Skip to content

FBI says ShinyHunters breach may have exposed staff data

newsSep 28, 202649366

In an internal memo, the F.B.I. said it believes the hacker group ShinyHunters may have stolen sensitive information on all of its employees after a breach of the agency’s careers portal. The bureau declared a major cybersecurity incident and judged the intrusion likely to result in demonstrable harm to U.S. national security. ShinyHunters claimed responsibility and told 404 Media it never intended to publish the data, after earlier giving the F.B.I. a one-week countdown; the group also framed the intrusion as a “marketing campaign” in other comments. Reporting by Reuters and others says the haul may include addresses, details on spouses, and psychiatric and medical records, and that the group reportedly exfiltrated over 2 terabytes of files. Dutch authorities arrested a person identified as a ShinyHunters member in the Netherlands, and cybersecurity firm Mandiant warned the group has worked around Oracle mitigations for the exploited vulnerability. The bureau’s assessment about possible exposure of every employee has prompted internal alarm about staff safety and counterintelligence risks and is likely to drive expanded federal incident response and protective measures for affected personnel.

Dustin Volz
@dustinvolz.bsky.social

New: FBI in internal memo says it believes ShinyHunters may have stolen private data on all employees. Fears of longterm consequences of breach magnify as hackers threaten to leak everything online by end of Tuesday. www.nytimes.com/2026/09/28/u...

1593h ago
1 source