FBI Hack Exposed Agents’ Home Addresses And Family Details: 5,000 Records Shared as ‘Proof’

The attackers defaced the official FBI jobs portal with a mock seizure notice and dismissed monetary ransom, opting instead for what they termed coercion

FBI Cyber Breach Investigation
Hackers from the infamous ShinyHunters group claim to have stolen sensitive personal data on every FBI employee and applicant Gemini

A hacking group claims it breached several FBI-related systems and stole records relating to all FBI employees and applicants.

Speaking to 404 Media, a member of ShinyHunters said the allegedly stolen files feature personal details such as agents' home addresses, names, phone numbers and information about their spouses.

National Security and Counterintelligence Risks

If the hackers' claims are accurate, the alleged data exposure could have significant national security and counterintelligence implications. 404 Media reported that criminals from the same ecosystem as ShinyHunters have previously used hacked data, such as phone records, to track, intimidate and harass FBI agents investigating them.

The publication also reported that the information could be valuable to foreign intelligence agencies seeking to better understand the FBI's operations.

If the information were to spread more widely among criminals, FBI employees and their spouses could also face serious safety and privacy risks.

'We hacked the FBI. We hold data on all FBI employees and applicants,' a spokesperson stated to the publication.

Verification And Defacement Of Recruitment Portals

To back up their claims, the spokesperson provided 404 Media with a sample containing records for 5,000 alleged FBI employees. The documents included home addresses, phone numbers, dates of birth and, in some cases, information about employees' spouses.

The publication cross-checked several phone numbers using the OSINT Industries platform and found matches between the numbers and names in the sample. Investigators also ran records through the DARKSIDE database operated by District 4 Labs, which uncovered connections between select numbers and U.S. Department of Justice staff. District 4 Labs describes DARKSIDE as a repository of compromised records and person-of-interest data.

The hacking group also defaced the FBI's recruitment portal earlier in the week, leaving a mock seizure banner designed to resemble a law enforcement takedown notice. According to the spokesperson, the intrusion took place on Monday evening. At the time of 404 Media's report, the landing page displayed the message: 'Apply.fbijobs.gov and the Special Agent Applicant Portal are currently unavailable.'

The altered page further warned, 'All FBI data was compromised, including PII/PHI [personally identifiable information and protected health information] on incumbent and former FBI employees and all applicant information. We have a lot more than we claim here.'

The message also included the line: 'Thank you for your attention to this matter.'

An agency spokesperson shared via email that 'The FBI is aware of claims regarding unauthorised activity affecting FBIjobs.gov and is currently investigating.'

Zero-Day Exploit And Coercion Demands

The ShinyHunters spokesperson claimed that the group exploited a zero-day flaw in Oracle PeopleSoft to breach AWS GovCloud servers and exfiltrate between two and three terabytes of data.

The PeopleSoft zero-day element is consistent with separate threat intelligence reporting from Mandiant and Google Threat Intelligence Group, which documented ShinyHunters exploiting a critical Oracle PeopleSoft vulnerability, CVE-2026-35273, in attacks earlier in 2026. However, that reporting does not independently establish that the alleged FBI intrusion used the same vulnerability.

While the collective typically extorts targets by threatening leaks unless paid, a representative noted regarding the bureau, 'what we plan to do is not something I'd call extortion, maybe coercion,' adding, 'This is not financially motivated.'

On its leak portal, ShinyHunters accused the bureau of making 'false allegations' in a prior report—which stated the group exaggerates claims, sends threatening texts or calls to victims' families, and orchestrates swatting—and warned, 'allowing you [the FBI] a time of 1 week to correct' or retract the publication.