International🌐 Available in EnglishSeptember 23, 2026

FBI investigating claims that a major cybercrime group stole sensitive personnel data

FBI investigating claims that a major cybercrime group stole sensitive personnel data
Axios
A
Axios
Original Source

A notorious cybercriminal group claims to have stolen over 2 terabytes of sensitive data including detailed personal information about thousands of FBI employees and job applicants. The FBI is currently investigating the claims as cybersecurity experts warn that the leaked data could be sold to the highest bidder on the dark web.

FBI investigates claim notorious hacking group stole employee data

*
* Newsletters
*
* Axios Pro
* Axios Live
* The Axios Show

Axios

Axios

26 mins ago - Technology

FBI investigates hackers' claims of massive data theft

* Sam Sabin

*
*
*

Add Axios on Google

Add Axios as your preferred source to

see more of our stories on Google.

Add Axios on Google

!FBI logo appears on the screen of a cell phone sitting on top of a laptop keyboard

*Photo: Thomas Fuller/SOPA Images/LightRocket via Getty Images*

A notorious cybercrime group is claiming they stole more than 2 terabytes of data that includes detailed personal information about thousands of FBI employees and job applicants.

**Why it matters**: Cybercriminals and state-sponsored attackers have penetrated U.S. IT systems for years, but stealing detailed and sensitive information about FBI employees is brazen, cyber experts told Axios.

* Cybercriminals are known to trade leaked information on the dark web, a prospect that would leave the data up for grabs from the highest bidder.
**Driving the news**: ShinyHunters, a group that's broken into numerous institutions, said in a post on its dark-web site Tuesday that it stole "very sensitive data on almost ALL FBI agents and individuals who filed an application with the FBI for a job."

An FBI spokesperson said in a statement the bureau is "aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating."

**What to watch**: Cynthia Kaiser, a former top official in the FBI's cyber division, told Axios that when a hacker targets the FBI, expect the bureau "to marshal additional resources to bring them more quickly to justice."

**The big picture**: While the breach is likely to bring more law enforcement attention to ShinyHunters in the short term, the long tail impact is greater on the FBI employees and their families whose information was stolen, Allan Liska, a threat intelligence analyst at Recorded Future, told Axios.

* "The data is out there and has likely been repeatedly downloaded and passed around to other threat actors," Liska said.

**Axios has not been able to** corroborate that the data stolen is legitimate or recent, but cybersecurity researchers confirmed that the attack appears legitimate. 404 Media obtained a sample of the stolen data, which appears to include information about 5,000 alleged agents.

**Zoom in**: ShinyHunters told Axios in an email that the stolen data includes names, FBI agent statuses, emails, phone numbers, home addresses and "sometimes even spouse information," including their Social Security numbers.

* The group also claims it broke into the FBI's criminal justice, HR and other services.
* ShinyHunters also said it seized and defaced the FBI's jobs webpage via a zero-day in Oracle's PeopleSoft platform. The site was still offline as of Tuesday afternoon.

!Two Labradors wearing K-9 vests rest on a concrete ledge beside a calm pond in a park. A tan lab sits on the left and a black lab on the right, with a distant monument in the background. The site says it is down for scheduled maintenance.

*Screenshot: FBI career page on Sept. 22.*

**Catch up quick**: ShinyHunters says its hack is not financially motivated. Instead, the group is pushing the FBI to retract statements it made about how ShinyHunters operates.

* In a May advisory, the FBI warned the hackers "commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting."
* ShinyHunters claims this isn't true and told Axios that it believes these claims have been tied to their group because "other low-skilled threat actors" have been using the group's name in their attacks.

**Threat level:** Andrew Brandt, principal threat intelligence incident commander at Huntress, told Axios that a major concern is over whether ShinyHunters chooses to sell the data to other criminal or nation-state hackers.

* "It doesn't take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released," Brandt said.

*
*
*

Add Axios on Google

What to read next

*
*
*
*
*
*

Smarter, faster on what matters.

Explore Axios Newsletters

* About Axios
* Advertise with us
* Careers
* Contact us

* Newsletters
* Axios Live
* Axios HQ

* Privacy policy
* Terms of use
*

Axios Homepage

Axios Media Inc., 2026

🔗 Share Article

Tags:#الأمن السيبراني#مكتب التحقيقات الفيدرالي#الجرائم الإلكترونية#سرقة البيانات#ShinyHunters#الويب المظلم
Source: Axios

For Context

Related reads from the same topic or latest developments