence Program Management Section.
The inclusion of emergency-contact information could extend the exposure beyond employees themselves. Reuters cited former FBI officials and cybersecurity specialists who said information about spouses, children and other contacts can create additional risks for people connected to personnel working in sensitive roles.
The recruitment system has historically handled substantial amounts of personal information.
A 2022 FBI Privacy Impact Assessment for FBIJobs.gov and FBI Candidate Gateway says the system supports recruiting, hiring, job applications and staff review processes.
The assessment says candidates can use the system over the internet to research FBI employment, submit applications and receive communications about employment. It also says the system integrates with FBI human resources systems, including HR Source, which resides on the bureau’s secure network.
The same assessment states that the system was hosted on Amazon Web Services Government Cloud and used Oracle PeopleSoft HRS 9.2, Oracle Database 19c and Drupal.
The FBIJobs.gov public website itself was described in the assessment as a source of general employment information, while the Candidate Gateway handled job application submissions.
The assessment says the Candidate Gateway could contain sensitive but unclassified personal information from applicants, including names, Social Security numbers, dates of birth, veterans-preference eligibility, gender and citizenship.
The document also identifies additional categories of information maintained by the recruiting system, including addresses, personal email addresses, telephone numbers, education information, military status, employment history and other applicant information.
The FBI has not publicly established that the current incident compromised the bureau’s wider internal network. Its September 23 statement says investigators are still determining whether the point of breach was a third-party environment or the FBI’s enterprise.
The incident follows a separate campaign earlier in 2026 involving Oracle PeopleSoft infrastructure.
Google’s Mandiant and Google Threat Intelligence Group reported in June that ShinyHunters, tracked by them as UNC6240, had been conducting an active compromise and extortion campaign against organisations using Oracle PeopleSoft.
The activity was observed from May 27 through June 9 and involved exploitation of CVE-2026-35273, a critical remote-code-execution vulnerability affecting Oracle PeopleSoft PeopleTools.
Oracle’s security advisory rates the vulnerability at 9.8 under CVSS 3.1 and says it can be exploited remotely without authentication. The affected supported versions listed by Oracle are PeopleTools 8.61 and 8.62.
Google said it notified more than 100 organisations whose infrastructure appeared potentially exposed during the campaign. The company said 68% of those organisations were in higher education.
The current FBI incident has also involved claims from ShinyHunters about the method used to gain access. The group has described a new PeopleSoft vulnerability and said it used that vulnerability to reach FBI systems.
Reports by BleepingComputer said the group claimed it obtained remote code execution and moved into FBI-managed infrastructure, but the FBI has not publicly described the technical intrusion in those terms.
The group has also made claims about the amount of information it obtained. Reuters reported that the 5,000-line spreadsheet was described by the hackers as a small portion of a larger collection.
The immediate focus remains the FBI’s investigation into the FBIJobs.gov environment and the personal information associated with employees and applicants.
The FBI said it is working with the third-party providers that support the recruitment portal as investigators determine how the intrusion occurred and what information may have been affected.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



