
People who have applied for jobs at the FBI are now facing questions about whether information submitted during the recruitment process was caught in a much larger cyberattack on the agency’s jobs portal.
The hacking group ShinyHunters says it stole between 2 and 3 terabytes of data after compromising FBIJobs.gov, including records linked to current and former employees and people who applied for FBI jobs.
While the FBI says it is investigating the incident, it has not confirmed the group’s claimed volume of stolen data or the full impact on applicants. The Bureau also says it has not yet determined whether the original breach occurred inside its own systems or through a third-party provider supporting the jobs site.
What ShinyHunters Claims It Accessed
According to ShinyHunters, the group entered through a vulnerability in Oracle PeopleSoft, software used for human resources and recruitment, before moving into FBI-managed systems hosted on AWS GovCloud. It claims the stolen information covered current and former employees as well as FBI job applicants.
The group has also named systems connected to human resources, criminal justice, and MedLink among the services it says it accessed. However, the FBI has not confirmed that attack route, the claimed PeopleSoft vulnerability, or even the wider access described by the hackers.
But independent reporting has confirmed that at least some of the stolen material contains highly sensitive information. Reuters examined a roughly 5,000-line spreadsheet containing names, addresses, phone numbers, dates of birth, Social Security numbers, emergency contacts, and FBI job assignments. Some records linked named employees to work involving Chinese and Russian intelligence, Iran, Hezbollah, human intelligence, surveillance, and covert operations.
Reuters also verified information belonging to more than 22 people by comparing the records with credit data and previous leaks, although it could not authenticate the entire spreadsheet.
Reuters later reviewed medical records, and one document from a fitness-for-duty examination for a prospective employee listed daily aspirin use and allergies to dust and cats. Another said a potential employee had shown symptoms of depression in high school, while a third included an electrocardiogram result. It also matched an FBI psychiatrist named in the material to a public professional profile and independently confirmed that another medical professional named in the documents had performed FBI evaluations at the time.
Why the Claim Matters for Job Applicants
These findings make the possible exposure of applicant information particularly important because an FBI recruitment process can involve much more sensitive information than a typical job application.
The FBI’s published privacy policy says information collected during the application process is used to assess qualifications and suitability for employment. It also states that Social Security numbers or other identifiers may be used to identify applicant records and support employment and background checks.
Additionally, the FBI’s hiring process can later involve a background investigation for a Top Secret security clearance, and the medical document reviewed by Reuters also shows that at least some prospective employees underwent fitness-for-duty assessments containing personal health information.
What Happens Next
The FBI says it is actively investigating the breach and has been communicating with people who may have been affected. The scale claimed by ShinyHunters also remains unverified. And while Reuters could confirm portions of the leaked information, it still could not establish whether the documents it examined represented the rest of the hackers’ claimed 2 to 3 terabytes of data.
The FBI has also publicly warned the remaining members of ShinyHunters as investigators pursue the group. Cyber Division Assistant Director Brett Leatherman pointed to the arrest of an alleged ShinyHunters leader in the Netherlands and told other members that investigators were learning more about them through arrests and seized infrastructure.
“You know how to find us, and we know how to find you,” he said. “I suggest you reach out first while the choice is still yours.”
For applicants, the central concern remains that until the FBI establishes exactly what was accessed, people who previously submitted information through FBIJobs.gov do not yet have a clear answer on whether their own records were included in ShinyHunters’ claimed haul.
