deniz.in

Markets

Weather

Loading weather

· via TechCrunch

FBI confirms agents' personal data stolen in breach of its job application portal

The FBI has told employees that names, addresses, job titles and Social Security numbers were stolen in the FBIJobs.gov portal breach, which reportedly traces back to an Oracle PeopleSoft flaw.

FBI confirms agents' personal data stolen in breach of its job application portal

FBI tells staff that hackers took their data

The FBI has told its agents and support staff that hackers stole their personal information in a recent attack on the bureau's job application portal, according to TechCrunch. The disclosure came in an internal notification, first reported by MS NOW journalist Ken Dilanian over the weekend, in which the bureau declared a "cyber security incident" — its first acknowledgement that agents' personal data was actually taken.

According to the report, the exposed data includes employees' names, home addresses, job titles and Social Security numbers. Until now, the FBI had publicly said only that it was aware of a hacking group's claim of an attack, and that whether any data had actually been taken was "still undetermined."

Medical records are part of the haul

Outlets covering the story have since confirmed that medical information forms part of the stolen material, including records relating to blood and urine samples and to psychiatric evaluations.

An Oracle PeopleSoft flaw as the way in

The group behind the intrusion, ShinyHunters, previously told TechCrunch it holds data on "mostly all of FBI," along with a "substantial" amount of information on people who applied through the FBIJobs.gov portal. The group says it gained access through a flaw in an Oracle PeopleSoft server holding human resources records on agents and on staff who were hired after applying through the site.

ABC News reports that the job portal has been the main route for applying to work at the bureau since 2017. It was still offline at the time of TechCrunch's reporting.

Hackers want a report corrected, not a payment

In an unusual twist for a breach of this scale, ShinyHunters told TechCrunch they are not seeking a financial ransom. Instead, they are pressing the FBI to change an earlier report that they argue paints an inaccurate picture of their activities.

Congressional notification is still an open question

Under US federal law, agencies must alert Congress when an intrusion meets the bar of a "major incident" — a threshold that can include cases where stolen personally identifiable information is "likely to result in demonstrable harm" to national security. TechCrunch reports that it remains unclear whether the FBI has made such a disclosure, and that bureau lawyers are presumably working through that question now.

If a disclosure is required, it would be the FBI's second known breach notification to lawmakers this year. Earlier in 2026, intruders believed to be linked to China compromised a surveillance system and exposed who the bureau was watching and investigating.

An FBI spokesperson did not respond to a request for comment, and the White House likewise had no answer on whether a major incident had been declared. Representatives of lawmakers with oversight of the FBI offered no immediate answers either.

Why it matters

Justin Sherman, a national security expert, called the breach a "counterintelligence disaster" in a post for Lawfare, warning that the data will "expose thousands of FBI personnel to profiling, phishing, foreign intelligence approaches, and much more." A list of named individuals matched to their roles, addresses, Social Security numbers and sensitive medical histories is precisely the raw material foreign intelligence services use to target, coerce or impersonate government staff.

The incident also shows the blast radius of long-lived HR platforms: one vulnerability in an Oracle PeopleSoft server appears to have exposed applicant records going back to 2017, and the portal has yet to return to service.

  • #security
  • #data-breach
  • #fbi
  • #oracle-peoplesoft
  • #cybercrime

Related posts