Monday, September 28, 2026
Tech Beat
Sep 28, 2026, 2:50 PMCybersecurity

FBI Agents’ Social Security and Medical Data Stolen in Jobs Portal Hack

FBI staff names, addresses, Social Security numbers and medical records were stolen through FBIJobs.gov, prompting an internal cybersecurity incident alert.

Listen to this briefingAudio briefing

Summary

On September 26, 2026, the FBI reportedly declared a cybersecurity incident and told agents and support staff that attackers stole names, addresses, job titles and Social Security numbers through FBIJobs.gov. Some files contained blood and urine sample records and psychiatric reports. The internal notice was the bureau’s first acknowledgment that employee data was taken, after it publicly said the theft remained undetermined. The portal, its primary application channel since 2017, remained offline on September 28.

ShinyHunters claims it obtained data on mostly all FBI personnel and substantial information about applicants by exploiting a vulnerability in an Oracle PeopleSoft server holding human resources records. The group is not seeking money, but demands that the FBI correct an earlier assessment it says misrepresented its activities. National security expert Justin Sherman called the breach a counterintelligence disaster that could expose thousands of personnel to profiling, phishing and approaches by foreign intelligence services.

It remains unclear whether Congress has been notified. Federal law requires disclosure when an intrusion qualifies as a major incident, including theft of personally identifiable information likely to demonstrably harm national security. A required disclosure would be the FBI’s second known notification to lawmakers in 2026, after suspected Chinese hackers breached a surveillance system and exposed targets of FBI surveillance and investigations. The FBI and White House provided no clarification on September 28, while relevant lawmakers had no immediate answers.

Positives

  • The FBI’s September 26 internal notice informed agents and support staff that their personal information had been exposed.
  • FBIJobs.gov remained offline on September 28, limiting continued access through the compromised portal.
  • ShinyHunters says it is not demanding a financial ransom, instead seeking a correction to an earlier FBI assessment.

Risks & concerns

  • Stolen records include Social Security numbers, home addresses, job titles, psychiatric reports, and blood and urine sample information.
  • ShinyHunters claims it obtained data on mostly all FBI personnel and substantial information about FBIJobs.gov applicants.
  • An Oracle PeopleSoft vulnerability allegedly exposed human resources records belonging to agents, employees and applicants.
  • Justin Sherman warned that thousands could face profiling, phishing and approaches from foreign intelligence services.
  • Congressional notification remains uncertain despite federal disclosure requirements for incidents likely to demonstrably harm national security.
  • A separate 2026 breach attributed to suspected Chinese hackers exposed targets of FBI surveillance and investigations.
Primary sourceTechCrunchhttps://techcrunch.com/2026/09/28/fbi-reportedly-declares-cyber-security-incident-after-hackers-steal-agents-personal-data/
Read full article
Editorial note: Tech Beat summarizes and analyzes third-party reporting. The source link is the authoritative article. This page does not reproduce the full source text.

More From The Wire

CybersecuritySep 28

Truecaller Launches Scam Checker for Web Fraud Beyond Caller ID

CybersecuritySep 25

16,000 Supabase Databases Expose Personal Data as Vibe Coding Security Risks Grow

CybersecuritySep 25

Kiteworks Urges Server Shutdown Over Imminent Zero Day Threat